# Logstash rename json fields

**URL:** <https://discuss.elastic.co/t/logstash-rename-json-fields/325399>\
**Category:** Logstash\
**Created:** [February 13, 2023, 2:49pm UTC](https://discuss.elastic.co/t/logstash-rename-json-fields/325399 "2023-02-13T14:49:46Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![yilmazbuhar](https://avatars.discourse-cdn.com/v4/letter/y/46a35a/32.png) [@yilmazbuhar](https://discuss.elastic.co/u/yilmazbuhar)\
**Post date:** [February 13, 2023, 2:49pm UTC](https://discuss.elastic.co/t/logstash-rename-json-fields/325399/1 "2023-02-13T14:49:46Z")

</div>

Hi community,

We have a json log as below

```auto
{
  "Timestamp": "2023-02-09T17:41:54.5320239+03:00",
  "Level": "",
  "MessageTemplate": "",
  "Properties": {
    "responsetime": 4758,
    "SourceContext": "",
    "Username": null,
    "Url": "",
    "HttpMethod": "POST",
    "TraceId": "",
    "UserIP": "",
    "UserAgent": "",
    "RequestBody": "",
    "RequestQueryString": "",
    "ResponseBody": "",
    "RequestId": "",
    "RequestPath": "",
    "ConnectionId": "",
    "ApplicationName": ""
  }
}

```

We need to ship this json to any source as below

```auto
{
  "Timestamp": "2023-02-09T17:41:54.5320239+03:00",
  "Level": "",
  "MessageTemplate": "",
  "M1": 4758,
  "M3": "",
  "M4": null,
  "M5": "",
  "M6": "POST",
  "M7": "",
  "M9": "",
  "N8": "",
  "N6": "",
  "Y2": "",
  "...":"...."
}

```

so we need to change all fields name.

Thanks any help.

---

<div class="post-metadata">

**Author:** ![Wave](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/wave/32/117242_2.png) [@Wave](https://discuss.elastic.co/u/Wave)\
**Post date:** [February 13, 2023, 3:50pm UTC](https://discuss.elastic.co/t/logstash-rename-json-fields/325399/2 "2023-02-13T15:50:55Z")

</div>

Sounds like a great case for the logstash and the [mutate filter](https://www.elastic.co/guide/en/logstash/current/plugins-filters-mutate.html).

Something like this:

```auto
 mutate {
      rename => { "responsetime" => "M1" }
      rename => { "SourceContext" => "M3" }
    }

```

You'll also want to flatten out the json as well.

Good luck!

---

<div class="post-metadata">

**Author:** ![yilmazbuhar](https://avatars.discourse-cdn.com/v4/letter/y/46a35a/32.png) [@yilmazbuhar](https://discuss.elastic.co/u/yilmazbuhar)\
**Post date:** [February 13, 2023, 5:02pm UTC](https://discuss.elastic.co/t/logstash-rename-json-fields/325399/3 "2023-02-13T17:02:59Z")

</div>

Hi Andrew,

My config is

```auto
input {
    file {
        path => ["/usr/share/logstash/pipeline/logs/*.log"]
        codec => json
        sincedb_path => "/dev/null"
        start_position => "beginning"
    }
}

filter {
    mutate {
      rename => { "responsetime" => "M1" }
      rename => { "SourceContext" => "M3" }
    }
}

output {
    file {
        path => ["/usr/share/logstash/pipeline/logs_migration/"]
    }
}

```

output is

```auto
{
  "event": {
    "original": "{\"Timestamp\":\"2023-02-09T17:41:54.5320239+03:00\",\"Level\":\"Information\",\"MessageTemplate\":\"Request finished in {responsetime} ms.\",\"Properties\":{\"responsetime\":4758,\"SourceContext\":\"VPOS.Application.RequestResponseLoggingMiddleware\",\"Username\":null,\"Url\":\"http://localhost:5187/api/token\",\"HttpMethod\":\"POST\",\"TraceId\":\"0HMOALF12PNG6:00000002\",\"UserIP\":\"::1\",\"UserAgent\":\"PostmanRuntime/7.30.0\",\"RequestBody\":\"{\\r\\n \\\"username\\\": \\\"testadmin\\\",\\r\\n \\\"password\\\": \\\" ****** \\\"\\r\\n}\",\"RequestQueryString\":\"\",\"ResponseBody\":\"{\\\"token\\\":\\\"4q23PcpOKO5YKVxzwvoTN0hQnp3GIZ328qWiIHUN2ueO2MwHa8N5RFu6P2ou3g\\\",\\\"created\\\":\\\"2023-02-09T17:41:54.510778+03:00\\\"}\",\"RequestId\":\"0HMOALF12PNG6:00000002\",\"RequestPath\":\"/api/token\",\"ConnectionId\":\"0HMOALF12PNG6\",\"ApplicationName\":\"VPOS.Auth.Api, Version=1.0.0.0, Culture=neutral, PublicKeyToken=null\"}}\r"
  },
  "host": { "name": "de5133b1867a" },
  "log": { "file": { "path": "/usr/share/logstash/pipeline/logs/logs.log" } },
  "Level": "Information",
  "Properties": {
    "SourceContext": "",
    "RequestBody": "",
    "TraceId": "0HMOALF12PNG6:00000002",
    "RequestQueryString": "",
    "HttpMethod": "POST",
    "RequestPath": "",
    "Username": null,
    "ResponseBody": "",
    "ConnectionId": "0HMOALF12PNG6",
    "ApplicationName": "VPOS.Auth.Api, Version=1.0.0.0, Culture=neutral, PublicKeyToken=null",
    "responsetime": 4758,
    "UserAgent": "PostmanRuntime/7.30.0",
    "Url": "",
    "UserIP": "::1",
    "RequestId": "0HMOALF12PNG6:00000002"
  },
  "@version": "1",
  "Timestamp": "2023-02-09T17:41:54.5320239+03:00",
  "MessageTemplate": "Request finished in {responsetime} ms.",
  "@timestamp": "2023-02-13T16:56:44.582486700Z"
}

```

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [February 13, 2023, 5:11pm UTC](https://discuss.elastic.co/t/logstash-rename-json-fields/325399/4 "2023-02-13T17:11:08Z")

</div>

> [@yilmazbuhar](#):
>
> ```auto
> filter {
> mutate {
> rename => { "responsetime" => "M1" }
> rename => { "SourceContext" => "M3" }
> }
> }
> 
> ```

The field name is wrong, you do not have a `responsetime` or `SourceContext` field, both are nested inder the `Properties` field, so you need to use the correct field name.

Try the following:

```auto
filter {
    mutate {
      rename => { "[Properties][responsetime]" => "M1" }
      rename => { "[Properties][SourceContext]" => "M3" }
    }
}

```

---

<div class="post-metadata">

**Author:** ![Wave](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/wave/32/117242_2.png) [@Wave](https://discuss.elastic.co/u/Wave)\
**Post date:** [February 13, 2023, 5:34pm UTC](https://discuss.elastic.co/t/logstash-rename-json-fields/325399/5 "2023-02-13T17:34:38Z")

</div>

Oh yeah, probably wasn’t very clear by my "flatten out the json" comment but you’ll want to access the nested values like @leandrojmp says.

---

<div class="post-metadata">

**Author:** ![yilmazbuhar](https://avatars.discourse-cdn.com/v4/letter/y/46a35a/32.png) [@yilmazbuhar](https://discuss.elastic.co/u/yilmazbuhar)\
**Post date:** [February 15, 2023, 4:16pm UTC](https://discuss.elastic.co/t/logstash-rename-json-fields/325399/6 "2023-02-15T16:16:14Z")

</div>

Hi all,

Thank you so much, it works fine.

---

<div class="post-metadata">

**Author:** ![Wave](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/wave/32/117242_2.png) [@Wave](https://discuss.elastic.co/u/Wave)\
**Post date:** [February 15, 2023, 9:24pm UTC](https://discuss.elastic.co/t/logstash-rename-json-fields/325399/7 "2023-02-15T21:24:05Z")

</div>

You're welcome. Glad to hear.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 15, 2023, 9:24pm UTC](https://discuss.elastic.co/t/logstash-rename-json-fields/325399/8 "2023-03-15T21:24:46Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
