# Rename field with filebeat

**URL:** <https://discuss.elastic.co/t/rename-field-with-filebeat/178064>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [April 23, 2019, 3:30pm UTC](https://discuss.elastic.co/t/rename-field-with-filebeat/178064 "2019-04-23T15:30:55Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![Raju\_Gupta](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/raju_gupta/32/42425_2.png) [@Raju\_Gupta](https://discuss.elastic.co/u/Raju_Gupta)\
**Post date:** [April 23, 2019, 3:30pm UTC](https://discuss.elastic.co/t/rename-field-with-filebeat/178064/1 "2019-04-23T15:30:56Z")

</div>

I am trying to rename non json field with filebeat but json field also getting renamed. Not sure what i am missing. Can some budy help me?

Here is my config.

```auto
setup.template.settings:
  index.number_of_shards: 1
  index.number_of_replicas: 1
  index.mapping.ignore_malformed: true
output.elasticsearch:
  hosts: ["localhost:9200"]
  indices:
    - index: "%{[fields.env]}-%{[fields.app]}-%{[fields.name]}-%{[fields.type]}-%{+yyyy.MM.dd}"

filebeat.inputs:
  ### API Trace
  - type: log
    fields:
      env: hello
      app: hi
      name: a
      type: trace
    paths:
      - /var/log/json/*.json
    json.ignore_decoding_error: true
    json.keys_under_root: true
    json.add_error_keys: true
    processors:
      - rename:
          fields:
           - from: "context"
             to: "context_str"
          ignore_missing: false
          fail_on_error: true
          when:
             not:
               equals:
                 regexp:
                   context: '^\{\}$'
      - decode_json_fields:
          fields: ["message", "context", "input", "body", "response", "content", "request"]
          process_array: true
          max_depth: 15

```

---

<div class="post-metadata">

**Author:** ![steffens](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/steffens/32/79630_2.png) [@steffens](https://discuss.elastic.co/u/steffens)\
**Post date:** [April 23, 2019, 9:48pm UTC](https://discuss.elastic.co/t/rename-field-with-filebeat/178064/2 "2019-04-23T21:48:00Z")

</div>

Do you have some sample input event?

---

<div class="post-metadata">

**Author:** ![Raju\_Gupta](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/raju_gupta/32/42425_2.png) [@Raju\_Gupta](https://discuss.elastic.co/u/Raju_Gupta)\
**Post date:** [April 23, 2019, 11:09pm UTC](https://discuss.elastic.co/t/rename-field-with-filebeat/178064/3 "2019-04-23T23:09:34Z")

</div>

context field with Json: `{ "@timestamp":"2019-04-23T16:33:16.045Z", "context":{"test1":"test1", "test":"test"} }`  
context field with nonjson: `{ "@timestamp":"2019-04-23T16:33:16.045Z", "context":["test|test|test|test|test"] }`

---

<div class="post-metadata">

**Author:** ![Phillip7631](https://avatars.discourse-cdn.com/v4/letter/p/e95f7d/32.png) [@Phillip7631](https://discuss.elastic.co/u/Phillip7631)\
**Post date:** [April 24, 2019, 9:04am UTC](https://discuss.elastic.co/t/rename-field-with-filebeat/178064/4 "2019-04-24T09:04:57Z")

</div>

there will be a `rename` processor in Beats. See [https://www.elastic.co/guide/en/beats/filebeat/master/rename-fields.html](https://www.elastic.co/guide/en/beats/filebeat/master/rename-fields.html).

But until that is released you need to use either Logstash or Ingest Node to rename [tellpopeyes](https://www.tellpopeyes.me/) fields.

- [https://www.elastic.co/guide/en/logstash/current/plugins-filters-mutate.html#plugins-filters-mutate-rename](https://www.elastic.co/guide/en/logstash/current/plugins-filters-mutate.html#plugins-filters-mutate-rename)
- [https://www.elastic.co/guide/en/elasticsearch/reference/current/rename-processor.html](https://www.elastic.co/guide/en/elasticsearch/reference/current/rename-processor.html)

---

<div class="post-metadata">

**Author:** ![Debashis](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/debashis/32/45290_2.png) [@Debashis](https://discuss.elastic.co/u/Debashis)\
**Post date:** [April 24, 2019, 11:25am UTC](https://discuss.elastic.co/t/rename-field-with-filebeat/178064/5 "2019-04-24T11:25:10Z")

</div>

@Raju_Gupta, Kindly provide the output you are getting during event publish. Which version of filebeat are you using?

---

<div class="post-metadata">

**Author:** ![Debashis](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/debashis/32/45290_2.png) [@Debashis](https://discuss.elastic.co/u/Debashis)\
**Post date:** [April 24, 2019, 11:28am UTC](https://discuss.elastic.co/t/rename-field-with-filebeat/178064/6 "2019-04-24T11:28:00Z")

</div>

@Phillip7631, From filebeat version 6.3 "rename" processor is already available.

---

<div class="post-metadata">

**Author:** ![steffens](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/steffens/32/79630_2.png) [@steffens](https://discuss.elastic.co/u/steffens)\
**Post date:** [April 24, 2019, 12:57pm UTC](https://discuss.elastic.co/t/rename-field-with-filebeat/178064/7 "2019-04-24T12:57:00Z")

</div>

The `context` field is a valid JSON object. You can not capture it as a string and rename, as it's already parsed. JSON support in filebeat parses the complete document as is. Reading your config I guess you assume all top-level fields still to be strings. This is not the case.

The `regexp.context` filter can not succeed, cause `regexp` condition looks for a string or an array of strings, yet you present it either an object or and array.

Your options are (one of):

- Drop the `context` field, so indexing works
- Create an Ingest Node pipeline with painless script to process the events. JSON can be parsed either in Beats or Ingest Node
- Enforce some stronger types/schema for the context fields

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 22, 2019, 12:57pm UTC](https://discuss.elastic.co/t/rename-field-with-filebeat/178064/8 "2019-05-22T12:57:02Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
