# Rename json field from the mongo log with filebeat processor

**URL:** <https://discuss.elastic.co/t/rename-json-field-from-the-mongo-log-with-filebeat-processor/338111>\
**Category:** Beats\
**Tags:** elastic-stack-monitoring, filebeat\
**Created:** [July 11, 2023, 1:52pm UTC](https://discuss.elastic.co/t/rename-json-field-from-the-mongo-log-with-filebeat-processor/338111 "2023-07-11T13:52:29Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![slashlinux](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/slashlinux/32/79430_2.png) [@slashlinux](https://discuss.elastic.co/u/slashlinux)\
**Post date:** [July 11, 2023, 1:52pm UTC](https://discuss.elastic.co/t/rename-json-field-from-the-mongo-log-with-filebeat-processor/338111/1 "2023-07-11T13:52:29Z")

</div>

Hi guys,

I'm trying to use the official website documentation for filebeat renaming field from the json but doesn't work so I ve decided to post here what i ve done and learn more about my mistake. I want to rename for example the field "s" to "severity" and "i" to "info".

**The json example:**

{

```auto
* "took":1,
* "timed_out":false,
* "_shards":{},
* "hits":{
  * "total":{
    * "value":490,
    * "relation":"eq"},
  * "max_score":1.0,
  * "hits":[
    1. {
      * "_index":"filebeat-7.10.2-2023.07.11-000001",
      * "_type":"_doc",
      * "_id":"orEURYkBcFrHMc1Pavyg",
      * "_score":1.0,
      * "_source":{
        * "@timestamp":"2023-07-11T13:11:50.211Z",
        * "attr":{},
        * "message":"{\"t\":{\"$date\":\"2023-07-11T03:20:02.253+00:00\"},\"s\":\"I\", \"c\":\"CONTROL\", \"id\":20721, \"ctx\":\"SignalHandler\",\"msg\":\"Process Details\",\"attr\":{\"pid\":\"1509\",\"port\":27018,\"architecture\":\"64-bit\",\"host\":\"mongoserver\"}}",
        * "agent":{},
        * "c":"CONTROL",
        * "s":"I",
        * "log":{
          * "offset":0,
          * "file":{
            * "path":"/tmp/mongod.log"}},
        * "host":{
          * "name":"ecs-basic"},
        * "t":{
          * "$date":"2023-07-11T03:20:02.253+00:00"},

```

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/a/1/a17fdd1a6dae5fd695941d0b14c65c1fa9d0abc9.png)

**My filebeat.yml looks like:**

```auto
processors:
  - rename:
      fields:
        - from: "hits.hits._source.s"
          to: "hits.hits._source.severity"
      ignore_missing: false
      fail_on_error: true

```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 8, 2023, 3:53pm UTC](https://discuss.elastic.co/t/rename-json-field-from-the-mongo-log-with-filebeat-processor/338111/2 "2023-08-08T15:53:04Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
