# How to rename some fields by using regex statement

**URL:** <https://discuss.elastic.co/t/how-to-rename-some-fields-by-using-regex-statement/257031>\
**Category:** Logstash\
**Created:** [November 30, 2020, 8:23am UTC](https://discuss.elastic.co/t/how-to-rename-some-fields-by-using-regex-statement/257031 "2020-11-30T08:23:43Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![xrubick](https://avatars.discourse-cdn.com/v4/letter/x/e5b9ba/32.png) [@xrubick](https://discuss.elastic.co/u/xrubick)\
**Post date:** [November 30, 2020, 8:23am UTC](https://discuss.elastic.co/t/how-to-rename-some-fields-by-using-regex-statement/257031/1 "2020-11-30T08:23:43Z")

</div>

this's my logstash output:

```bash
    "prometheus" => {   
        "metrics" => {
             "container_cpu_load_average_10s" => 0,
             "container_cpu_user_seconds_total" => 18.15,
             "container_cpu_system_seconds_total" => 12.64
        }
    },

```

now I want use one statement like this:

```bash
mutate {
          rename => {
              "[prometheus][metrics][.*]" => "[.*]"
          }
}

```

to implement like this:

```bash
mutate {
          rename => {
             "[prometheus][metrics][container_cpu_load_average_10s]" => "[container_cpu_load_average_10s]"
             "[prometheus][metrics][container_cpu_user_seconds_total]" => "[container_cpu_user_seconds_total]"
             "[prometheus][metrics][container_cpu_system_seconds_total]" => "[container_cpu_system_seconds_total]"
          }
}

```

Can you help me?Pls!

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [November 30, 2020, 3:34pm UTC](https://discuss.elastic.co/t/how-to-rename-some-fields-by-using-regex-statement/257031/2 "2020-11-30T15:34:53Z")

</div>

You could rename a variable set of fields using a filter like [this](https://discuss.elastic.co/t/how-to-dynamically-move-nested-key-value-to-root-level/180006/2).

---

<div class="post-metadata">

**Author:** ![xrubick](https://avatars.discourse-cdn.com/v4/letter/x/e5b9ba/32.png) [@xrubick](https://discuss.elastic.co/u/xrubick)\
**Post date:** [December 1, 2020, 2:45am UTC](https://discuss.elastic.co/t/how-to-rename-some-fields-by-using-regex-statement/257031/3 "2020-12-01T02:45:04Z")

</div>

It works! Gratefully!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 29, 2020, 2:45am UTC](https://discuss.elastic.co/t/how-to-rename-some-fields-by-using-regex-statement/257031/4 "2020-12-29T02:45:16Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
