# Why elasticsearch convert all my field name to lower case?

**URL:** <https://discuss.elastic.co/t/why-elasticsearch-convert-all-my-field-name-to-lower-case/134593>\
**Category:** Elasticsearch\
**Created:** [June 5, 2018, 11:00am UTC](https://discuss.elastic.co/t/why-elasticsearch-convert-all-my-field-name-to-lower-case/134593 "2018-06-05T11:00:18Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![ali1](https://avatars.discourse-cdn.com/v4/letter/a/76d3ee/32.png) [@ali1](https://discuss.elastic.co/u/ali1)\
**Post date:** [June 5, 2018, 11:00am UTC](https://discuss.elastic.co/t/why-elasticsearch-convert-all-my-field-name-to-lower-case/134593/1 "2018-06-05T11:00:19Z")

</div>

hello,

i create the following index :

```
PUT testindex 
{
  "mappings": {
    "datai": { 
      "properties": { 
        "firsName": { "type": "text" }, 
	    "lastName": { "type": "text" },
        "phoneNumber": { "type": "text" }			
      }
    }
  }
}

```

and i want the "N" letter in upper case , but when i got my data from a DB using logstash , elasticsearch convert all my field name to lower case , is this normal ?

this the result when i try to get data :

```
{
	"_index": "testindex",
	"_type": "datai",
	"_id": "12",
	"_version": 1,
	"found": true,
		"_source": {
		"firstname": "my firstname",
		"lastname": "my lastname",
		"phonenumber": "0989888",
		"@version": "1",
		"@timestamp": "2018-06-05T10:41:18.098Z"
		}
}

```

ther is any tips to force elasticsearch to respect my fileds name ?

this my sql query executed by logstash (i'm using oracle DB:

`select firstname "firsName", lastname "lastName", phonenumber "phoneNumber" from my table`

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [June 5, 2018, 11:21am UTC](https://discuss.elastic.co/t/why-elasticsearch-convert-all-my-field-name-to-lower-case/134593/2 "2018-06-05T11:21:14Z")

</div>

Elasticsearch never alters the `_source` field. Which means that Logstash basically sent something like:

```auto
{
	"firstname": "my firstname",
	"lastname": "my lastname",
	"phonenumber": "0989888",
	"@version": "1",
	"@timestamp": "2018-06-05T10:41:18.098Z"
}

```

Probably something to solve on Logstash side.

---

<div class="post-metadata">

**Author:** ![ali1](https://avatars.discourse-cdn.com/v4/letter/a/76d3ee/32.png) [@ali1](https://discuss.elastic.co/u/ali1)\
**Post date:** [June 5, 2018, 11:52am UTC](https://discuss.elastic.co/t/why-elasticsearch-convert-all-my-field-name-to-lower-case/134593/3 "2018-06-05T11:52:25Z")

</div>

thank you for your response , do you have any idea on how to resolve this on Logstash Side ?

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [June 5, 2018, 12:29pm UTC](https://discuss.elastic.co/t/why-elasticsearch-convert-all-my-field-name-to-lower-case/134593/4 "2018-06-05T12:29:41Z")

</div>

No. I don't know what you did.

---

<div class="post-metadata">

**Author:** ![ali1](https://avatars.discourse-cdn.com/v4/letter/a/76d3ee/32.png) [@ali1](https://discuss.elastic.co/u/ali1)\
**Post date:** [June 5, 2018, 1:07pm UTC](https://discuss.elastic.co/t/why-elasticsearch-convert-all-my-field-name-to-lower-case/134593/5 "2018-06-05T13:07:41Z")

</div>

I solve the problem by renaming my fileds in logstash filter

```
filter {
  mutate {
  
	rename => {
				  "firstname" => "firsName"
				  "lastname" => "lastName"
				  "phonenumber" => "phoneNumber"
				
         }
	
  }
}

```

good luck

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [June 5, 2018, 1:23pm UTC](https://discuss.elastic.co/t/why-elasticsearch-convert-all-my-field-name-to-lower-case/134593/6 "2018-06-05T13:23:28Z")

</div>

But can you share your input part of the logstash configuration?  
The problem you described might indicate a bug.

---

<div class="post-metadata">

**Author:** ![ali1](https://avatars.discourse-cdn.com/v4/letter/a/76d3ee/32.png) [@ali1](https://discuss.elastic.co/u/ali1)\
**Post date:** [June 5, 2018, 2:21pm UTC](https://discuss.elastic.co/t/why-elasticsearch-convert-all-my-field-name-to-lower-case/134593/7 "2018-06-05T14:21:08Z")

</div>

i follow this tutorial : [https://www.elastic.co/blog/logstash-jdbc-input-plugin](https://www.elastic.co/blog/logstash-jdbc-input-plugin)

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [June 5, 2018, 2:57pm UTC](https://discuss.elastic.co/t/why-elasticsearch-convert-all-my-field-name-to-lower-case/134593/8 "2018-06-05T14:57:38Z")

</div>

But I don't see UpperCase / LowerCase `SELECT` clauses in logstash configurations there.

So again, please share your Logstash configuration.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 3, 2018, 2:57pm UTC](https://discuss.elastic.co/t/why-elasticsearch-convert-all-my-field-name-to-lower-case/134593/9 "2018-07-03T14:57:46Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
