i've tried
mutate {
rename => ["[cookies][mfo]","mfo"]
rename => ["[cookies][mfov]","mfov"]
rename => ["[cookies][plat]","plat"]
}
but there's only a few of entries affected
You need to use a ruby filter for that. I'm pretty sure there are examples of that (or something very similar) in the archives here or on StackOverflow.
Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant logo are trademarks of the Apache Software Foundation in the United States and/or other countries.