# Mutate rename filter not working on nested fields

**URL:** <https://discuss.elastic.co/t/mutate-rename-filter-not-working-on-nested-fields/255713>\
**Category:** Logstash\
**Created:** [November 17, 2020, 2:12pm UTC](https://discuss.elastic.co/t/mutate-rename-filter-not-working-on-nested-fields/255713 "2020-11-17T14:12:42Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![blastodorm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/blastodorm/32/79172_2.png) [@blastodorm](https://discuss.elastic.co/u/blastodorm)\
**Post date:** [November 17, 2020, 2:12pm UTC](https://discuss.elastic.co/t/mutate-rename-filter-not-working-on-nested-fields/255713/1 "2020-11-17T14:12:42Z")

</div>

I'm trying to rename a field to work with my data. The field I'm attempting to rename is nested.  
My config:

```
filter {

mutate {rename => { "[message][context][payload][geolocation][latitude]" => "[message][context][payload][geolocation][lat]" } }

}

```

but this is not working.

my data:  
{  
"message": "User",  
"context": {  
"uuid": "06bb5548-0585-4243-92ee-4bd6764b6b93",  
"payload": {  
"id": "06bb5548-0585-4243-92ee-4bd6764b6b93",  
"geolocation": {  
"latitude": 40.4047,  
"longitude": 2.997135,  
"accuracy": 20,  
"altitude": 0,  
},  
"addedAt": "2020-11-16T10:03:08.000000+00:00",  
"createdAt": "2020-11-16T10:03:17.904974+00:00"  
}  
}  
}

---

<div class="post-metadata">

**Author:** ![ylasri](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ylasri/32/86120_2.png) [@ylasri](https://discuss.elastic.co/u/ylasri)\
**Post date:** [November 17, 2020, 2:22pm UTC](https://discuss.elastic.co/t/mutate-rename-filter-not-working-on-nested-fields/255713/2 "2020-11-17T14:22:51Z")

</div>

If your event is already parsed as json, then you can access field directly without message like this

```auto
mutate {rename => { "[context][payload][geolocation][latitude]" => "[context][payload][geolocation][lat]" } }

```

```auto
{
  "message": "User",
  "context": {
    "uuid": "06bb5548-0585-4243-92ee-4bd6764b6b93",
    "payload": {
      "id": "06bb5548-0585-4243-92ee-4bd6764b6b93",
      "geolocation": {
        "latitude": 40.4047,
        "longitude": 2.997135,
        "accuracy": 20,
        "altitude": 0
      },
      "addedAt": "2020-11-16T10:03:08.000000+00:00",
      "createdAt": "2020-11-16T10:03:17.904974+00:00"
    }
  }
}

```

---

<div class="post-metadata">

**Author:** ![blastodorm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/blastodorm/32/79172_2.png) [@blastodorm](https://discuss.elastic.co/u/blastodorm)\
**Post date:** [November 17, 2020, 2:33pm UTC](https://discuss.elastic.co/t/mutate-rename-filter-not-working-on-nested-fields/255713/3 "2020-11-17T14:33:03Z")

</div>

> [@blastodorm](#):
>
> ```auto
> mutate {rename => { "[context][payload][geolocation][latitude]" => "[context][payload][geolocation][lat]" } }
> 
> ```

I tried it and it doesn't work it. If I try to rename only the message field, it works.  
mutate {rename =\> { "[message]" =\> "[xxx]" } }

the problem is when I try to rename nested fields.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 15, 2020, 2:33pm UTC](https://discuss.elastic.co/t/mutate-rename-filter-not-working-on-nested-fields/255713/4 "2020-12-15T14:33:04Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
