# Renaming Nested Objects

**URL:** <https://discuss.elastic.co/t/renaming-nested-objects/176885>\
**Category:** Logstash\
**Created:** [April 15, 2019, 10:49am UTC](https://discuss.elastic.co/t/renaming-nested-objects/176885 "2019-04-15T10:49:52Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![dawiro](https://avatars.discourse-cdn.com/v4/letter/d/71e660/32.png) [@dawiro](https://discuss.elastic.co/u/dawiro)\
**Post date:** [April 15, 2019, 10:49am UTC](https://discuss.elastic.co/t/renaming-nested-objects/176885/1 "2019-04-15T10:49:52Z")

</div>

Hi,  
If I have a field that is a dict-like object such as `[field\_1][field\_2][field\_3]' how can I rename 'field\_1' while leaving the sub-fields unchanged?

I have tried:

```auto
filter {
    mutate {
      rename => { "[field_1]" => "[renamed_field]" }
    }
}

```

But the field isn't renamed. What am I doing wrong?

Regards,  
D

---

<div class="post-metadata">

**Author:** ![dawiro](https://avatars.discourse-cdn.com/v4/letter/d/71e660/32.png) [@dawiro](https://discuss.elastic.co/u/dawiro)\
**Post date:** [April 16, 2019, 12:45pm UTC](https://discuss.elastic.co/t/renaming-nested-objects/176885/2 "2019-04-16T12:45:05Z")

</div>

Hi,  
Is there any way I can do this?

Regards,  
D

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [April 16, 2019, 1:01pm UTC](https://discuss.elastic.co/t/renaming-nested-objects/176885/3 "2019-04-16T13:01:57Z")

</div>

> [@dawiro](#):
>
> mutate { rename =\> { "[field\_1]" =\> "[renamed\_field]" } }

What you are doing should work. If I run

```
input { generator { count => 1 message => '' } }

filter {
    mutate { add_field => { "[field_1][field_2][field_3]" => "foo" } }
    mutate { rename => { "[field_1]" => "[renamed_field]" } }
}

```

then I get

```
"renamed_field" => {
    "field_2" => {
        "field_3" => "foo"
    }
},

```

---

<div class="post-metadata">

**Author:** ![dawiro](https://avatars.discourse-cdn.com/v4/letter/d/71e660/32.png) [@dawiro](https://discuss.elastic.co/u/dawiro)\
**Post date:** [April 16, 2019, 2:32pm UTC](https://discuss.elastic.co/t/renaming-nested-objects/176885/4 "2019-04-16T14:32:25Z")

</div>

@Badger Thanks. I'm trying to rename the host data object added by the `add_host_metadata` processor in filebeat 6.7.1 as the name clashes with other fields. However, the host object is being indexed unaltered which has me perplexed.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 14, 2019, 2:32pm UTC](https://discuss.elastic.co/t/renaming-nested-objects/176885/5 "2019-05-14T14:32:40Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
