# Rename strings field to nested field

**URL:** <https://discuss.elastic.co/t/rename-strings-field-to-nested-field/275912>\
**Category:** Logstash\
**Created:** [June 15, 2021, 12:12am UTC](https://discuss.elastic.co/t/rename-strings-field-to-nested-field/275912 "2021-06-15T00:12:46Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![frank\_rib](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/frank_rib/32/104372_2.png) [@frank\_rib](https://discuss.elastic.co/u/frank_rib)\
**Post date:** [June 15, 2021, 12:12am UTC](https://discuss.elastic.co/t/rename-strings-field-to-nested-field/275912/1 "2021-06-15T00:12:46Z")

</div>

Hello every body,  
I want to parse the logs bellow

> Apr 20 01:10:04 hostname sshproxy[150]: [SSH Session] session\_id="56454646eaeazjajflen" client\_ip="X.X.X.X" target\_ip="X.X.X.X" user="X.X.X.X" device="X.X.X.X" service="SSH" account="XXX" type="KBD\_INPUT" data="sudo -i"

The config file:

> filter{  
> grok{  
> match =\> {"message" =\> "%{SYSLOGBASE2} %{GREEDYDATA:syslog\_message}}  
> }  
> kv{  
> source =\> "syslog\_message"  
> value\_split =\> "=""  
> field\_split =\> ""\s"  
> }}

As output i had fields : (host, user,account, ...)  
How can i convert the host field to [host][name], the user to [user][name] and account to [user][name]

Best regards,

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [June 15, 2021, 12:21am UTC](https://discuss.elastic.co/t/rename-strings-field-to-nested-field/275912/2 "2021-06-15T00:21:06Z")

</div>

Use mutate+rename...

```
mutate {
    rename => {
        "[user]" => "[user][name]"
        "[host]" => "[host][name]"
        ...
    }
}
```

---

<div class="post-metadata">

**Author:** ![frank\_rib](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/frank_rib/32/104372_2.png) [@frank\_rib](https://discuss.elastic.co/u/frank_rib)\
**Post date:** [June 15, 2021, 8:26am UTC](https://discuss.elastic.co/t/rename-strings-field-to-nested-field/275912/3 "2021-06-15T08:26:30Z")

</div>

Hello badger,  
Thank-you for your prompt response, after renaming the [host] with [host][name] I get the error bellow :

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/1/7/17175ad2ba38a88e84b570226fe8f406d851c396.png)

And for the second one [user] with the [user][name] I had the result

![image](https://us1.discourse-cdn.com/elastic/original/3X/4/c/4ce538abdd4b59488d3d6fb8fa8912d798259f13.png)

The mutate filter

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/4/b/4b31c5f83eb82a239eb5de676ed425e20233c198.png)

Can you please help me to resolve those issues  
Best regard

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [June 15, 2021, 2:18pm UTC](https://discuss.elastic.co/t/rename-strings-field-to-nested-field/275912/4 "2021-06-15T14:18:31Z")

</div>

If you have indexed events where [host] is the hostname then you will need to switch to a new index if you want [host] to be an object with a [name] field inside it. A field on a document can be text or an object, but it cannot be one on some documents and the other on others.

---

<div class="post-metadata">

**Author:** ![frank\_rib](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/frank_rib/32/104372_2.png) [@frank\_rib](https://discuss.elastic.co/u/frank_rib)\
**Post date:** [June 15, 2021, 4:43pm UTC](https://discuss.elastic.co/t/rename-strings-field-to-nested-field/275912/5 "2021-06-15T16:43:27Z")

</div>

Hello Badger,

Thanks for the reply, Is it possible to convert the [host] field from text to objet? if yes how i can do it?

Best regards,

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [June 15, 2021, 4:44pm UTC](https://discuss.elastic.co/t/rename-strings-field-to-nested-field/275912/6 "2021-06-15T16:44:37Z")

</div>

In elasticsearch if a field has already been mapped as text it cannot be changed to an object without re-indexing the data into a different index.

---

<div class="post-metadata">

**Author:** ![frank\_rib](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/frank_rib/32/104372_2.png) [@frank\_rib](https://discuss.elastic.co/u/frank_rib)\
**Post date:** [June 15, 2021, 4:48pm UTC](https://discuss.elastic.co/t/rename-strings-field-to-nested-field/275912/7 "2021-06-15T16:48:00Z")

</div>

Thanks Badger i will try to re-index the data to a different index

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 13, 2021, 4:48pm UTC](https://discuss.elastic.co/t/rename-strings-field-to-nested-field/275912/8 "2021-07-13T16:48:57Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
