# Logstash coverting field names to all lowercase

**URL:** <https://discuss.elastic.co/t/logstash-coverting-field-names-to-all-lowercase/76470>\
**Category:** Logstash\
**Created:** [February 25, 2017, 7:54am UTC](https://discuss.elastic.co/t/logstash-coverting-field-names-to-all-lowercase/76470 "2017-02-25T07:54:26Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![harikishore96](https://avatars.discourse-cdn.com/v4/letter/h/bbe5ce/32.png) [@harikishore96](https://discuss.elastic.co/u/harikishore96)\
**Post date:** [February 25, 2017, 7:54am UTC](https://discuss.elastic.co/t/logstash-coverting-field-names-to-all-lowercase/76470/1 "2017-02-25T07:54:26Z")

</div>

I'm using Logstash to keep my MySql database and ES in sync. I want to keep field names in both databases to be same. But logstash is converting some uppercase field names to lowercase. How to config logstash, so that those uppercase field names remain same?

Thanks in Advance!

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [February 25, 2017, 9:33am UTC](https://discuss.elastic.co/t/logstash-coverting-field-names-to-all-lowercase/76470/2 "2017-02-25T09:33:17Z")

</div>

It should pass through what it gets, can you show us your config?

---

<div class="post-metadata">

**Author:** ![harikishore96](https://avatars.discourse-cdn.com/v4/letter/h/bbe5ce/32.png) [@harikishore96](https://discuss.elastic.co/u/harikishore96)\
**Post date:** [February 25, 2017, 9:50am UTC](https://discuss.elastic.co/t/logstash-coverting-field-names-to-all-lowercase/76470/3 "2017-02-25T09:50:45Z")

</div>

input {  
jdbc {  
jdbc\_validate\_connection =\> true  
jdbc\_driver\_library =\> "/usr/share/java/mysql-connector-java-5.1.28.jar"  
jdbc\_driver\_class =\> "com.mysql.jdbc.Driver"  
jdbc\_connection\_string =\> "jdbc:mysql://127.0.0.1:3306/testDB"  
jdbc\_user =\> "root"  
jdbc\_password =\> "\*\*\*_"  
schedule =\> "_ \* \* \* \*"  
statement =\> "SELECT \* FROM ` ****` LEFT OUTER JOIN `***** ` USING(` ***** `)"  
}  
}

output {  
elasticsearch {  
# protocol =\> "http"  
index =\> "\*\*\*\*\*\*"  
document\_type =\> "\***_"  
document\_id =\> "%{_**}"  
hosts =\> ["localhost:9200"]  
}  
stdout { codec =\> rubydebug }  
}  
This is my config.  
Those \*\*\*\* are used to hide real names.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 25, 2017, 9:50am UTC](https://discuss.elastic.co/t/logstash-coverting-field-names-to-all-lowercase/76470/4 "2017-03-25T09:50:58Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
