# Es response with field name with dots to bind in hive

**URL:** <https://discuss.elastic.co/t/es-response-with-field-name-with-dots-to-bind-in-hive/127019>\
**Category:** Elasticsearch\
**Tags:** es-hadoop\
**Created:** [April 6, 2018, 3:00am UTC](https://discuss.elastic.co/t/es-response-with-field-name-with-dots-to-bind-in-hive/127019 "2018-04-06T03:00:29Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Suktae\_Choi](https://avatars.discourse-cdn.com/v4/letter/s/2bfe46/32.png) [@Suktae\_Choi](https://discuss.elastic.co/u/Suktae_Choi)\
**Post date:** [April 6, 2018, 3:00am UTC](https://discuss.elastic.co/t/es-response-with-field-name-with-dots-to-bind-in-hive/127019/1 "2018-04-06T03:00:29Z")

</div>

I tired to bind this response to hive and got failed.

```
{
    "took":3068,
    "timed_out":false,
    "_shards":{
        "total":348,
        "successful":348,
        "skipped":0,
        "failed":0
    },
    "hits":{
        "total":238,
        "max_score":0,
        "hits":[
            {
                "_id":"QY9QcmIB_VYGYMGMm28T",
                "_score":0,
                "_source":{
                    "nx.request_body":"...",
                    "nx.request_url":"...",
                    "nx.request_length":"..."
                }
            }
        ]
    }
}

```

enclosing json field has dot separate delimiter.  
and here is hive schema definition.

```
CREATE EXTERNAL TABLE ncp.tmp_nginx_center_photoprint (
    prospector STRUCT <type:STRING>,
    beat STRUCT <
        hostname:STRING,
        name:STRING,
        version:STRING
    >,
    nx.request_body STRING, // parsing error
    body STRING // didnt work (bind to NULL)
)
STORED BY 'org.elasticsearch.hadoop.hive.EsStorageHandler'
TBLPROPERTIES(
    'es.mapping.names' = 'body:nx.request_body',
);

```

1. hive can't work with column name with special characters like . so nx.request\_body STRING is failed
2. tried to map nx.request\_body to newly defined name (body) and use it in DDL but binding result is always NULL (maybe value is not bound properly)

Any idea to bind field name with dot into hive table?  
I can workaround with renaming all field in ES query like

```
"script_fields": {
    "request_url": {
      "script": "params['_source']['nx.request_url']"
    },
    "request_body": {
      "script": "params['_source']['nx.request_body']"
    }
}

```

But It doesn't good nice, (should re-defined all required fields line by line) so Im looking forward to knowing spec of this problem can be solved or not

---

<div class="post-metadata">

**Author:** ![james.baiera](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/james.baiera/32/10209_2.png) [@james.baiera](https://discuss.elastic.co/u/james.baiera)\
**Post date:** [April 6, 2018, 3:11pm UTC](https://discuss.elastic.co/t/es-response-with-field-name-with-dots-to-bind-in-hive/127019/2 "2018-04-06T15:11:19Z")

</div>

This is a known issue: [https://github.com/elastic/elasticsearch-hadoop/issues/853](https://github.com/elastic/elasticsearch-hadoop/issues/853)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 4, 2018, 3:11pm UTC](https://discuss.elastic.co/t/es-response-with-field-name-with-dots-to-bind-in-hive/127019/3 "2018-05-04T15:11:43Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
