# Elasticsearch mapping - cannot index a field having name starting with a dot

**URL:** <https://discuss.elastic.co/t/elasticsearch-mapping-cannot-index-a-field-having-name-starting-with-a-dot/163804>\
**Category:** Logstash\
**Created:** [January 10, 2019, 8:46pm UTC](https://discuss.elastic.co/t/elasticsearch-mapping-cannot-index-a-field-having-name-starting-with-a-dot/163804 "2019-01-10T20:46:09Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![amitnegi6190](https://avatars.discourse-cdn.com/v4/letter/a/b4bc9f/32.png) [@amitnegi6190](https://discuss.elastic.co/u/amitnegi6190)\
**Post date:** [January 10, 2019, 8:46pm UTC](https://discuss.elastic.co/t/elasticsearch-mapping-cannot-index-a-field-having-name-starting-with-a-dot/163804/1 "2019-01-10T20:46:09Z")

</div>

Hi,

I am trying to send some JSON data into elasticsearch using logstash:

My logstash configuration looks like this: test.config

```
input{
	file{
			path => "/Users/bob/data/test.json"
			codec => json
			sincedb_path => "/dev/null"
			start_position => "beginning"
		}
}

filter{
	json{
		source => "student"
		target => "student"
	}

	mutate{
		convert => { 
			"name" => "string"
			"score" => "float"
			"address" => "string"
		}
	}
}

output{
	elasticsearch{
		hosts => "localhost:9200"
		index => "test"
		document_type => "student"
		manage_template => true
		template => "/Users/bob/data/index_templates/test_template.json"
		template_name => "test_template"
		template_overwrite => true
	}
	stdout { 
		codec => rubydebug 
	}
}

```

And the mapping template being used here is: test\_template.json

```
{
    "index_patterns": "test",
    "settings" : {
        "number_of_shards" : 1,
        "number_of_replicas" : 0,
        "index" : {
            "query" : { "default_field" : "@words" }
        }
    },
    "mappings": {
        "student": { 
            "_source": { "enabled": true },
            "dynamic_templates": [
                {
                    "string_template" : { 
                        "match" : "*",
                        "mapping": { "type": "keyword", "index": true },
                        "match_mapping_type" : "string"
                     } 
                 }
             ],
             "properties" : {
                "name": {"type":"keyword", "index": true},
                "score": {"type": "float"},
                "address": {"type":"keyword", "index": true},
                "lastUpdated":{"type": "date", "format": "epoch_millis"},
                "firstUpdated": {"type": "date", "format": "epoch_millis"},
                "official":{
                    "type": "nested",
                    "properties": {
                        "suid": {"type": "keyword", "index": true},
                        "uploader": {
                            "type": "nested",
                            "properties": {
                                "AGS": {"type": "date", "format": "epoch_millis"},
                                "AGM": {"type": "date", "format": "epoch_millis"}
                            }
                        },
                        "rank": {"type": "integer"}
                    }
                },
                "files":{
                	"type": "nested",
                	"properties": {
                		"../bob/filename1": {
                			"type": "nested",
                			"properties":{
                				"name": {"type":"keyword", "index": true},
                				"signed": {"type":"boolean"},
                				"failure": {"type":"keyword", "index": true},
                				"version": {"type":"keyword", "index": true},
                				"checksum": {"type":"keyword", "index": true},
                				"signer": {"type":"keyword", "index": true},
                			}
                		},
                		"../bob/filename2": {
                			"type": "nested",
                			"properties":{
                				"name": {"type":"keyword", "index": true},
                				"signed": {"type":"boolean"},
                				"failure": {"type":"keyword", "index": true},
                				"version": {"type":"keyword", "index": true},
                				"checksum": {"type":"keyword", "index": true},
                				"signer": {"type":"keyword", "index": true},
                			}
                		}
                	}
                }
            }
        }
    }
}

```

Here, the fields _../bob/filename2_ & _../bob/filename2_ start with dots (..). This causes trouble in indexing my JSON data into elasticsearch. My JSON file is:

```
{"name":"Jonathan James","score":"9.9","address":"NewDelhi","lastUpdated":null,"firstUpdated":"86400","official":[{"suid":"c0c85dc9-e13c-41d1-88a0-6db76ded6a41","uploader":{"AGS":1544817662070,"AGM":1544817662070},"rank":1},{"suid":"c0c85dc9-e13c-41d1-88a0-6db76ded6a1f","uploader":{"AGS":1544817662070,"AGM":1544817662070},"rank":2}],"files":{"../bob/filename1":{"name":"filename1", "signed":true, "failure":null, "version":"13.0.0", "checksum":null, "signer":"Developer ID Application: ABCD"}, "../bob/filename2":{ "name":"filename2", "signed":false, "failure":"InvalidCodeSignature(-67061)", "version":"6.0.0.75", "checksum":null, "signer":"ABCD"}}}
{"name":"Sam Durram Singh","score":"8.9","address":"NewYork","lastUpdated":"1545078074640","firstUpdated":"86400","official":[{"suid":"c0c85dc9-d1d6-42bb-89b0-900e5f1e066d","uploader":{"AGS":1544817662070,"AGM":1544817662070},"rank":3},{"suid":"c0c85dc9-1d1e-4bf4-9596-e6c93d3d3dd0","uploader":{"AGS":1544817662070,"AGM":1544817662070},"rank":4}],"files":{"../bob/filename1":{"name":"filename1", "signed":true, "failureReason":null, "version":"13.0.0", "checksum":null, "signer":"Developer ID Application: ABCD"}, "../bob/filename2":{ "name":"filename2", "signed":false, "failure":"InvalidCodeSignature(-67061)", "version":"6.0.0.75", "checksum":null, "signer":"ABCD"}}}

```

I cannot change the field name in my JSON file. Although, I am ready change the field name in logstash before sending the data into elasticsearch. How do I achieve this?

I even tried renaming the field in the logstash mutate filter:

mutate{  
rename =\> { "../bob/filename1" =\> "filename1" }  
}

but this didn't work. I still get the same error:

> Could not index event to Elasticsearch. {:status=\>400, :action=\>["index", {:\_id=\>nil, :\_index=\>"test", :\_type=\>"student", :routing=\>nil}, #\<LogStash::Event:0x71b03f5a\>], :response=\>{"index"=\>{"\_index"=\>"test", "\_type"=\>"student", "\_id"=\>"UGl\_OWgB9ZDL-4\_eKilu", "status"=\>400, "error"=\>{"type"=\>"mapper\_parsing\_exception", "reason"=\>"failed to parse", "caused\_by"=\>{"type"=\>"illegal\_argument\_exception", "reason"=\>"object field starting or ending with a [.] makes object resolution ambiguous: [../bob/filename1]"}}}}}

---

<div class="post-metadata">

**Author:** ![zqc0512](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/zqc0512/32/32141_2.png) [@zqc0512](https://discuss.elastic.co/u/zqc0512)\
**Post date:** [January 11, 2019, 3:05am UTC](https://discuss.elastic.co/t/elasticsearch-mapping-cannot-index-a-field-having-name-starting-with-a-dot/163804/2 "2019-01-11T03:05:20Z")

</div>

> [@amitnegi6190](#):
>
> [../bob/filename1]"}}}}}

Data parsing error.

---

<div class="post-metadata">

**Author:** ![amitnegi6190](https://avatars.discourse-cdn.com/v4/letter/a/b4bc9f/32.png) [@amitnegi6190](https://discuss.elastic.co/u/amitnegi6190)\
**Post date:** [January 11, 2019, 6:16am UTC](https://discuss.elastic.co/t/elasticsearch-mapping-cannot-index-a-field-having-name-starting-with-a-dot/163804/3 "2019-01-11T06:16:30Z")

</div>

Hi @zqc0512, I am aware that this error is because of the dots(..) in the field name but is there any way I can go ahead as it is? Or maybe rename the field altogether in logstash mutate filter before passing onto elasticsearch?

---

<div class="post-metadata">

**Author:** ![zqc0512](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/zqc0512/32/32141_2.png) [@zqc0512](https://discuss.elastic.co/u/zqc0512)\
**Post date:** [January 11, 2019, 6:26am UTC](https://discuss.elastic.co/t/elasticsearch-mapping-cannot-index-a-field-having-name-starting-with-a-dot/163804/4 "2019-01-11T06:26:27Z")

</div>

try data type string. with mapping

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [January 11, 2019, 7:08am UTC](https://discuss.elastic.co/t/elasticsearch-mapping-cannot-index-a-field-having-name-starting-with-a-dot/163804/5 "2019-01-11T07:08:18Z")

</div>

Yes. You need to modify the field name.  
I moved your question to #logstash where you can hopefully get more help on this.

---

<div class="post-metadata">

**Author:** ![amitnegi6190](https://avatars.discourse-cdn.com/v4/letter/a/b4bc9f/32.png) [@amitnegi6190](https://discuss.elastic.co/u/amitnegi6190)\
**Post date:** [January 11, 2019, 8:29am UTC](https://discuss.elastic.co/t/elasticsearch-mapping-cannot-index-a-field-having-name-starting-with-a-dot/163804/7 "2019-01-11T08:29:21Z")

</div>

Hi @zqc0512, I cannot change the type to string as this is a nested field and can have _nested_ type only

---

<div class="post-metadata">

**Author:** ![amitnegi6190](https://avatars.discourse-cdn.com/v4/letter/a/b4bc9f/32.png) [@amitnegi6190](https://discuss.elastic.co/u/amitnegi6190)\
**Post date:** [January 11, 2019, 8:30am UTC](https://discuss.elastic.co/t/elasticsearch-mapping-cannot-index-a-field-having-name-starting-with-a-dot/163804/8 "2019-01-11T08:30:19Z")

</div>

Hi @dadoonet, Thank you. I tried modifying the field name in my logstash file

```
mutate{
   rename =&gt; { "../bob/filename1" => "filename1" }
}

```

This did not work I was still getting the same error. Am I doing something wrong while renaming the field?

---

<div class="post-metadata">

**Author:** ![amitnegi6190](https://avatars.discourse-cdn.com/v4/letter/a/b4bc9f/32.png) [@amitnegi6190](https://discuss.elastic.co/u/amitnegi6190)\
**Post date:** [January 11, 2019, 8:47am UTC](https://discuss.elastic.co/t/elasticsearch-mapping-cannot-index-a-field-having-name-starting-with-a-dot/163804/9 "2019-01-11T08:47:57Z")

</div>

Thank you guys, I worked it out. I was not renaming the field correctly. I should have done this:

mutate{ rename =\> { "[../bob/filename1]" =\> "[filename1]" } }

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 8, 2019, 8:47am UTC](https://discuss.elastic.co/t/elasticsearch-mapping-cannot-index-a-field-having-name-starting-with-a-dot/163804/10 "2019-02-08T08:47:57Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
