# Rename Field with \[\]

**URL:** <https://discuss.elastic.co/t/rename-field-with/305117>\
**Category:** Logstash\
**Created:** [May 19, 2022, 12:35am UTC](https://discuss.elastic.co/t/rename-field-with/305117 "2022-05-19T00:35:17Z")\
**Posts on this page:** 10\
**Page:** 1

<div class="post-metadata">

**Author:** ![cris](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/cris/32/101855_2.png) [@cris](https://discuss.elastic.co/u/cris)\
**Post date:** [May 19, 2022, 12:35am UTC](https://discuss.elastic.co/t/rename-field-with/305117/1 "2022-05-19T00:35:17Z")

</div>

Hello I want to rename some field without affect the other data. I tried with.

```auto
input {
    elasticsearch {
           hosts => "localhost:9200"
    index => "services"
    size => 1
    docinfo => true
    }
}
filter {
    mutate {
	rename => { "[Europe][Login[1]]" => "[Europe][Login]" }
    }
}
output {
    elasticsearch {
    hosts => "localhost:9200"
    index => "services"
    }
}

```

But I have problems because Logstash showme that the "Login[1]" has a Invalid FieldReference so I thing is for the part of the "[1]".  
How can I set this kind of field on logstash?

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [May 19, 2022, 1:32am UTC](https://discuss.elastic.co/t/rename-field-with/305117/2 "2022-05-19T01:32:14Z")

</div>

What does that field name look like if you go to the JSON tab after expanding an event in the Kibana Discover pane?

---

<div class="post-metadata">

**Author:** ![Rios](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rios/32/95745_2.png) [@Rios](https://discuss.elastic.co/u/Rios)\
**Post date:** [May 19, 2022, 6:44am UTC](https://discuss.elastic.co/t/rename-field-with/305117/3 "2022-05-19T06:44:15Z")

</div>

> [@cris](#):
>
> `[Europe][Login[1]]`

Try with: [Europe][Login][1]

Also you can rename field with [reindex](https://discuss.elastic.co/t/elasticsearch-rename-nested-fields-using-reindex/144956/2)

---

<div class="post-metadata">

**Author:** ![cris](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/cris/32/101855_2.png) [@cris](https://discuss.elastic.co/u/cris)\
**Post date:** [May 19, 2022, 8:41pm UTC](https://discuss.elastic.co/t/rename-field-with/305117/4 "2022-05-19T20:41:21Z")

</div>

it looks like this:

````auto
 "Europe: {
      "Login[1]": {
        "status": "passed"
      },```
````

---

<div class="post-metadata">

**Author:** ![cris](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/cris/32/101855_2.png) [@cris](https://discuss.elastic.co/u/cris)\
**Post date:** [May 19, 2022, 8:41pm UTC](https://discuss.elastic.co/t/rename-field-with/305117/5 "2022-05-19T20:41:54Z")

</div>

I tried but I get the same error, that the name is wrong

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [May 19, 2022, 9:13pm UTC](https://discuss.elastic.co/t/rename-field-with/305117/6 "2022-05-19T21:13:49Z")

</div>

I cannot test it since every method I have tried to create a field with that name results in an invalid field reference 😃 You could try

```
ruby {
    code => '
         login = event.remove("[Europe][Login[1]]")
         if login
             event.set("[Europe][login]", login)
         end
    '
}
```

---

<div class="post-metadata">

**Author:** ![cris](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/cris/32/101855_2.png) [@cris](https://discuss.elastic.co/u/cris)\
**Post date:** [May 19, 2022, 11:19pm UTC](https://discuss.elastic.co/t/rename-field-with/305117/7 "2022-05-19T23:19:44Z")

</div>

The same result I got a Invalid Reference

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [May 20, 2022, 12:36am UTC](https://discuss.elastic.co/t/rename-field-with/305117/8 "2022-05-20T00:36:21Z")

</div>

Then it may not be possible to do it in logstash itself. However, ingest pipelines have a [rename](https://www.elastic.co/guide/en/elasticsearch/reference/current/rename-processor.html) processor that might be able to do it. I do not run Elasticsearch myself, so I cannot test it. Perhaps @stephenb can speak to that.You can set the pipeline option on an Elasticsearch output to say which ingest pipeline should be used.

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [May 20, 2022, 6:04pm UTC](https://discuss.elastic.co/t/rename-field-with/305117/9 "2022-05-20T18:04:37Z")

</div>

> [@cris](#):
>
> `[Europe][Login[1]]`

> [@Badger](#):
>
> @stephenb can speak to that.You can set the pipeline option on an Elasticsearch output to say which ingest pipeline should be used.

I will take a look....

This works you would set this up (with your own pipeline name) then as @Badger indicated you can set the `pipeline => "my-pipeline"` setting in the logstash Elasticsearch output section

```auto
PUT _ingest/pipeline/discuss-test
{
  "processors": [
    {
      "rename": {
        "field": "test.field[1]",
        "target_field": "test.field"
      }
    }
  ]
}
  

POST _ingest/pipeline/discuss-test/_simulate
{
  "docs": [
    {
      "_source": {
        "test": {
          "field[1]": "test value"
        }
      }
    }
  ]
}

```

result

```auto
  "docs" : [
    {
      "doc" : {
        "_index" : "_index",
        "_id" : "_id",
        "_source" : {
          "test" : {
            "field" : "test value"
          }
        },
        "_ingest" : {
          "timestamp" : "2022-05-20T21:46:17.753381622Z"
        }
      }
    }
  ]
}

```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 17, 2022, 6:05pm UTC](https://discuss.elastic.co/t/rename-field-with/305117/10 "2022-06-17T18:05:13Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
