# ES 2.1.2: Handling bad field names

**URL:** https://discuss.elastic.co/t/es-2-1-2-handling-bad-field-names/47472
**Category:** Elasticsearch
**Created:** [April 15, 2016, 7:57am UTC](https://discuss.elastic.co/t/es-2-1-2-handling-bad-field-names/47472 "2016-04-15T07:57:16Z")
**Posts on this page:** 4
**Page:** 1

<div class="post-metadata">

### Author: ![dawiro](https://avatars.discourse-cdn.com/v4/letter/d/71e660/32.png) [@dawiro](https://discuss.elastic.co/u/dawiro)
#### Post date: [April 15, 2016, 7:57am UTC](https://discuss.elastic.co/t/es-2-1-2-handling-bad-field-names/47472/1 "2016-04-15T07:57:16Z")

</div>

Hi,  
In our elasticsearch environment we use dynamic mapping for log aggregation. However, we have some inbound logs with fields of the format "[field.name](http://field.name)". Which generates an exception:

[2016-04-15 08:22:52,274][DEBUG][action.admin.indices.mapping.put] [es\_master] failed to put mappings on indices [[logs-debug-2016.04.15]], type [service\_core]  
MapperParsingException[Field name [[field.name](http://field.name)] cannot contain '.']

Can I allow for these poorly formatted field names by adding a mapping to my index template? If so, how do I do it?

Regards,  
David

---

<div class="post-metadata">

### Author: ![JD557](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jd557/32/9112_2.png) [@JD557](https://discuss.elastic.co/u/JD557)
#### Post date: [April 15, 2016, 2:56pm UTC](https://discuss.elastic.co/t/es-2-1-2-handling-bad-field-names/47472/2 "2016-04-15T14:56:47Z")

</div>

If those logs come from logstash, I believe that you can use the [de\_dot filter](https://www.elastic.co/guide/en/logstash/current/plugins-filters-de_dot.html).

---

<div class="post-metadata">

### Author: ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)
#### Post date: [April 16, 2016, 8:26pm UTC](https://discuss.elastic.co/t/es-2-1-2-handling-bad-field-names/47472/3 "2016-04-16T20:26:42Z")

</div>

The only way to do it in ES would be to use something like [https://www.elastic.co/guide/en/elasticsearch/reference/current/analysis-pattern-tokenizer.html](https://www.elastic.co/guide/en/elasticsearch/reference/current/analysis-pattern-tokenizer.html) with a custom pattern.

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [July 5, 2017, 10:58pm UTC](https://discuss.elastic.co/t/es-2-1-2-handling-bad-field-names/47472/4 "2017-07-05T22:58:47Z")

</div>


