# Weird Bug, Field name is blocked, cant use the same name of field it in other pipelines

**URL:** <https://discuss.elastic.co/t/weird-bug-field-name-is-blocked-cant-use-the-same-name-of-field-it-in-other-pipelines/333890>\
**Category:** Logstash\
**Created:** [May 19, 2023, 9:02pm UTC](https://discuss.elastic.co/t/weird-bug-field-name-is-blocked-cant-use-the-same-name-of-field-it-in-other-pipelines/333890 "2023-05-19T21:02:30Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![ElasticLiver](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/elasticliver/32/64869_2.png) [@ElasticLiver](https://discuss.elastic.co/u/ElasticLiver)\
**Post date:** [May 19, 2023, 9:02pm UTC](https://discuss.elastic.co/t/weird-bug-field-name-is-blocked-cant-use-the-same-name-of-field-it-in-other-pipelines/333890/1 "2023-05-19T21:02:30Z")

</div>

Hi, I have a pipeline that stores the fields `memory_memused_per` and `memory_swapused_per` in an index , in another pipeline that stores data in another index I have tried to use the same name but nothing is indexed. after hours of debugging I just realize if I change the name to `mem_memused_per` and `mem_swapused_per` it works without problems, this is the ruby code:

```auto
        ruby {
          code => '
            log = event.get("status")
            mem_memused_per = log.scan(/Physical Memory Used\s*%=\s*(-?[\d.]+)/).flatten.first
            mem_swapused_per = log.scan(/Memoria Swap\s*%=\s*(-?[\d.]+)/).flatten.first

            event.set("memory_memused_per", mem_memused_per)
            event.set("memory_swapused_per", mem_swapused_per)

          '
        }

        mutate {
            convert => { "memory_memused_per" => "float" }
            convert => { "memory_swapused_per" => "float" }
      }

```

so if i just change the name of the field, and the mutate convert

```auto
            event.set("mem_memused_per", mem_memused_per)
            event.set("mem_swapused_per", mem_swapused_per)

```

the documents are indexed.

Any known bugs related to this?

Logstash 7.5

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [May 20, 2023, 12:25am UTC](https://discuss.elastic.co/t/weird-bug-field-name-is-blocked-cant-use-the-same-name-of-field-it-in-other-pipelines/333890/2 "2023-05-20T00:25:54Z")

</div>

Have you looked at the mappings?

Perhaps your original names have an incorrect mapping so the fields can not be stored

And when you changed the name you got a correct mapping and thus the can be stored

---

<div class="post-metadata">

**Author:** ![ElasticLiver](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/elasticliver/32/64869_2.png) [@ElasticLiver](https://discuss.elastic.co/u/ElasticLiver)\
**Post date:** [May 20, 2023, 1:18am UTC](https://discuss.elastic.co/t/weird-bug-field-name-is-blocked-cant-use-the-same-name-of-field-it-in-other-pipelines/333890/3 "2023-05-20T01:18:52Z")

</div>

Hi, thanks for you reply, so i create a new index with no mapping and add these lines to ruby so I can index fields that start with memory an the fields that start with mem, both from the same source:

```auto
           memory_memused_per = log.scan(/Physical Memory Used\s*%=\s*(-?[\d.]+)/).flatten.first
           memory_swapused_per = log.scan(/Memoria Swap\s*%=\s*(-?[\d.]+)/).flatten.first

            event.set("memory_memused_per", memory_memused_per)
            event.set("memory_swapused_per", memory_swapused_per)

            event.set("mem_memused_per", memory_memused_per)
            event.set("mem_swapused_per", memory_swapused_per)

```

the mapping response in devtools:

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/6/5/6524648e9ea9cfeb0b60d05d3f38563f3d4ee3df.png)

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/b/c/bc8862bb11e6ff55f921fb2d997e8d53b25271ae.png)

And then in Discover only the field mem\_memused\_per appears with data, both fields have the same source, and mapping

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/4/6/460a6f0f8bfc23345ef41be9330557dfb8e43655.png)

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [May 20, 2023, 1:33am UTC](https://discuss.elastic.co/t/weird-bug-field-name-is-blocked-cant-use-the-same-name-of-field-it-in-other-pipelines/333890/4 "2023-05-20T01:33:25Z")

</div>

Look at the source json in discover....

Is elasticsearch 7.5 as well?... _could be a bug._.. but seems awfully "weird" as you say  
7.5 is pretty old... any chance run a quick new elasticsearch?

---

<div class="post-metadata">

**Author:** ![ElasticLiver](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/elasticliver/32/64869_2.png) [@ElasticLiver](https://discuss.elastic.co/u/ElasticLiver)\
**Post date:** [May 20, 2023, 2:17am UTC](https://discuss.elastic.co/t/weird-bug-field-name-is-blocked-cant-use-the-same-name-of-field-it-in-other-pipelines/333890/5 "2023-05-20T02:17:18Z")

</div>

Oh...I feel very dumb right now, In the same pipeline was another ruby filter using the same field and parsing another type of log 🤦‍♂️, thanks for your anwers and sorry to waste your time brother.

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [May 20, 2023, 2:25am UTC](https://discuss.elastic.co/t/weird-bug-field-name-is-blocked-cant-use-the-same-name-of-field-it-in-other-pipelines/333890/6 "2023-05-20T02:25:50Z")

</div>

No worries... We've been running into a lot of these things. It's good to just have someone help you find them.

No waste of time. You're a good member of the community!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 17, 2023, 2:26am UTC](https://discuss.elastic.co/t/weird-bug-field-name-is-blocked-cant-use-the-same-name-of-field-it-in-other-pipelines/333890/7 "2023-06-17T02:26:49Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
