# "unknown field \[pivot\]" error

**URL:** <https://discuss.elastic.co/t/unknown-field-pivot-error/381330>\
**Category:** Elasticsearch\
**Created:** [August 25, 2025, 10:42pm UTC](https://discuss.elastic.co/t/unknown-field-pivot-error/381330 "2025-08-25T22:42:54Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![meatwad](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/meatwad/32/36031_2.png) [@meatwad](https://discuss.elastic.co/u/meatwad)\
**Post date:** [August 25, 2025, 10:42pm UTC](https://discuss.elastic.co/t/unknown-field-pivot-error/381330/1 "2025-08-25T22:42:54Z")

</div>

Hi there,

I’m trying to follow along with this post to try and enrich FortiGate logs:

> [@Best practice for adding additional fields to transform](https://discuss.elastic.co/t/best-practice-for-adding-additional-fields-to-transform/379665):
>
> Hi community, I've created a custom transform job to extract Fortigate VPN events into custom index to get start / stop time. Sharing it below for reference. This is extracting data from fortigate integration so we already have the geo fields in the source data. I'm wondering that is the best practice for adding geoip fields to the data for client.ip? Is it recommended to add a new custom ingest pipeline that uses geoip processor on the client.ip field? PUT \_transform/fortivpntunnels/\_update…

But when I do the initial `POST _transform/fortivpntunnels/_update`, I get the following error:

```auto
{
  "error": {
    "root_cause": [
      {
        "type": "x_content_parse_exception",
        "reason": "[92:3] [data_frame_transform_config_update] unknown field [pivot]"
      }
    ],
    "type": "x_content_parse_exception",
    "reason": "[92:3] [data_frame_transform_config_update] unknown field [pivot]"
  },
  "status": 400
}

```

Is there something that needs enabling in my 8.14.2 install or what exactly do I need to do? Sorry for the stupid question but I appreciate the assistance!

---

<div class="post-metadata">

**Author:** ![Tortoise](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tortoise/32/147587_2.png) [@Tortoise](https://discuss.elastic.co/u/Tortoise)\
**Post date:** [August 26, 2025, 6:13am UTC](https://discuss.elastic.co/t/unknown-field-pivot-error/381330/2 "2025-08-26T06:13:34Z")

</div>

Hello @meatwad

As per documentation below is used to update a transform :

**POST/\_transform/{transform\_id}/\_update**

> **[Update a transform | Elasticsearch API documentation](https://www.elastic.co/docs/api/doc/elasticsearch/operation/operation-transform-update-transform)**
>
> Updates certain properties of a transform.
> All updated properties except description do not take effect until after the transform starts the next checkpoint,
> thus there is data ...

```auto
To create a transform we will have to use 
PUT _transform/fortivpntunnels
{
}

When you want to update the transform we use _update
POST _transform/fortivpntunnels/_update
{
}

But in this he has not used pivot field to update existing fields :

POST _transform/fortivpntunnels/_update
{
  "dest": {
    "index": "fortinet-vpn-tunnels",
    "pipeline": "add-client-geo"
  }
}

```

Thanks!!
