thx for answer.
behavior is the same with brackets.
strange is that it is working for action field with syntax mutate { rename => ["action" , "event.action"] }
additional info: action is the first key value pair in the data blob
This would be easier to debug if you posted the ruby debug output of an example event.
Are you sure that the field is actually called "dst" and not " dst" or something like that? (That would explain why the first one works and could easily be solved by the trim_key option in the kv filter)
Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant
logo are trademarks of the
Apache Software Foundation
in the United States and/or other countries.