# How to change the content of message field

**URL:** <https://discuss.elastic.co/t/how-to-change-the-content-of-message-field/175510>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [April 5, 2019, 4:59am UTC](https://discuss.elastic.co/t/how-to-change-the-content-of-message-field/175510 "2019-04-05T04:59:48Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![savitaashture](https://avatars.discourse-cdn.com/v4/letter/s/4af34b/32.png) [@savitaashture](https://discuss.elastic.co/u/savitaashture)\
**Post date:** [April 5, 2019, 4:59am UTC](https://discuss.elastic.co/t/how-to-change-the-content-of-message-field/175510/1 "2019-04-05T04:59:48Z")

</div>

Hi All,

Input log content:  
{" **time**": "2019-04-03T23:35:17.751Z","stream":"stdout"," **log**":"message content information\n"}

console output:

{  
"@timestamp": "2019-04-05T04:21:57.239Z",  
"@metadata": {  
"beat": "filebeat",  
"type": "doc",  
"version": "6.7.0"  
},  
"log": {  
"file": {  
"path": "c:\Users\I502170\Desktop\savita\code\src\xxxxx\cloudfoundry\public-endpoint-client\integrationtests\please.log"  
}  
},  
"message": "{"time": "2019-04-03T23:35:17.751Z","stream":"stdout","log":"message content information\n"}",  
"beat": {  
"name": "INLN56586635A",  
"version": "6.7.0"  
},  
"testhost": "INLN56586635A",  
"source": "c:\Users\I502170\Desktop\savita\code\src\[github.infra.hana.ondemand.com](http://github.infra.hana.ondemand.com)\cloudfoundry\public-endpoint-client\integrationtests\please.log",  
"offset": 776,  
"prospector": {  
"type": "log"  
},  
"input": {  
"type": "log"  
},  
"host": {  
"name": "INLN56586635A"  
}  
}

Requirement:

Before sending to output(logstash, elasticsearch etc...) we wanted to change  
**time ---\> written\_at**  
**log ---\> msg**

followed all the docs but dint get exact solution for this.

Can please someone suggest for this scenario .

Thank you  
Savita

---

<div class="post-metadata">

**Author:** ![Michal\_Pristas](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/michal_pristas/32/46639_2.png) [@Michal\_Pristas](https://discuss.elastic.co/u/Michal_Pristas)\
**Post date:** [April 5, 2019, 9:37am UTC](https://discuss.elastic.co/t/how-to-change-the-content-of-message-field/175510/2 "2019-04-05T09:37:49Z")

</div>

Hey @savitaashture, welcome to elastic discuss

maybe [rename input processor](https://www.elastic.co/guide/en/beats/filebeat/6.7/rename-fields.html) might be useful to you

Also please make sure to format any configuration you post here. Theres a button `</>` to do that. Sometimes the issue is with indentation of the configuration which is hard to spot if it is not correctly formatted

---

<div class="post-metadata">

**Author:** ![savitaashture](https://avatars.discourse-cdn.com/v4/letter/s/4af34b/32.png) [@savitaashture](https://discuss.elastic.co/u/savitaashture)\
**Post date:** [April 5, 2019, 10:41am UTC](https://discuss.elastic.co/t/how-to-change-the-content-of-message-field/175510/3 "2019-04-05T10:41:47Z")

</div>

Hi @Michal_Pristas,

Thanks for the info...  
Sure i will take care formating next time.

I tried using **rename input processor**  
But it will change only the fields not the content of field

Ex:  
"message": "{"time": "2019-04-03T23:35:17.751Z","stream":"stdout","log":"message content information\n"}",

here  
message is a field which stores string info..  
and i wanted to change content of **message** field.

**log** ---\> **msg**  
**time** ---\> **written\_at**

---

<div class="post-metadata">

**Author:** ![Michal\_Pristas](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/michal_pristas/32/46639_2.png) [@Michal\_Pristas](https://discuss.elastic.co/u/Michal_Pristas)\
**Post date:** [April 5, 2019, 11:02am UTC](https://discuss.elastic.co/t/how-to-change-the-content-of-message-field/175510/4 "2019-04-05T11:02:07Z")

</div>

I'm not sure it is possible on beat directly. You can still use [decode json field](https://www.elastic.co/guide/en/beats/filebeat/6.7/decode-json-fields.html)  
which will parse your message and add additional fields so it will be

```auto
{
    "message": "{"time": "2019-04-03T23:35:17.751Z","stream":"stdout","log":"message content information\n"}",
    "target": {
        "time": "2019-04-03T23:35:17.751Z",
        "stream":"stdout",
        "log":"message content information\n",
    }
}

```

and then on top of it `rename` processor to make it:

```auto
{
    "message": "{"time": "2019-04-03T23:35:17.751Z","stream":"stdout","log":"message content information\n"}",
    "target": {
        "written_at": "2019-04-03T23:35:17.751Z",
        "stream":"stdout",
        "msg":"message content information\n",
    }
}

```

other than that you can look at more advanced options [provided by LogStash](https://www.elastic.co/guide/en/logstash/6.7/plugins-filters-mutate.html#plugins-filters-mutate-gsub)

---

<div class="post-metadata">

**Author:** ![savitaashture](https://avatars.discourse-cdn.com/v4/letter/s/4af34b/32.png) [@savitaashture](https://discuss.elastic.co/u/savitaashture)\
**Post date:** [April 5, 2019, 11:59am UTC](https://discuss.elastic.co/t/how-to-change-the-content-of-message-field/175510/5 "2019-04-05T11:59:12Z")

</div>

Hey @Michal_Pristas

Thanks a lot for the information.

One more query

Once we modify the fields data using [decode json field](https://www.elastic.co/guide/en/beats/filebeat/6.7/decode-json-fields.html)

That particular field will become object .

So can we again convert it back to strings with the updated data.

Thank you  
savita

---

<div class="post-metadata">

**Author:** ![Michal\_Pristas](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/michal_pristas/32/46639_2.png) [@Michal\_Pristas](https://discuss.elastic.co/u/Michal_Pristas)\
**Post date:** [April 5, 2019, 1:44pm UTC](https://discuss.elastic.co/t/how-to-change-the-content-of-message-field/175510/6 "2019-04-05T13:44:32Z")

</div>

I believe the answer is no at the moment, but it is an interesting idea

---

<div class="post-metadata">

**Author:** ![savitaashture](https://avatars.discourse-cdn.com/v4/letter/s/4af34b/32.png) [@savitaashture](https://discuss.elastic.co/u/savitaashture)\
**Post date:** [April 5, 2019, 2:00pm UTC](https://discuss.elastic.co/t/how-to-change-the-content-of-message-field/175510/7 "2019-04-05T14:00:08Z")

</div>

@Michal_Pristas,

Oh Okey...

Thank you for clearing all the doubts 🙂

Thanks  
Savita

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 3, 2019, 2:00pm UTC](https://discuss.elastic.co/t/how-to-change-the-content-of-message-field/175510/8 "2019-05-03T14:00:08Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
