# Field name cannot contain '.'

**URL:** <https://discuss.elastic.co/t/field-name-cannot-contain/33251>\
**Category:** Logstash\
**Created:** [October 29, 2015, 2:05pm UTC](https://discuss.elastic.co/t/field-name-cannot-contain/33251 "2015-10-29T14:05:04Z")\
**Posts on this page:** 8\
**Page:** 3

<div class="post-metadata">

**Author:** ![Nizar\_Khalifa](https://avatars.discourse-cdn.com/v4/letter/n/ed655f/32.png) [@Nizar\_Khalifa](https://discuss.elastic.co/u/Nizar_Khalifa)\
**Post date:** [June 24, 2016, 2:33pm UTC](https://discuss.elastic.co/t/field-name-cannot-contain/33251/42 "2016-06-24T14:33:38Z")

</div>

Yes it's just an example.  
I tested your code to replace a field name starting winth dot but it doesn't work for second level (params..title)

---

<div class="post-metadata">

**Author:** ![3ygun](https://avatars.discourse-cdn.com/v4/letter/3/67e7ee/32.png) [@3ygun](https://discuss.elastic.co/u/3ygun)\
**Post date:** [July 18, 2016, 4:39pm UTC](https://discuss.elastic.co/t/field-name-cannot-contain/33251/43 "2016-07-18T16:39:30Z")

</div>

For anyone looking into this here is the current state:

- \*\*'.'\*\*s _can_ be used in Logstash
- \*\*'.'\*\*s _cannot_ be used in Elasticsearch 2.X
  - [ES issue](https://github.com/elastic/elasticsearch/issues/15951)

- \*\*BUT '.'\*\*s _should_ be usable in Elasticsearch 5.X
  - ['.'s in Dynamic Mappings](https://github.com/elastic/elasticsearch/pull/17759)
  - ['.'s in Specific Mappings](https://github.com/elastic/elasticsearch/issues/19443)

Best of luck!

---

<div class="post-metadata">

**Author:** ![ndtreviv](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ndtreviv/32/22494_2.png) [@ndtreviv](https://discuss.elastic.co/u/ndtreviv)\
**Post date:** [July 21, 2016, 10:17am UTC](https://discuss.elastic.co/t/field-name-cannot-contain/33251/44 "2016-07-21T10:17:57Z")

</div>

OK, so question-from-ignorant me:

We're upgrading from 1.7 to 2.3. Some of our field names have dots in. What's the best way for us to migrate our data?

---

<div class="post-metadata">

**Author:** ![SwethaS](https://avatars.discourse-cdn.com/v4/letter/s/e99b99/32.png) [@SwethaS](https://discuss.elastic.co/u/SwethaS)\
**Post date:** [July 21, 2016, 10:38am UTC](https://discuss.elastic.co/t/field-name-cannot-contain/33251/45 "2016-07-21T10:38:57Z")

</div>

if your 1.7 index has \_source enabled, de-dot filter helps you in replacing . in field names to \_ or any other seperator. Once you run this utility 2.3 will be able to identify these indices.  
if \_source is disabled, there is no way to re-use the same indices, so have to discard the old ones and do indexing again

---

<div class="post-metadata">

**Author:** ![ndtreviv](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ndtreviv/32/22494_2.png) [@ndtreviv](https://discuss.elastic.co/u/ndtreviv)\
**Post date:** [July 21, 2016, 12:01pm UTC](https://discuss.elastic.co/t/field-name-cannot-contain/33251/46 "2016-07-21T12:01:44Z")

</div>

Is it available as an elasticsearch plugin? Or only with logstash?

---

<div class="post-metadata">

**Author:** ![SwethaS](https://avatars.discourse-cdn.com/v4/letter/s/e99b99/32.png) [@SwethaS](https://discuss.elastic.co/u/SwethaS)\
**Post date:** [July 21, 2016, 12:17pm UTC](https://discuss.elastic.co/t/field-name-cannot-contain/33251/47 "2016-07-21T12:17:28Z")

</div>

Only with logstash

---

<div class="post-metadata">

**Author:** ![tomski](https://avatars.discourse-cdn.com/v4/letter/t/9fc348/32.png) [@tomski](https://discuss.elastic.co/u/tomski)\
**Post date:** [August 4, 2016, 4:31pm UTC](https://discuss.elastic.co/t/field-name-cannot-contain/33251/48 "2016-08-04T16:31:15Z")

</div>

Hi!

Im also stucking with the "dot in a field problem"  
I installed the de\_dot plugin and activated it in the filter section:

```
filter {
  de_dot {
    nested => true
  }
}

```

The plugin itself seems working as I tested to add some fields with a successfully result.  
But it seems that the dots in a field are not replaced, here is an example output:

```
{
   "kind" => "NodeList",
   "apiVersion" => "v1",
   "metadata" => {
        "selfLink" => "/api/v1/nodes",
        "resourceVersion" => "3890942"
    },
       "items" => [
        [0] {
            "metadata" => {
            "name" => "172.28.50.151",
            "selfLink" => "/api/v1/nodes/172.28.50.151",
            "uid" => "a2a40d8e-438e-11e6-befd-326261363032",
            "resourceVersion" => "3890934",
            "creationTimestamp" => "2016-07-06T15:30:57Z",
                    "labels" => {
                    " **beta.kubernetes.io** /arch" => "amd64",
                    " **beta.kubernetes.io** /os" => "linux",
                    " **kubernetes.io** /hostname" => "172.28.50.151"
                },
                    "annotations" => {
                    "volumes.kubernetes.io/controller-managed-attach-detach" => "true"
                }
            },
           "spec" => {

```

The json input string seems to be valid, I checked it with an online json parser, here is an extract from the input:

```
{
  "kind": "NodeList",
  "apiVersion": "v1",
  "metadata": {
    "selfLink": "/api/v1/nodes",
    "resourceVersion": "3886292"
  },
  "items": [
    {
      "metadata": {
        "name": "172.28.50.151",
        "selfLink": "/api/v1/nodes/172.28.50.151",
        "uid": "a2a40d8e-438e-11e6-befd-326261363032",
        "resourceVersion": "3886286",
        "creationTimestamp": "2016-07-06T15:30:57Z",
        "labels": {
          " **beta.kubernetes**.io/arch": "amd64",
          " **beta.kubernetes.io** /os": "linux",
          "kubernetes.io/hostname": "172.28.50.151"
        },
        "annotations": {
          "volumes.kubernetes.io/controller-managed-attach-detach": "true"
        }
      },
      "spec": {

```

This is the error message I get:  
`"reason"=>"Field name [volumes.kubernetes.io/controller-managed-attach-detach] cannot contain '.'"}}}, :level=>:warn}`

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 4:44am UTC](https://discuss.elastic.co/t/field-name-cannot-contain/33251/49 "2017-07-06T04:44:21Z")

</div>



[Previous page](https://discuss.elastic.co/t/field-name-cannot-contain/33251.md?page=2)
