# Rename dynamic nested field

**URL:** <https://discuss.elastic.co/t/rename-dynamic-nested-field/228827>\
**Category:** Logstash\
**Created:** [April 20, 2020, 9:38am UTC](https://discuss.elastic.co/t/rename-dynamic-nested-field/228827 "2020-04-20T09:38:04Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![banst](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/banst/32/66663_2.png) [@banst](https://discuss.elastic.co/u/banst)\
**Post date:** [April 20, 2020, 9:38am UTC](https://discuss.elastic.co/t/rename-dynamic-nested-field/228827/1 "2020-04-20T09:38:04Z")

</div>

Hello there,

Giving this event :

```auto
{
  field_name : "foo"
  nested: {
    foo: "bar"
  }
}

```

Is there a way with a mutate filter (or another solution) to transform it to :

```auto
{
  field_name : "foo"
  nested: {
    foo: "bar"
  }
  new_field: "bar"
}

```

Obviously the _foo_ property is dynamic, and that's what is causing me a headache. I tried with **rename** and **add\_field** , but didn't achieve my goal.

---

<div class="post-metadata">

**Author:** ![banst](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/banst/32/66663_2.png) [@banst](https://discuss.elastic.co/u/banst)\
**Post date:** [April 20, 2020, 10:58am UTC](https://discuss.elastic.co/t/rename-dynamic-nested-field/228827/2 "2020-04-20T10:58:27Z")

</div>

I found a working solution using ruby code.

_/usr/share/logstash/dynamic\_field\_rename.rb_

```ruby
def register(params)
	@from_field = params["from_field"]
	@path_in = params["path_in"]
	@set_field = params["set_field"]
end

def filter(event)
  path = event.get(@path_in)
  value = event.get(@from_field+path)
  event.set(@set_field, value)
  return [event]
end

test "dynamic rename" do
  parameters do
    {
      "from_field" => "[nested]",
      "path_in" => "[field_name]",
      "set_field" => "baz"
    }
  end

  in_event { { "field_name" => "[foo]", "nested" => { "foo" => "hello" } } }

  expect("add field") do |events|
    events[0].get("baz") == "hello"
  end
end

```

_/usr/share/logstash/pipeline/logstash.conf_

```auto
...
filter {
    ruby {
      path => "/usr/share/logstash/dynamic_field_rename.rb"
      script_params => { 
        "from_field" => "[nested]"
        "path_in" => "[field_name]"
        "set_field" => "baz"
      }
    }
}

```

I'am open to better solutions using built-in plugins like mutate if it exists.

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [April 20, 2020, 3:13pm UTC](https://discuss.elastic.co/t/rename-dynamic-nested-field/228827/3 "2020-04-20T15:13:03Z")

</div>

> [@banst](#):
>
> I'am open to better solutions using built-in plugins like mutate if it exists.

I think a ruby filter is the only way to do this.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 18, 2020, 3:13pm UTC](https://discuss.elastic.co/t/rename-dynamic-nested-field/228827/4 "2020-05-18T15:13:05Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
