# Mutate Replace not working properly in ELK STACK 7.2 Looks there a bunch of bug of this verion

**URL:** <https://discuss.elastic.co/t/mutate-replace-not-working-properly-in-elk-stack-7-2-looks-there-a-bunch-of-bug-of-this-verion/188995>\
**Category:** Logstash\
**Created:** [July 5, 2019, 3:41am UTC](https://discuss.elastic.co/t/mutate-replace-not-working-properly-in-elk-stack-7-2-looks-there-a-bunch-of-bug-of-this-verion/188995 "2019-07-05T03:41:30Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![mark.quilates](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mark.quilates/32/24802_2.png) [@mark.quilates](https://discuss.elastic.co/u/mark.quilates)\
**Post date:** [July 5, 2019, 3:41am UTC](https://discuss.elastic.co/t/mutate-replace-not-working-properly-in-elk-stack-7-2-looks-there-a-bunch-of-bug-of-this-verion/188995/1 "2019-07-05T03:41:30Z")

</div>

Hi All,

Tried these in my logstash filtering.

```
  filter {
    if [geoip.region_name] == "Guangxi" {
     mutate {
      replace => ["geoip.region_name", "Guangxi Zhuang Autonomous Region"]
     }
    }

    if [geoip.region_name] == "Inner Mongolia Autonomous Region" {
     mutate {
      replace => ["geoip.region_name", "Inner Mongolia"]
     }
    }
}

```

To replace the "Guangxi" to "Guangxi Zhuang Autonomous Region" and "Inner Mongolia Autonomous Region" to "Inner Mongolia", to work on vector map of China province. However it never changed the output as expected and still the same.

But logstash check was "Configuration OK"

Same thing here in my previous posted.

> [@Scripted field not working properly in ELK 7.2](https://discuss.elastic.co/t/scripted-field-not-working-properly-in-elk-7-2/188599):
>
> Hi Anyone can you help me? Below codes were from my ELK Version: 6.3.2 and everything works fine before. But, when I've upgraded this week to 7.2 these code not working as expected. Also, tried this: if (doc['os.keyword'].value != null || doc['os\_major.keyword'].value != null || doc['os\_minor.keyword'].value != null) { return doc['os.keyword'].value + ' ' + doc['os\_major.keyword'].value + '.' + doc['os\_minor.keyword'].value; } return ""; It say... Once deleted the script…

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [July 5, 2019, 2:37pm UTC](https://discuss.elastic.co/t/mutate-replace-not-working-properly-in-elk-stack-7-2-looks-there-a-bunch-of-bug-of-this-verion/188995/2 "2019-07-05T14:37:59Z")

</div>

> [@mark.quilates](#):
>
> if [geoip.region\_name]

That refers to a field with a dot in its name, a geoip is an object with fields inside it. Use [geoip][region\_name]

---

<div class="post-metadata">

**Author:** ![mark.quilates](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mark.quilates/32/24802_2.png) [@mark.quilates](https://discuss.elastic.co/u/mark.quilates)\
**Post date:** [July 8, 2019, 3:37am UTC](https://discuss.elastic.co/t/mutate-replace-not-working-properly-in-elk-stack-7-2-looks-there-a-bunch-of-bug-of-this-verion/188995/3 "2019-07-08T03:37:12Z")

</div>

@Badger,

Great! It works perfectly as my expected. Thank you very much for your helped.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 5, 2019, 3:37am UTC](https://discuss.elastic.co/t/mutate-replace-not-working-properly-in-elk-stack-7-2-looks-there-a-bunch-of-bug-of-this-verion/188995/4 "2019-08-05T03:37:22Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
