# How can I rename and reorder fields in Kibana?

**URL:** <https://discuss.elastic.co/t/how-can-i-rename-and-reorder-fields-in-kibana/79914>\
**Category:** Kibana\
**Created:** [March 24, 2017, 3:21pm UTC](https://discuss.elastic.co/t/how-can-i-rename-and-reorder-fields-in-kibana/79914 "2017-03-24T15:21:58Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![dolanmk](https://avatars.discourse-cdn.com/v4/letter/d/a183cd/32.png) [@dolanmk](https://discuss.elastic.co/u/dolanmk)\
**Post date:** [March 24, 2017, 3:21pm UTC](https://discuss.elastic.co/t/how-can-i-rename-and-reorder-fields-in-kibana/79914/1 "2017-03-24T15:21:58Z")

</div>

Hi.

I am wondering if there is a way to rearrange the list of fields as they are presented when a document is expanded like in the picture below.

 ![](https://us1.discourse-cdn.com/elastic/original/3X/8/8/88273cef41bbb18b7b8e38162bddec4fa480d07e.png)

I am also wondering if it is possible to rename the "@timestamp" field. For my logs I have a date field, "logdate", that is based on when the logs were originally created along with the "@timestamp" field for when they were sent to ES. I am hoping to rename "@timestamp" to something more descriptive like "stashdate" so that other users do not get confused by the two date fields.

Thank you so much!!

---

<div class="post-metadata">

**Author:** ![Stacey\_Gammon](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stacey_gammon/32/14025_2.png) [@Stacey\_Gammon](https://discuss.elastic.co/u/Stacey_Gammon)\
**Post date:** [March 24, 2017, 6:23pm UTC](https://discuss.elastic.co/t/how-can-i-rename-and-reorder-fields-in-kibana/79914/2 "2017-03-24T18:23:06Z")

</div>

Unfortunately neither are possible in kibana currently, though we do have a popular request for field name aliases here: [https://github.com/elastic/kibana/issues/1896](https://github.com/elastic/kibana/issues/1896). How are you ingesting your data? Perhaps you can change the name at that level?

---

<div class="post-metadata">

**Author:** ![dolanmk](https://avatars.discourse-cdn.com/v4/letter/d/a183cd/32.png) [@dolanmk](https://discuss.elastic.co/u/dolanmk)\
**Post date:** [March 24, 2017, 6:35pm UTC](https://discuss.elastic.co/t/how-can-i-rename-and-reorder-fields-in-kibana/79914/3 "2017-03-24T18:35:49Z")

</div>

Thank you for the prompt reply! I am using Grok patterns to bring the data into ES through Logstash. I tried using the Logstash mutate filter plugin to rename @timestamp but got an error in the console about there being no @timestamp field. Is there another option to rename it before it is sent to Elasticsearch? Maybe copying the values to another field with a different name and then using remove\_field for @timestamp?

---

<div class="post-metadata">

**Author:** ![Stacey\_Gammon](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stacey_gammon/32/14025_2.png) [@Stacey\_Gammon](https://discuss.elastic.co/u/Stacey_Gammon)\
**Post date:** [March 24, 2017, 7:10pm UTC](https://discuss.elastic.co/t/how-can-i-rename-and-reorder-fields-in-kibana/79914/4 "2017-03-24T19:10:06Z")

</div>

You should be able to do this by giving the time field a custom field name, and then using the date filter plugin to make sure it's captured as a date type.

This discuss post outlines steps: [Converting string to date](https://discuss.elastic.co/t/converting-string-to-date/26748)

---

<div class="post-metadata">

**Author:** ![dolanmk](https://avatars.discourse-cdn.com/v4/letter/d/a183cd/32.png) [@dolanmk](https://discuss.elastic.co/u/dolanmk)\
**Post date:** [March 27, 2017, 3:43pm UTC](https://discuss.elastic.co/t/how-can-i-rename-and-reorder-fields-in-kibana/79914/5 "2017-03-27T15:43:29Z")

</div>

Thanks, Stacey! I have added a new field with same value as @timestamp with following code:

![](https://us1.discourse-cdn.com/elastic/original/3X/4/0/40aa9d9a41a8d63cfe54d8cef430362f69463f98.jpg)

Is there anyway to remove the @timestamp field, or at least keep it from being visible in Kibana?

Thanks again!

---

<div class="post-metadata">

**Author:** ![Stacey\_Gammon](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stacey_gammon/32/14025_2.png) [@Stacey\_Gammon](https://discuss.elastic.co/u/Stacey_Gammon)\
**Post date:** [March 28, 2017, 11:23am UTC](https://discuss.elastic.co/t/how-can-i-rename-and-reorder-fields-in-kibana/79914/6 "2017-03-28T11:23:21Z")

</div>

hmm, it does look like there is, as mentioned in the above blog post:

> For bonus points, you can remove the now-superfluous timestamp field (since you overwrote @timestamp), by adding remove\_field =\> "timestamp" to your date filter block. This will only delete the timestamp field upon successful conversion. This way you're not filling up your indices with a redundant timestamp field.

But it looks like you aren't using the date filter to achieve the second time field, so perhaps those instructions won't work. Have you checked out `remove_field` available in the ruby filter. Take a look at these docs:

> **[Ruby filter plugin | Logstash Reference \[8.11\] | Elastic](https://www.elastic.co/guide/en/logstash/current/plugins-filters-ruby.html#plugins-filters-ruby-remove_field)**

Maybe that will do the trick!

---

<div class="post-metadata">

**Author:** ![dolanmk](https://avatars.discourse-cdn.com/v4/letter/d/a183cd/32.png) [@dolanmk](https://discuss.elastic.co/u/dolanmk)\
**Post date:** [March 28, 2017, 2:37pm UTC](https://discuss.elastic.co/t/how-can-i-rename-and-reorder-fields-in-kibana/79914/7 "2017-03-28T14:37:11Z")

</div>

I've tried using the mutate filter to name @timestamp and the ruby filter to remove the field but I get the following error each time:

An unexpected error occurred! :error =\> timestamp field is missing

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 25, 2017, 2:37pm UTC](https://discuss.elastic.co/t/how-can-i-rename-and-reorder-fields-in-kibana/79914/8 "2017-04-25T14:37:24Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
