# JSON rename

**URL:** <https://discuss.elastic.co/t/json-rename/29767>\
**Category:** Logstash\
**Created:** [September 22, 2015, 9:32am UTC](https://discuss.elastic.co/t/json-rename/29767 "2015-09-22T09:32:52Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![radu.stefanache](https://avatars.discourse-cdn.com/v4/letter/r/dbc845/32.png) [@radu.stefanache](https://discuss.elastic.co/u/radu.stefanache)\
**Post date:** [September 22, 2015, 9:32am UTC](https://discuss.elastic.co/t/json-rename/29767/1 "2015-09-22T09:32:52Z")

</div>

Hello everyone,

I am currently parsing a json string into an object which gets mapped into a structure similar to this :

```
[parentobj][childobj][attr1]
[parentobj][childobj][attr2]
[parentobj][childobj][attr2]

```

What I want to achieve is to rename all by just removing the `[parentobj]` so it will look like this :

```
[childobj][attr1]
[childobj][attr2]
[childobj][attr3]

```

From what I've seen this can be achieve with mutate's rename function but this means that I will have to statically define every single rename statement and it doesn't scale that well .

Does anyone have a better idea on how to do this ?

Thank you in advance! 😄

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [September 22, 2015, 9:53am UTC](https://discuss.elastic.co/t/json-rename/29767/2 "2015-09-22T09:53:30Z")

</div>

Unless you can rename `[parentobj][childobj]` to `[childobj]` I think you need to use a ruby filter.

```
filter {
  ruby {
    code => "
      event['childobj'] = event['parentobj']['childobj']
    "
  }
}
```

---

<div class="post-metadata">

**Author:** ![radu.stefanache](https://avatars.discourse-cdn.com/v4/letter/r/dbc845/32.png) [@radu.stefanache](https://discuss.elastic.co/u/radu.stefanache)\
**Post date:** [September 22, 2015, 10:16am UTC](https://discuss.elastic.co/t/json-rename/29767/3 "2015-09-22T10:16:54Z")

</div>

Thank you Magnus .

I could match till the `childobj` so I can basically apply a `kv` filter for the `parentobj` and then json the `childobj` and this way I wouldn't have to rename but this means again more scenarios to cover aka more match rules therefore this is why I was looking for a rename function .  
The ruby code works well, now I have to choose if I want to use ruby to `rename` or do a `kv` on the `parentobj` and json on the child . Either way I have to write multiple lines per scenario since I have multiple `childobj` per `parentobj` .

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 5:28am UTC](https://discuss.elastic.co/t/json-rename/29767/4 "2017-07-06T05:28:24Z")

</div>


