# Reingenst CSV to change field names

**URL:** <https://discuss.elastic.co/t/reingenst-csv-to-change-field-names/324219>\
**Category:** Kibana\
**Created:** [January 30, 2023, 11:05am UTC](https://discuss.elastic.co/t/reingenst-csv-to-change-field-names/324219 "2023-01-30T11:05:58Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![momoaux](https://avatars.discourse-cdn.com/v4/letter/m/7feea3/32.png) [@momoaux](https://discuss.elastic.co/u/momoaux)\
**Post date:** [January 30, 2023, 11:05am UTC](https://discuss.elastic.co/t/reingenst-csv-to-change-field-names/324219/1 "2023-01-30T11:05:58Z")

</div>

Hello, I'm new to ELK stack.

I have a lot of CSV files which share some common columns.  
But all have different names for their columns.

Example:  
File 1: Name, Type, Code  
File 2: TP, NM, CD  
File 3: Co,Ty,Na

My code needs to reference them with the same name, so I need to normalize the names on ingest (I think).

So I changed the column names on ingest to PRE\_NAME, PRE\_CODE, PRE\_TYPE

Now I made a mistake, forgot the underscore and ingested one as:  
PRENAME, PRECODE, PRETYPE

Is there a simple way to change that and reingest or do I always have to completely delete index and data view and recreate the whole thing again?

My examples are made easy but I have around 50 columns so recreating everytime is painfull.

greetings, Martin

---

<div class="post-metadata">

**Author:** ![Venkata\_Raja](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/venkata_raja/32/114264_2.png) [@Venkata\_Raja](https://discuss.elastic.co/u/Venkata_Raja)\
**Post date:** [January 31, 2023, 6:07am UTC](https://discuss.elastic.co/t/reingenst-csv-to-change-field-names/324219/2 "2023-01-31T06:07:31Z")

</div>

Hi Martin,

You can use rename processor in ingest pipeline and re-index api to achieve above.

1. Create a [Ingest pipeline](https://www.elastic.co/guide/en/elasticsearch/reference/current/ingest.html) with [rename](https://www.elastic.co/guide/en/elasticsearch/reference/current/rename-processor.html) processor and enter field names.
2. [Reindex](https://www.elastic.co/guide/en/elasticsearch/reference/8.6/docs-reindex.html#reindex-with-an-ingest-pipeline) the data into same indices by applying pipeline,

---

<div class="post-metadata">

**Author:** ![momoaux](https://avatars.discourse-cdn.com/v4/letter/m/7feea3/32.png) [@momoaux](https://discuss.elastic.co/u/momoaux)\
**Post date:** [February 2, 2023, 7:49am UTC](https://discuss.elastic.co/t/reingenst-csv-to-change-field-names/324219/3 "2023-02-02T07:49:56Z")

</div>

Hello, thank you for pointing me to the right methods.  
I tried to use the reindex.  
But if I try to use my index as source and dest, I get an error.  
How can I reindex the CSV again?  
I mean, how do I add it to the source of the \_reindex ?  
Sorry if I missed something in the docs but I cans find how to set a CSV as source.

I used Kibana Machine Learning File import to do the first import

Ah, maybe I have to import the file in a index without changing anything first like myFile\_native and then do a reindex into a new one like myFile\_foruse with my changes and use the myFile\_foruse in the application right?

---

<div class="post-metadata">

**Author:** ![Venkata\_Raja](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/venkata_raja/32/114264_2.png) [@Venkata\_Raja](https://discuss.elastic.co/u/Venkata_Raja)\
**Post date:** [February 2, 2023, 11:18am UTC](https://discuss.elastic.co/t/reingenst-csv-to-change-field-names/324219/4 "2023-02-02T11:18:44Z")

</div>

lets say you have your data in index1 currently , Just reindex by keeping index1 as source and index2(a new index) as a dest by applying pipeline.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 2, 2023, 11:19am UTC](https://discuss.elastic.co/t/reingenst-csv-to-change-field-names/324219/5 "2023-03-02T11:19:23Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
