# Replace ip with hostname on data already indexed

**URL:** <https://discuss.elastic.co/t/replace-ip-with-hostname-on-data-already-indexed/77867>\
**Category:** Elasticsearch\
**Created:** [March 8, 2017, 6:02pm UTC](https://discuss.elastic.co/t/replace-ip-with-hostname-on-data-already-indexed/77867 "2017-03-08T18:02:04Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![Pete\_Del\_Rosso](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/pete_del_rosso/32/15548_2.png) [@Pete\_Del\_Rosso](https://discuss.elastic.co/u/Pete_Del_Rosso)\
**Post date:** [March 8, 2017, 6:02pm UTC](https://discuss.elastic.co/t/replace-ip-with-hostname-on-data-already-indexed/77867/1 "2017-03-08T18:02:04Z")

</div>

I am streaming sys logs to log stash. To make them more useful I added a dns filter so we can see machine name:

dns {  
reverse =\> ["remoteAddress"]  
action =\> "replace"  
}

This is working well. I want to update the existing "remoteAddress" fields and replace the IP with the host name. I have looked at the bulk update API and the update by query api and can't figure out how to do this. There's only a handful of values so i don't mind writing a couple of API requests by hand to do this.

Using the Dev Tool link in the Kibana UI, I have been trying something like this with no luck:

POST myindex/\_update\_by\_query  
{  
"query" : {  
"term" : {  
"remoteAddress" : { "1.2.3.4" }  
}  
}  
"replace" : {  
"doc" : {  
"remoteAddress" : { "myservername" }  
}  
}  
}

i have been looking online for simple examples to build my query with, no luck. Any help would be greatly appreciated.

Thanks,  
Pete 🙂

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [March 8, 2017, 7:42pm UTC](https://discuss.elastic.co/t/replace-ip-with-hostname-on-data-already-indexed/77867/2 "2017-03-08T19:42:33Z")

</div>

Does that query not work?

---

<div class="post-metadata">

**Author:** ![Pete\_Del\_Rosso](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/pete_del_rosso/32/15548_2.png) [@Pete\_Del\_Rosso](https://discuss.elastic.co/u/Pete_Del_Rosso)\
**Post date:** [March 8, 2017, 7:58pm UTC](https://discuss.elastic.co/t/replace-ip-with-hostname-on-data-already-indexed/77867/3 "2017-03-08T19:58:08Z")

</div>

this query:

POST http-access-cos/\_update\_by\_query  
{  
"query" : {  
"term" : {  
"remoteAddress" : { "127.0.0.1" }  
}  
}  
"replace" : {  
"doc" : {  
"remoteAddress" : { "localhost" }  
}  
}

returns:

{  
"error": {  
"root\_cause": [  
{  
"type": "json\_parse\_exception",  
"reason": "Unexpected character ('}' (code 125)): was expecting a colon to separate field name and value\n at [Source: org.elasticsearch.transport.netty4.ByteBufStreamInput@70c87ba0; line: 4, column: 34]"  
}  
],  
"type": "json\_parse\_exception",  
"reason": "Unexpected character ('}' (code 125)): was expecting a colon to separate field name and value\n at [Source: org.elasticsearch.transport.netty4.ByteBufStreamInput@70c87ba0; line: 4, column: 34]"  
},  
"status": 500  
}

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [March 8, 2017, 9:28pm UTC](https://discuss.elastic.co/t/replace-ip-with-hostname-on-data-already-indexed/77867/4 "2017-03-08T21:28:38Z")

</div>

> [@Pete\_Del\_Rosso](#):
>
> "remoteAddress" : { "127.0.0.1" }

Try `"remoteAddress" : "127.0.0.1"`.  
Same for the second `remoteAddress`.

---

<div class="post-metadata">

**Author:** ![Pete\_Del\_Rosso](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/pete_del_rosso/32/15548_2.png) [@Pete\_Del\_Rosso](https://discuss.elastic.co/u/Pete_Del_Rosso)\
**Post date:** [March 9, 2017, 5:21pm UTC](https://discuss.elastic.co/t/replace-ip-with-hostname-on-data-already-indexed/77867/5 "2017-03-09T17:21:34Z")

</div>

nope, is this documented somewhere? or is there a valid example we could reference?

POST http-access-cos/\_update\_by\_query  
{  
"query" : {  
"term" : {  
"remoteAddress" : "127.0.0.1"  
}  
}  
"replace" : {  
"doc" : {  
"remoteAddress" :"localhost"  
}  
}  
}

{  
"error": {  
"root\_cause": [  
{  
"type": "json\_parse\_exception",  
"reason": "Unexpected character ('"' (code 34)): was expecting comma to separate Object entries\n at [Source: org.elasticsearch.transport.netty4.ByteBufStreamInput@4c4f39f9; line: 7, column: 5]"  
}  
],  
"type": "json\_parse\_exception",  
"reason": "Unexpected character ('"' (code 34)): was expecting comma to separate Object entries\n at [Source: org.elasticsearch.transport.netty4.ByteBufStreamInput@4c4f39f9; line: 7, column: 5]"  
},  
"status": 500  
}

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 6, 2017, 5:22pm UTC](https://discuss.elastic.co/t/replace-ip-with-hostname-on-data-already-indexed/77867/6 "2017-04-06T17:22:28Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
