# Fields with a "dot" in them do not persist

**URL:** <https://discuss.elastic.co/t/fields-with-a-dot-in-them-do-not-persist/234965>\
**Category:** Kibana\
**Tags:** painless\
**Created:** [May 29, 2020, 5:52pm UTC](https://discuss.elastic.co/t/fields-with-a-dot-in-them-do-not-persist/234965 "2020-05-29T17:52:25Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![jayson](https://avatars.discourse-cdn.com/v4/letter/j/aeb1de/32.png) [@jayson](https://discuss.elastic.co/u/jayson)\
**Post date:** [May 29, 2020, 5:52pm UTC](https://discuss.elastic.co/t/fields-with-a-dot-in-them-do-not-persist/234965/1 "2020-05-29T17:52:25Z")

</div>

I'm trying to use Painless to do a transform for a Slack alert message. I believe I've followed the standard for using Painless to be able to persist the field that have a dot in them. However, those fields always show up as null. I'm not sure what I'm doing wrong. Any help would be appreciated.  
Here is the request:

> <https://gist.github.com/jaysonv0341/ec4a715625f99e4b3e469735d2cb6c55.js>

  
And here is the response. Notice that agent.version and host.hostname are NULL in the transform.  

> <https://gist.github.com/jaysonv0341/cfc0cf97eec21b5861496cb40f223be2.js>

---

<div class="post-metadata">

**Author:** ![poff](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/poff/32/81795_2.png) [@poff](https://discuss.elastic.co/u/poff)\
**Post date:** [June 1, 2020, 7:24pm UTC](https://discuss.elastic.co/t/fields-with-a-dot-in-them-do-not-persist/234965/2 "2020-06-01T19:24:33Z")

</div>

Hey there jayson,

In your transform, instead of referring to the fields like `data._source['host.hostname']`, try referring to the fields like `data._source.host.hostname`

Does that still give null values?

---

<div class="post-metadata">

**Author:** ![jayson](https://avatars.discourse-cdn.com/v4/letter/j/aeb1de/32.png) [@jayson](https://discuss.elastic.co/u/jayson)\
**Post date:** [June 1, 2020, 8:04pm UTC](https://discuss.elastic.co/t/fields-with-a-dot-in-them-do-not-persist/234965/3 "2020-06-01T20:04:45Z")

</div>

That did work. Thank you. I read in another post that Painless needed the brackets around the fields that had "." in the field name. I removed those and it worked great.  
Some info below for others to reference and understand better in the future.  
['host']['hostname'] traverses the `host` object and accesses the `hostname` key  
['host.hostname'] accesses the key "host.hostname" which doesn’t exist

---

<div class="post-metadata">

**Author:** ![poff](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/poff/32/81795_2.png) [@poff](https://discuss.elastic.co/u/poff)\
**Post date:** [June 1, 2020, 8:09pm UTC](https://discuss.elastic.co/t/fields-with-a-dot-in-them-do-not-persist/234965/4 "2020-06-01T20:09:53Z")

</div>

Excellent! Great to hear that worked for ya 🙂

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 29, 2020, 8:09pm UTC](https://discuss.elastic.co/t/fields-with-a-dot-in-them-do-not-persist/234965/5 "2020-06-29T20:09:53Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
