# Field name \[server.example.com\] cannot contain '.'

**URL:** https://discuss.elastic.co/t/field-name-server-example-com-cannot-contain/61868
**Category:** Logstash
**Created:** [September 29, 2016, 8:42pm UTC](https://discuss.elastic.co/t/field-name-server-example-com-cannot-contain/61868 "2016-09-29T20:42:56Z")
**Posts on this page:** 4
**Page:** 1

<div class="post-metadata">

### Author: ![Ryan\_Groten](https://avatars.discourse-cdn.com/v4/letter/r/f9ae1b/32.png) [@Ryan\_Groten](https://discuss.elastic.co/u/Ryan_Groten)
#### Post date: [September 29, 2016, 8:42pm UTC](https://discuss.elastic.co/t/field-name-server-example-com-cannot-contain/61868/1 "2016-09-29T20:42:56Z")

</div>

I have an application that sends JSON messages to logstash. The JSON looks like this:

```
{
    "status": "Successful",
    "hosts": {
        "server.example.com": {
            "ok": 2,
            "failed": "false"
        },
        "server2.example.com": {
           "ok": 1,
           "failed": "true"
        }
    }
}

```

Elasticsearch throws the error 'Field name [[server.example.com](http://server.example.com)] cannot contain '.'"'

I tried adding de\_dot filter to replace the dots, but I can't get the nesting to work properly. It adds the tag, but the fields all stay the same.

```
de_dot {
    fields => ["hosts"]
    add_tag => ["de_dot"]
    nested => true
}

```

Any suggestions on what I'm doing wrong with de\_dot (or better options!)?

logstash 2.4.0  
elasticsearch 2.4.0

---

<div class="post-metadata">

### Author: ![Ryan\_Groten](https://avatars.discourse-cdn.com/v4/letter/r/f9ae1b/32.png) [@Ryan\_Groten](https://discuss.elastic.co/u/Ryan_Groten)
#### Post date: [September 29, 2016, 9:24pm UTC](https://discuss.elastic.co/t/field-name-server-example-com-cannot-contain/61868/2 "2016-09-29T21:24:52Z")

</div>

I was able to convert nested fqdn strings to short names with this incredibly unappealing solution. If anyone has a better alternative I'd love to hear them!

```
ruby {
    code => "
        data = event['hosts'].clone.to_hash;
        data.each do |k,v|
            newFieldName = k.split('.')[0]
            event['hosts'].delete(k)
            event['hosts'][newFieldName] = v
        end
    "
}

```

Thanks,  
Ryan

---

<div class="post-metadata">

### Author: ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)
#### Post date: [September 30, 2016, 5:47am UTC](https://discuss.elastic.co/t/field-name-server-example-com-cannot-contain/61868/3 "2016-09-30T05:47:35Z")

</div>

It seems the de\_dot filter only considers top-level fields. So yes, for now your ruby filter workaround is probably your best bet.

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [July 6, 2017, 4:36am UTC](https://discuss.elastic.co/t/field-name-server-example-com-cannot-contain/61868/4 "2017-07-06T04:36:21Z")

</div>


