# How to remove part of name in multiple fields with Ruby in logstash?

**URL:** <https://discuss.elastic.co/t/how-to-remove-part-of-name-in-multiple-fields-with-ruby-in-logstash/254263>\
**Category:** Logstash\
**Created:** [November 4, 2020, 11:39am UTC](https://discuss.elastic.co/t/how-to-remove-part-of-name-in-multiple-fields-with-ruby-in-logstash/254263 "2020-11-04T11:39:01Z")\
**Posts on this page:** 11\
**Page:** 1

<div class="post-metadata">

**Author:** ![alytkowski](https://avatars.discourse-cdn.com/v4/letter/a/cc9497/32.png) [@alytkowski](https://discuss.elastic.co/u/alytkowski)\
**Post date:** [November 4, 2020, 11:39am UTC](https://discuss.elastic.co/t/how-to-remove-part-of-name-in-multiple-fields-with-ruby-in-logstash/254263/1 "2020-11-04T11:39:01Z")

</div>

I have a source of metrics, which are received by logstash and sent out to Elastic later. There are multiple fields starting with "prometheus.metrics.ems".  
Can someone help with the ruby code or some other method to cut down this part of title from all of the fields? Is it possible?

---

<div class="post-metadata">

**Author:** ![Wolfram\_Haussig](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/wolfram_haussig/32/70528_2.png) [@Wolfram\_Haussig](https://discuss.elastic.co/u/Wolfram_Haussig)\
**Post date:** [November 4, 2020, 11:44am UTC](https://discuss.elastic.co/t/how-to-remove-part-of-name-in-multiple-fields-with-ruby-in-logstash/254263/2 "2020-11-04T11:44:44Z")

</div>

Hi,

How many fields/groups have to be renamed? The easiest would be to use the [rename](https://www.elastic.co/guide/en/logstash/current/plugins-filters-mutate.html#plugins-filters-mutate-rename) option of the mutate filter:

```auto
filter {
      mutate {
        # Renames the 'HOSTORIP' field to 'client_ip'
        rename => { "prometheus.metrics.ems.field1" => "field1" }
      }
    }

```

I think this also works with nested fields so you shouldn't need to rename each field manually.

Best regards  
Wolfram

---

<div class="post-metadata">

**Author:** ![alytkowski](https://avatars.discourse-cdn.com/v4/letter/a/cc9497/32.png) [@alytkowski](https://discuss.elastic.co/u/alytkowski)\
**Post date:** [November 4, 2020, 11:53am UTC](https://discuss.elastic.co/t/how-to-remove-part-of-name-in-multiple-fields-with-ruby-in-logstash/254263/3 "2020-11-04T11:53:54Z")

</div>

Hi!  
I require to change more than 50 fields, that's why I was looking for a more automated method.

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [November 4, 2020, 4:57pm UTC](https://discuss.elastic.co/t/how-to-remove-part-of-name-in-multiple-fields-with-ruby-in-logstash/254263/4 "2020-11-04T16:57:17Z")

</div>

Maybe something like this (which I have not tested)

```
ruby {
    code => '
        event.to_hash.each { |k,v|
            if k =~ "^prometheus.metrics.ems"
                newK = k.sub(/^prometheus.metrics.ems/, "")
                event.remove(k)
                event.set(newK, v)
            end
        }
    '
}
```

---

<div class="post-metadata">

**Author:** ![alytkowski](https://avatars.discourse-cdn.com/v4/letter/a/cc9497/32.png) [@alytkowski](https://discuss.elastic.co/u/alytkowski)\
**Post date:** [November 5, 2020, 7:16am UTC](https://discuss.elastic.co/t/how-to-remove-part-of-name-in-multiple-fields-with-ruby-in-logstash/254263/5 "2020-11-05T07:16:51Z")

</div>

> [@Badger](#):
>
> ```auto
> event.to_hash.each { |k,v|
> if k =~ "^prometheus.metrics.ems"
> newK = k.sub(/^prometheus.metrics.ems/, "")
> event.remove(k)
> event.set(newK, v)
> end
> }
> 
> ```

Unfortunately this gives out below error in the logs:  
[ERROR][logstash.filters.ruby][main] Ruby exception occurred: type mismatch: String given

---

<div class="post-metadata">

**Author:** ![alytkowski](https://avatars.discourse-cdn.com/v4/letter/a/cc9497/32.png) [@alytkowski](https://discuss.elastic.co/u/alytkowski)\
**Post date:** [November 5, 2020, 11:46am UTC](https://discuss.elastic.co/t/how-to-remove-part-of-name-in-multiple-fields-with-ruby-in-logstash/254263/6 "2020-11-05T11:46:56Z")

</div>

After multiple trials with ruby, I've decided to go with the manual rename approach, for now at least. I've contructed the rename filter for all of the fields and.... it doesn't work. Logstash starts up normally, without errors, but the fields aren't renamed in Kibana. They're exactly the same as before. Could you advise on why is that?  
Here's my config for this:  
mutate {  
`add_field => { "EMS-HOST" => "test-host" }`  
`rename => { "prometheus.labels.queue" => "queue" }`  
`rename => { "prometheus.metrics.ems:queue:consumerCount" => "queue:consumerCount" }`  
}

I've added the "EMS-HOST" field just to test if logstash is using the mutate field. The field has been added as a result to all metrics incoming, but the renaming part is not done. There are much more renames in my config, I haven't included them not to spam here.

---

<div class="post-metadata">

**Author:** ![Wolfram\_Haussig](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/wolfram_haussig/32/70528_2.png) [@Wolfram\_Haussig](https://discuss.elastic.co/u/Wolfram_Haussig)\
**Post date:** [November 5, 2020, 11:55am UTC](https://discuss.elastic.co/t/how-to-remove-part-of-name-in-multiple-fields-with-ruby-in-logstash/254263/7 "2020-11-05T11:55:38Z")

</div>

Is the field named `prometheus.labels.queue`or is it a structure like this?

```auto
- prometheus
  - labels
    - queue

```

If it is a structure you need to change the dots to objects:

```auto
mutate {
add_field => { "EMS-HOST" => "test-host" }
rename => { "[prometheus][labels][queue]" => "queue" }
}

```

---

<div class="post-metadata">

**Author:** ![alytkowski](https://avatars.discourse-cdn.com/v4/letter/a/cc9497/32.png) [@alytkowski](https://discuss.elastic.co/u/alytkowski)\
**Post date:** [November 5, 2020, 12:39pm UTC](https://discuss.elastic.co/t/how-to-remove-part-of-name-in-multiple-fields-with-ruby-in-logstash/254263/8 "2020-11-05T12:39:07Z")

</div>

This worked. Thank you very much!

---

<div class="post-metadata">

**Author:** ![alytkowski](https://avatars.discourse-cdn.com/v4/letter/a/cc9497/32.png) [@alytkowski](https://discuss.elastic.co/u/alytkowski)\
**Post date:** [November 5, 2020, 1:33pm UTC](https://discuss.elastic.co/t/how-to-remove-part-of-name-in-multiple-fields-with-ruby-in-logstash/254263/9 "2020-11-05T13:33:23Z")

</div>

> [@alytkowski](#):
>
> prometheus.metrics.ems:queue:consumerCount

How to go about this one? I've tried multiple variations and none are working ;/  
for example:  
`rename => { "[prometheus][metrics][ems]:[queue]:[consumerCount]" => "queue:consumerCount" }`  
`rename => { "[prometheus][metrics][ems][queue][consumerCount]" => "queue:consumerCount" }`  
`rename => { "[prometheus][metrics][ems]:queue:consumerCount" => "queue:consumerCount" }`

---

<div class="post-metadata">

**Author:** ![Wolfram\_Haussig](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/wolfram_haussig/32/70528_2.png) [@Wolfram\_Haussig](https://discuss.elastic.co/u/Wolfram_Haussig)\
**Post date:** [November 5, 2020, 1:57pm UTC](https://discuss.elastic.co/t/how-to-remove-part-of-name-in-multiple-fields-with-ruby-in-logstash/254263/10 "2020-11-05T13:57:47Z")

</div>

I think the colon is part of a normal name, right?

```auto
- prometheus
  - metric
    - ems:queue:consumerCount

```

In this case it would be:

```auto
mutate {
add_field => { "EMS-HOST" => "test-host" }
rename => { "[prometheus][metric][ems:queue:consumerCount]" => "queue:consumerCount" }
}

```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 3, 2020, 1:57pm UTC](https://discuss.elastic.co/t/how-to-remove-part-of-name-in-multiple-fields-with-ruby-in-logstash/254263/11 "2020-12-03T13:57:52Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
