# Mutate/remove fields with dot caracters

**URL:** <https://discuss.elastic.co/t/mutate-remove-fields-with-dot-caracters/91970>\
**Category:** Logstash\
**Created:** [July 5, 2017, 6:21pm UTC](https://discuss.elastic.co/t/mutate-remove-fields-with-dot-caracters/91970 "2017-07-05T18:21:51Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![Romain\_Pelissier](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/romain_pelissier/32/19806_2.png) [@Romain\_Pelissier](https://discuss.elastic.co/u/Romain_Pelissier)\
**Post date:** [July 5, 2017, 6:21pm UTC](https://discuss.elastic.co/t/mutate-remove-fields-with-dot-caracters/91970/1 "2017-07-05T18:21:51Z")

</div>

Hi all!  
We use the input cef codec because we have some arcsight connectors that we want to send their events to our ELK platform. CEF is cool but we would like to remove a lot ot fields that are not necessary for the dashboard we want to make. Of course mutate/remove field is used here but it seems that a lot of cef field have the "." character in them and for what I have read on some forum, it does not seems possible to use the mutate/remove field function with fields that have special characters.  
Can you tell me a good way to manage this?  
ex:

filter {  
if [cef\_vendor] =~ "Fortinet" {  
mutate {  
remove\_field =\> ["cef\_version", "cef\_sigid", "cef\_ext.destinationZoneURI", "cef\_ext.sourceZoneURI", "cef\_ext.sourceZoneURI.keyword", "cef\_ext.sourceZoneURI.keyword"]  
}  
}  
}

Here, the fields "cef\_version" and "cef\_sigid" are removed by the filters but not cef\_ext.\*

Thanks!

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [July 5, 2017, 7:25pm UTC](https://discuss.elastic.co/t/mutate-remove-fields-with-dot-caracters/91970/2 "2017-07-05T19:25:13Z")

</div>

Do you actually have dots in the field names or do you have a hierarchy of fields and subfields? What do your events really look like?

---

<div class="post-metadata">

**Author:** ![usego](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/usego/32/11096_2.png) [@usego](https://discuss.elastic.co/u/usego)\
**Post date:** [July 7, 2017, 11:59am UTC](https://discuss.elastic.co/t/mutate-remove-fields-with-dot-caracters/91970/3 "2017-07-07T11:59:09Z")

</div>

Sorry, let me put mine 2 cents as the issue I'm currently researching could be the same. I have a json filter which parses json sent by filebeat, so after json filter I have data like

eventData.userIdentity.currency EUR  
eventData.userIdentity.ip 13.46.17.118  
eventData.userIdentity.language en

The problem is that 1) geoip filter do not work with field eventData.userIdentity.ip 2) mutate { copy =\> { "eventData.userIdentity.ip", "userIp" } } do not work , even 3) mutate { copy =\> { "[beat.name](http://beat.name)", "beatNameCopy" } } do not work, but 4) mutate { copy =\> { "host", "hostCopy" } } works ,

so I'm assuming this is a global issue with fields with dots.

---

<div class="post-metadata">

**Author:** ![Romain\_Pelissier](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/romain_pelissier/32/19806_2.png) [@Romain\_Pelissier](https://discuss.elastic.co/u/Romain_Pelissier)\
**Post date:** [July 7, 2017, 12:48pm UTC](https://discuss.elastic.co/t/mutate-remove-fields-with-dot-caracters/91970/4 "2017-07-07T12:48:23Z")

</div>

Hi,  
2 things (and it's good news! 🙂

- One of my colleague found the solution (in fact, consider those fields as nested arrays ). You can manage them using the syntax [part1][part2]..[partx].  
ex:  
remove\_field =\> ["cef\_version", "cef\_sigid", "[cef\_ext].[destinationZoneURI]", "[cef\_ext].[sourceZoneURI]", "[cef\_ext][sourceZoneURI.keyword]", "[cef\_ext][sourceZoneURI.keyword]" ]
- The other good news is that all my events come from an ArcSight connectors and with the latest logstash version (or cef plugin), now the field are manged using the same ArcSight syntax. Ex: sourceZoneURI instead of [cef\_ext].[sourceZoneURI] which make the process more easier.

Thanks! Hope this can help.

---

<div class="post-metadata">

**Author:** ![usego](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/usego/32/11096_2.png) [@usego](https://discuss.elastic.co/u/usego)\
**Post date:** [July 9, 2017, 7:11am UTC](https://discuss.elastic.co/t/mutate-remove-fields-with-dot-caracters/91970/5 "2017-07-09T07:11:25Z")

</div>

Makes sense, thanks for the hint!

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [July 12, 2017, 10:43am UTC](https://discuss.elastic.co/t/mutate-remove-fields-with-dot-caracters/91970/6 "2017-07-12T10:43:30Z")

</div>

> so I'm assuming this is a global issue with fields with dots.

The syntax for nested fields is described here: [Accessing event data and fields | Logstash Reference [8.11] | Elastic](https://www.elastic.co/guide/en/logstash/current/event-dependent-configuration.html#logstash-config-field-references)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 9, 2017, 10:44am UTC](https://discuss.elastic.co/t/mutate-remove-fields-with-dot-caracters/91970/7 "2017-08-09T10:44:10Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
