# How to revome the prefix of nested json fields

**URL:** <https://discuss.elastic.co/t/how-to-revome-the-prefix-of-nested-json-fields/55489>\
**Category:** Logstash\
**Created:** [July 14, 2016, 8:34am UTC](https://discuss.elastic.co/t/how-to-revome-the-prefix-of-nested-json-fields/55489 "2016-07-14T08:34:25Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![suntuo](https://avatars.discourse-cdn.com/v4/letter/s/bb73d2/32.png) [@suntuo](https://discuss.elastic.co/u/suntuo)\
**Post date:** [July 14, 2016, 8:34am UTC](https://discuss.elastic.co/t/how-to-revome-the-prefix-of-nested-json-fields/55489/1 "2016-07-14T08:34:25Z")

</div>

input:  
{"cookies":{"mfov":"ZTE Q705U","sver":"5915","appid":"1","mfo":"ZTE","sysver":"4.2.2","plat":"1","sys":"android"}}  
filter{  
json {  
source =\> ["message"]  
}  
}  
 ![](https://us1.discourse-cdn.com/elastic/original/2X/f/f383e71591ab92165ab99b125a044f03e71cea4f.png)

how to remove prefix "cookie." of filed\_name

![](https://us1.discourse-cdn.com/elastic/original/2X/c/c926e4a54814f5ec9f76f73a4f36559783a442df.png)  
i've tried  
mutate {  
rename =\> ["[cookies][mfo]","mfo"]  
rename =\> ["[cookies][mfov]","mfov"]  
rename =\> ["[cookies][plat]","plat"]  
}  
but there's only a few of entries affected

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [July 15, 2016, 6:42am UTC](https://discuss.elastic.co/t/how-to-revome-the-prefix-of-nested-json-fields/55489/2 "2016-07-15T06:42:33Z")

</div>

Works fine with Logstash 2.3.2:

```auto
$ cat data 
{"cookies":{"mfov":"ZTE Q705U","sver":"5915","appid":"1","mfo":"ZTE","sysver":"4.2.2","plat":"1","sys":"android"}}
$ cat test.config 
input { stdin { codec => json } }
output { stdout { codec => rubydebug } }
filter {
  mutate {
    rename => ["[cookies][mfo]","mfo"]
    rename => ["[cookies][mfov]","mfov"]
    rename => ["[cookies][plat]","plat"]
  }
}
$ /opt/logstash/bin/logstash -f test.config < data             
Settings: Default pipeline workers: 8
Pipeline main started
{
       "cookies" => {
          "sver" => "5915",
         "appid" => "1",
        "sysver" => "4.2.2",
           "sys" => "android"
    },
      "@version" => "1",
    "@timestamp" => "2016-07-15T06:41:53.397Z",
          "host" => "lnxolofon",
           "mfo" => "ZTE",
          "mfov" => "ZTE Q705U",
          "plat" => "1"
}
Pipeline main has been shutdown
stopping pipeline {:id=>"main"}

```

---

<div class="post-metadata">

**Author:** ![suntuo](https://avatars.discourse-cdn.com/v4/letter/s/bb73d2/32.png) [@suntuo](https://discuss.elastic.co/u/suntuo)\
**Post date:** [July 15, 2016, 7:17am UTC](https://discuss.elastic.co/t/how-to-revome-the-prefix-of-nested-json-fields/55489/3 "2016-07-15T07:17:50Z")

</div>

thanks, can i remove all prefix? there's so many nested field. it's hard to rename each field.

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [July 15, 2016, 7:30am UTC](https://discuss.elastic.co/t/how-to-revome-the-prefix-of-nested-json-fields/55489/4 "2016-07-15T07:30:54Z")

</div>

You need to use a ruby filter for that. I'm pretty sure there are examples of that (or something very similar) in the archives here or on StackOverflow.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 4:47am UTC](https://discuss.elastic.co/t/how-to-revome-the-prefix-of-nested-json-fields/55489/5 "2017-07-06T04:47:53Z")

</div>


