# Rename Field in Index (index, visu, dashboard, etc...)

**URL:** <https://discuss.elastic.co/t/rename-field-in-index-index-visu-dashboard-etc/159881>\
**Category:** Elasticsearch\
**Created:** [December 7, 2018, 8:37am UTC](https://discuss.elastic.co/t/rename-field-in-index-index-visu-dashboard-etc/159881 "2018-12-07T08:37:39Z")\
**Posts on this page:** 12\
**Page:** 1

<div class="post-metadata">

**Author:** ![GitsBdr](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/gitsbdr/32/58828_2.png) [@GitsBdr](https://discuss.elastic.co/u/GitsBdr)\
**Post date:** [December 7, 2018, 8:37am UTC](https://discuss.elastic.co/t/rename-field-in-index-index-visu-dashboard-etc/159881/1 "2018-12-07T08:37:39Z")

</div>

Hi all,  
Thanks in advance for the help!  
I want to rename a field in an index 'everywhere'. By everywhere, I mean that I don't want my graphs and dashboard based on this field to be impacted, I don't know if there is any possibility to do it.  
I found this like on the web : [https://stackoverflow.com/questions/43120430/elasticsearch-mapping-rename-existing-field](https://stackoverflow.com/questions/43120430/elasticsearch-mapping-rename-existing-field)  
It's using an Ingest pipeline, a Rename processor and the Reindex API but I don't want to create a new index because I have more than hundred graphs included in many dashboards (means : very long to update everything with the new name of my field)  
Thanks again for your help !  
Regards  
Guillaume

[EDIT] - quick edit just to say that i'm running elasticsearch 6.4.3 and also to say why do I want to rename a field. For the moment I have something like :

- logs before 10th Dec I have into them myOldFieldName = user1
- logs after 10th Dec I have into them myNewFieldName = user1  
and I'd like the same myNewFieldName = user1 for all my logs

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [December 7, 2018, 8:57am UTC](https://discuss.elastic.co/t/rename-field-in-index-index-visu-dashboard-etc/159881/2 "2018-12-07T08:57:12Z")

</div>

Would that help? [https://www.elastic.co/guide/en/elasticsearch/reference/6.4/alias.html](https://www.elastic.co/guide/en/elasticsearch/reference/6.4/alias.html)

---

<div class="post-metadata">

**Author:** ![GitsBdr](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/gitsbdr/32/58828_2.png) [@GitsBdr](https://discuss.elastic.co/u/GitsBdr)\
**Post date:** [December 7, 2018, 9:14am UTC](https://discuss.elastic.co/t/rename-field-in-index-index-visu-dashboard-etc/159881/3 "2018-12-07T09:14:25Z")

</div>

Hello @dadoonet and thank you for your answer,  
I will take a look at it as soon as I can but first of all, I didn't see your reply before editing my post.  
Did you see in my post the edit below :

> [@GitsBdr](#):
>
> [EDIT] - quick edit just to say that i'm running elasticsearch 6.4.3 and also to say why do I want to rename a field. For the moment I have something like :
> 
> - logs before 10th Dec I have into them myOldFieldName = user1
> - logs after 10th Dec I have into them myNewFieldName = user1  
> and I'd like the same myNewFieldName = user1 for all my logs

Many thanks

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [December 7, 2018, 9:27am UTC](https://discuss.elastic.co/t/rename-field-in-index-index-visu-dashboard-etc/159881/4 "2018-12-07T09:27:31Z")

</div>

I do see the edit.

---

<div class="post-metadata">

**Author:** ![GitsBdr](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/gitsbdr/32/58828_2.png) [@GitsBdr](https://discuss.elastic.co/u/GitsBdr)\
**Post date:** [December 10, 2018, 9:31am UTC](https://discuss.elastic.co/t/rename-field-in-index-index-visu-dashboard-etc/159881/5 "2018-12-10T09:31:16Z")

</div>

Hi @dadoonet and all,  
I've been reading the page that you told me but I'm not sure if it can work in my case ...  
My command GET /\_search returns :  
{  
"my-index-name":{  
"aliases":{},  
"mappings":{  
"spread\_doctype":{  
"properties":{  
"@timestamp":{  
"type":"date"  
},  
"@version":{  
"type":"text",  
"fields":{  
"keyword":{  
"type":"keyword",  
"ignore\_above":256  
}  
}  
},  
"my-old-field-name":{  
"type":"text",  
"fields":{  
"keyword":{  
"type":"keyword",  
"ignore\_above":256  
}  
}  
},  
"my-new-field-name":{  
"type":"text",  
"fields":{  
"keyword":{  
"type":"keyword",  
"ignore\_above":256  
}  
}  
}  
}  
}  
},  
"settings":{  
"index":{  
//some settings  
}  
}  
}  
}  
As you can see, my-old-field-name and my-new-field-name are two independent fields in this index but the old one for the old logs and the new one for the new logs. I don't want to create a third field as alias here, I just wanna merge these two fields into a unique one.  
Sorry If I'm not clear  
Thank you

---

<div class="post-metadata">

**Author:** ![xeraa](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/xeraa/32/48181_2.png) [@xeraa](https://discuss.elastic.co/u/xeraa)\
**Post date:** [December 10, 2018, 6:15pm UTC](https://discuss.elastic.co/t/rename-field-in-index-index-visu-dashboard-etc/159881/6 "2018-12-10T18:15:33Z")

</div>

1. Please format your code for better readability 🙂
2. While you are saying that this is the output of `GET /_search` it looks like a mapping to me?
3. You said earlier that "logs before 10th Dec I have into them myOldFieldName = user1". Do you have a daily / weekly / ... index pattern? Then you would just add the alias to indices before the 10th of December. If it's one big index you'll probably need to do an `_update_by_query` on all fields that don't have the field `myNewFieldName`. Shout if the query with the script to rename the field is not obvious. At the end of [https://www.elastic.co/guide/en/elasticsearch/reference/current/removal-of-types.html](https://www.elastic.co/guide/en/elasticsearch/reference/current/removal-of-types.html) there is a very similar script, but you won't need a full reindex — update by query on the old format will do it.

---

<div class="post-metadata">

**Author:** ![GitsBdr](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/gitsbdr/32/58828_2.png) [@GitsBdr](https://discuss.elastic.co/u/GitsBdr)\
**Post date:** [December 11, 2018, 9:32am UTC](https://discuss.elastic.co/t/rename-field-in-index-index-visu-dashboard-etc/159881/7 "2018-12-11T09:32:32Z")

</div>

Hi @xeraa and thanks for your time,

1. Sorry I really don't figure out how the formatted text works ....

2. Below the answer for GET /spread/\_mapping/ (you were right)  
{  
"my-index-name":{  
"aliases":{},  
"mappings":{  
"spread\_doctype":{  
"properties":{  
"@timestamp":{  
"type":"date"  
},  
"@version":{  
"type":"text",  
"fields":{  
"keyword":{  
"type":"keyword",  
"ignore\_above":256  
}  
}  
},  
"my-old-field-name":{  
"type":"text",  
"fields":{  
"keyword":{  
"type":"keyword",  
"ignore\_above":256  
}  
}  
},  
"my-new-field-name":{  
"type":"text",  
"fields":{  
"keyword":{  
"type":"keyword",  
"ignore\_above":256  
}  
}  
}  
}  
}  
},  
"settings":{  
"index":{  
//some settings  
}  
}  
}  
}

3. My logs are imported by logstash to elasticearch every minute from a csv file. Before this 10th Dec the header of this csv file was with myOldFieldName field and after this 10th Dec I modified this header with myNewFieldName. So now what happened ? My logs before and after this 10th Dec don't have the same field name for the same "attribute". It's very painful in the case I want to create a dashboard and apply a filter based on this field ...

So your solution would be to add an alias on my logs that don't already contain myNewFieldName ? What do you mean by "big index" ? Mine has almost 30M logs ... I won't get any issue by adding an alias with the same name than a real field name contained in other (newer) logs ?

Many thanks

---

<div class="post-metadata">

**Author:** ![xeraa](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/xeraa/32/48181_2.png) [@xeraa](https://discuss.elastic.co/u/xeraa)\
**Post date:** [December 11, 2018, 11:42am UTC](https://discuss.elastic.co/t/rename-field-in-index-index-visu-dashboard-etc/159881/8 "2018-12-11T11:42:05Z")

</div>

So the way I read this is that you have a single index `spread` with all the data, right? Then you will need the `_update_by_query` approach for the old data. Otherwise you'd have the mapping problem of colliding a concrete field and the alias field.

---

<div class="post-metadata">

**Author:** ![GitsBdr](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/gitsbdr/32/58828_2.png) [@GitsBdr](https://discuss.elastic.co/u/GitsBdr)\
**Post date:** [December 11, 2018, 3:29pm UTC](https://discuss.elastic.co/t/rename-field-in-index-index-visu-dashboard-etc/159881/9 "2018-12-11T15:29:43Z")

</div>

Yes I'm only interested on this index. It doesn't have any link with the others.  
Yeah totally

---

<div class="post-metadata">

**Author:** ![GitsBdr](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/gitsbdr/32/58828_2.png) [@GitsBdr](https://discuss.elastic.co/u/GitsBdr)\
**Post date:** [December 12, 2018, 1:48pm UTC](https://discuss.elastic.co/t/rename-field-in-index-index-visu-dashboard-etc/159881/10 "2018-12-12T13:48:49Z")

</div>

Hi,  
I hope you re doing well,  
I've found how to create an alias but not how to say that I want to create this alias for the logs before a specific date or where a field doesn't exist or exist ...

I mean, I would like to do :  
**_create my alias_**  
PUT myIndex  
{  
"mappings": {  
"\_doc": {  
"properties": {  
"myOldFieldName": {  
"type": "keyword"  
},  
"myNewFieldName": {  
"type": "alias",  
"path": "myOldFieldName"  
}  
}  
}  
}  
}  
**_only for those logs_**  
GET /myIndex/\_search  
{  
"query": {  
"range" : {  
"@timestamp": {  
"lte" : "dateOfTheUpdate"  
}  
}  
}  
}

---

<div class="post-metadata">

**Author:** ![xeraa](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/xeraa/32/48181_2.png) [@xeraa](https://discuss.elastic.co/u/xeraa)\
**Post date:** [December 12, 2018, 4:04pm UTC](https://discuss.elastic.co/t/rename-field-in-index-index-visu-dashboard-etc/159881/11 "2018-12-12T16:04:38Z")

</div>

1. Please format your code.
2. You are using an index alias. I think what you actually would need is a field alias if the new field doesn't exist anywhere yet:

```auto
DELETE field_alias

PUT field_alias/_doc/1
{
  "foo": "test"
}

GET field_alias/_mapping

GET field_alias/_search
{
  "query": {
    "match": {
      "bar": "test"
    }
  }
}

PUT field_alias/_mapping/_doc
{
  "properties": {
    "bar": {
      "type": "alias",
      "path": "foo"
    }
  }
}

GET field_alias/_mapping

GET field_alias/_search
{
  "query": {
    "match": {
      "bar": "test"
    }
  }
}

```

1. If the field already exists in the index you will need to run an update query (though this is relatively heavy depending on how many documents need to be reindexed):

```auto
DELETE update_index

PUT update_index/_doc/1
{
  "foo": "test"
}
PUT update_index/_doc/2
{
  "bar": "test"
}

GET update_index/_mapping

GET update_index/_search
{
  "query": {
    "match": {
      "foo": "test"
    }
  }
}

# This will fail with: mapper [bar] of different type, current_type [text], merged_type [FieldAliasMapper]
PUT update_index/_mapping/_doc
{
  "properties": {
    "bar": {
      "type": "alias",
      "path": "foo"
    }
  }
}

POST update_index/_update_by_query
{
  "query": {
    "bool": {
      "must": {
        "exists": {
          "field": "bar"
        }
      },
      "must_not": {
        "exists": {
          "field": "foo"
        }
      }
    }
  },
  "script": {
    "source": """
      ctx._source.foo = ctx._source.bar;
    """
  }
}

GET update_index/_search
{
  "query": {
    "match": {
      "foo": "test"
    }
  }
}

```

1. Depending on your scenario you could also solve the problem at query time by simply searching both fields:

```auto
DELETE query_time

PUT query_time/_doc/1
{
  "foo": "test"
}
PUT query_time/_doc/2
{
  "bar": "test"
}

GET query_time/_search
{
  "query": {
    "multi_match": {
      "query": "test",
      "fields": ["foo", "bar"]
    }
  }
}

```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 9, 2019, 4:04pm UTC](https://discuss.elastic.co/t/rename-field-in-index-index-visu-dashboard-etc/159881/12 "2019-01-09T16:04:43Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
