# ElasticSearch Logstash JDBC: How to aggregate into different column names

**URL:** <https://discuss.elastic.co/t/elasticsearch-logstash-jdbc-how-to-aggregate-into-different-column-names/162323>\
**Category:** Logstash\
**Created:** [December 28, 2018, 9:14am UTC](https://discuss.elastic.co/t/elasticsearch-logstash-jdbc-how-to-aggregate-into-different-column-names/162323 "2018-12-28T09:14:46Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![mpssantos](https://avatars.discourse-cdn.com/v4/letter/m/c4cdca/32.png) [@mpssantos](https://discuss.elastic.co/u/mpssantos)\
**Post date:** [December 28, 2018, 9:14am UTC](https://discuss.elastic.co/t/elasticsearch-logstash-jdbc-how-to-aggregate-into-different-column-names/162323/1 "2018-12-28T09:14:46Z")

</div>

I am new to Elasticsearch and I am trying to use Logstash to load data to an index. Following is a partial of my losgstash config:

```auto
filter {
  aggregate {
    task_id => "%{code}"
    code => "
      map['campaignId'] = event.get('CAM_ID')
      map['country'] = event.get('COUNTRY')
      map['countryName'] = event.get('COUNTRYNAME')
    # etc
    "
    push_previous_map_as_event => true
    timeout => 5
  }
}

output {
  elasticsearch {
    document_id => "%{code}"
    document_type => "company"
    index => "company_v1"
    codec => "json"
    hosts => ["127.0.0.1:9200"]
  }
}

```

I was expecting that the aggregation would map for instance the column 'CAM\_ID' into a property in the ElasticSearch Index as 'campaignId'. Instead, is creating a property with the name 'cam\_id' which is the column name as lowercase. The same with the rest of the properties.

Following is the Index Document after logstash being executed:

```auto
{
  "company_v1": {
    "aliases": {

    },
    "mappings": {
      "company": {
        "properties": {
          "@timestamp": {
            "type": "date"
          },
          "@version": {
            "type": "text",
            "fields": {
              "keyword": {
                "type": "keyword",
                "ignore_above": 256
              }
            }
          },
          "cam_id": {
            "type": "long"
          },
          "campaignId": {
            "type": "long"
          },
          "cam_type": {
            "type": "text",
            "fields": {
              "keyword": {
                "type": "keyword",
                "ignore_above": 256
              }
            }
          },
          "campaignType": {
            "type": "text"
          }
        }
      }
    },
    "settings": {
      "index": {
        "creation_date": "1545905435871",
        "number_of_shards": "5",
        "number_of_replicas": "1",
        "uuid": "Dz0x16ohQWWpuhtCB3Y4Vw",
        "version": {
          "created": "6050399"
        },
        "provided_name": "company_v1"
      }
    }
  }
}

```

'campaignId' and 'campaignType' were created by me when i created the index, but logstash created the other 2.

Can someone explain me how to configure logstash to customize the indexes documents properties names when data is being loaded?

Where can i find a place to understand better how events and map works?

Thank you very much.

Best Regards

---

<div class="post-metadata">

**Author:** ![balumurari1](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/balumurari1/32/39203_2.png) [@balumurari1](https://discuss.elastic.co/u/balumurari1)\
**Post date:** [December 28, 2018, 12:09pm UTC](https://discuss.elastic.co/t/elasticsearch-logstash-jdbc-how-to-aggregate-into-different-column-names/162323/2 "2018-12-28T12:09:00Z")

</div>

in logstash config file, modify the query as

> statement =\> "select campaignId as CAM\_ID, country as COUNTRY , countryName as COUNTRYNAME from SAMPLE"

these alias names will replace with the names as per your requirement.

Regards

---

<div class="post-metadata">

**Author:** ![mpssantos](https://avatars.discourse-cdn.com/v4/letter/m/c4cdca/32.png) [@mpssantos](https://discuss.elastic.co/u/mpssantos)\
**Post date:** [December 28, 2018, 12:23pm UTC](https://discuss.elastic.co/t/elasticsearch-logstash-jdbc-how-to-aggregate-into-different-column-names/162323/3 "2018-12-28T12:23:15Z")

</div>

Thank you a lot.

To achieve that i had to add the following parameter:

input {  
...  
lowercase\_column\_names =\> false  
...  
}

I tried this as well and it worked. but I am not sure it is a workaround or if there is a

filter {  
mutate {  
rename =\> ["CAM\_ID", "campaignId"]  
rename =\> ["CAM\_TYPE", "campaignTypePY"]  
}  
}

Does this makes sense?

---

<div class="post-metadata">

**Author:** ![balumurari1](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/balumurari1/32/39203_2.png) [@balumurari1](https://discuss.elastic.co/u/balumurari1)\
**Post date:** [December 28, 2018, 12:31pm UTC](https://discuss.elastic.co/t/elasticsearch-logstash-jdbc-how-to-aggregate-into-different-column-names/162323/4 "2018-12-28T12:31:08Z")

</div>

yes you are on the correct path. 👍

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 25, 2019, 12:31pm UTC](https://discuss.elastic.co/t/elasticsearch-logstash-jdbc-how-to-aggregate-into-different-column-names/162323/5 "2019-01-25T12:31:19Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
