# Rename nested field based on its data type

**URL:** <https://discuss.elastic.co/t/rename-nested-field-based-on-its-data-type/331044>\
**Category:** Logstash\
**Created:** [April 28, 2023, 10:18am UTC](https://discuss.elastic.co/t/rename-nested-field-based-on-its-data-type/331044 "2023-04-28T10:18:21Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![aversecguy](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/aversecguy/32/118572_2.png) [@aversecguy](https://discuss.elastic.co/u/aversecguy)\
**Post date:** [April 28, 2023, 10:18am UTC](https://discuss.elastic.co/t/rename-nested-field-based-on-its-data-type/331044/1 "2023-04-28T10:18:21Z")

</div>

Hello, dear community, I am brand new to logstash, but have to fix a problem:  
We are gathering eks audit logs and have errors like [illegal\_state\_exception](https://discuss.elastic.co/t/getting-illegal-state-exception-error-while-pushing-logs-to-elasticsearch/290029/1) error because of the field responseObject.status could be the type of string or object. I came up to define mapping for this field in elastic as oject and in logstash config rename responseObject.status field to responseObject.statusString e.g. if the value is string. The link above describe the possible solution, but i cant figure out how exactly to do it for nested field like in my case. Another question is that erros being genereted in json filter plugin, may I put the condition that i going to write before json filter plugin? Thanks in advance!  
The part of current config looks like:

```auto
input {
  cloudwatch_logs {
      log_group => ""
      region => "eu-central-1"
      role_arn => ""
      start_position => "end"
      type => "eks"
  }
}

# ========= Filter ========================
filter {
    if [type] == "eks"{
        mutate {
            convert => {"[responseObject][status]" => "string"}
            }
        json{
            source => "message"
            remove_field => "message"
            skip_on_invalid_json => true
        }
    }
}

```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 26, 2023, 10:19am UTC](https://discuss.elastic.co/t/rename-nested-field-based-on-its-data-type/331044/2 "2023-05-26T10:19:16Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
