# Mutate - using the value of one field to set the name of another

**URL:** <https://discuss.elastic.co/t/mutate-using-the-value-of-one-field-to-set-the-name-of-another/270462>\
**Category:** Logstash\
**Created:** [April 17, 2021, 8:11pm UTC](https://discuss.elastic.co/t/mutate-using-the-value-of-one-field-to-set-the-name-of-another/270462 "2021-04-17T20:11:34Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![timshaw](https://avatars.discourse-cdn.com/v4/letter/t/9fc29f/32.png) [@timshaw](https://discuss.elastic.co/u/timshaw)\
**Post date:** [April 17, 2021, 8:11pm UTC](https://discuss.elastic.co/t/mutate-using-the-value-of-one-field-to-set-the-name-of-another/270462/1 "2021-04-17T20:11:34Z")

</div>

The following fields come from an extract of a CEF format event in which is is possible to create custom fields and include labels for those fields relevant to a specific event. Labels may be different for different events For example in the event below a custom string field is called cs1 and the relevant label for this field in this event is stored as cs1Label:

```auto
"suser" => "[Public]",
"dvc" => "1.1.1.5",
"cs1" => "CEFTEST",
"cs1Label" => "Tree Name",
"cat" => "Security",
"flexNumber2Label" => "Grouping",
"host" => "1.1.1.5",
"cn2" => "1",
"duser" => "[Public]",
"cs6Label" => "Server Name",
"flexString2Label" => "SubEvent"

```

I am trying to use mutate to set the VALUE of the cs1Label field to be the NAME of the cs1 field. In other words according to the example above I want to rename cs1 to "TreeName" and remove the cs1Label field altogether. So I would have a field "TreeName" =\> "CEFTEST"

I am unable to find any syntax which will achieve this. Both the mutate rename and add\_field commands seem only to recognise strings and not field references passed to them. Can anyone advise please?

---

<div class="post-metadata">

**Author:** ![aaron-nimocks](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/aaron-nimocks/32/73965_2.png) [@aaron-nimocks](https://discuss.elastic.co/u/aaron-nimocks)\
**Post date:** [April 17, 2021, 8:21pm UTC](https://discuss.elastic.co/t/mutate-using-the-value-of-one-field-to-set-the-name-of-another/270462/2 "2021-04-17T20:21:59Z")

</div>

Here is how I am currently doing this. Since the CN1, CS1, etc are set and should always be static I just rename the `cs1` field to what the value of `cs1Label` is.

```auto
mutate {
 rename => { 
  "[cs1]" => "TreeName"           
  "[cs2]" => "XXX"  
  "[cs3]" => "XXX"  
  "[cs4]" => "XXX"  
 }
}  

```

Then I remove all the label fields.

```auto
mutate { remove_field => ["cn1Label", "cn2Label", "cs1Label", "cs2Label", "cs3Label", "cs4Label", "cs5Label", "cs6Label"] }

```

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [April 17, 2021, 8:47pm UTC](https://discuss.elastic.co/t/mutate-using-the-value-of-one-field-to-set-the-name-of-another/270462/3 "2021-04-17T20:47:14Z")

</div>

If the set of fields is not known you would have to use ruby. I have not tested this, but something like

```
ruby {
    code => '
        event.to_hash.each { |k, v|
            newK = event.get("#{k}Label")
            if newK
                event.set(newK, v)
                event.remove(k)
                event.remove("#{k}Label"
            end
        }
    '
}
```

---

<div class="post-metadata">

**Author:** ![timshaw](https://avatars.discourse-cdn.com/v4/letter/t/9fc29f/32.png) [@timshaw](https://discuss.elastic.co/u/timshaw)\
**Post date:** [April 18, 2021, 8:45pm UTC](https://discuss.elastic.co/t/mutate-using-the-value-of-one-field-to-set-the-name-of-another/270462/4 "2021-04-18T20:45:22Z")

</div>

Mea culpa. Apologies. It works just fine - I had simply failed to eliminate the spaces from the label value and thus the intended field name was invalid. So for the record - although you may well be able to do this with ruby code, it is not necessary and you cannot rely on using fixed strings because CEF is an extensible format so different events may well - and in my case certainly do - have different values for the same label field for different events. Anyway problem solved, thanks for the replies and apologies for wasting your time!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 16, 2021, 8:45pm UTC](https://discuss.elastic.co/t/mutate-using-the-value-of-one-field-to-set-the-name-of-another/270462/5 "2021-05-16T20:45:45Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
