# Mutate - Lowercase

**URL:** <https://discuss.elastic.co/t/mutate-lowercase/40271>\
**Category:** Logstash\
**Created:** [January 27, 2016, 5:39pm UTC](https://discuss.elastic.co/t/mutate-lowercase/40271 "2016-01-27T17:39:34Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![bblank](https://avatars.discourse-cdn.com/v4/letter/b/f14d63/32.png) [@bblank](https://discuss.elastic.co/u/bblank)\
**Post date:** [January 27, 2016, 5:39pm UTC](https://discuss.elastic.co/t/mutate-lowercase/40271/1 "2016-01-27T17:39:35Z")

</div>

If I try to add a new field based on another existing field, and then make the new field value lowercase I get what looks like an array in my new field and it isn't lowercase.

FILTER:

mutate {  
add\_field =\> ["myindex", "%{cef\_DeviceVendor}"]  
lowercase =\> ["myindex"]  
}

STDOUT:

"cef\_DeviceVendor" =\> "Microsoft"  
"myindex" =\> [[0] "Microsoft" ]

# =============== OR if I put the lowercase method in it's own mutate filter section, it does convert my new field to lowercase but also converts the original field.

FILTERS:

mutate {  
add\_field =\> ["myindex", "%{cef\_DeviceVendor}"]  
}

mutate { lowercase =\> "myindex" }

STDOUT:

"cef\_DeviceVendor" =\> "microsoft"  
"myindex" =\> "microsoft"

=============  
Can someone describe to me what I am doing wrong? I simply want to use the value of one field as my Index but it has to be lowercase. I don't want to change the value of the original field as well.

TIA - Bob.

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [January 27, 2016, 6:23pm UTC](https://discuss.elastic.co/t/mutate-lowercase/40271/2 "2016-01-27T18:23:23Z")

</div>

Huh, that's weird. I can confirm this on Logstash 2.1.1. It's like the add\_field operation doesn't copy the value of the original field but a reference to it, so that when you downcase the copy the original is affected too.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 5:14am UTC](https://discuss.elastic.co/t/mutate-lowercase/40271/3 "2017-07-06T05:14:04Z")

</div>


