# Rename Multiple Fields Using Pipeline Rule

**URL:** <https://community.graylog.org/t/rename-multiple-fields-using-pipeline-rule/10160>\
**Category:** Graylog Central (peer support)\
**Tags:** pipeline-rules\
**Created:** [April 26, 2019, 7:19pm UTC](https://community.graylog.org/t/rename-multiple-fields-using-pipeline-rule/10160 "2019-04-26T19:19:55Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![libertasfox](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/libertasfox/32/4310_2.png) [@libertasfox](https://community.graylog.org/u/libertasfox)\
**Post date:** [April 26, 2019, 7:19pm UTC](https://community.graylog.org/t/rename-multiple-fields-using-pipeline-rule/10160/1 "2019-04-26T19:19:55Z")

</div>

Greetings Grayloggers,

I’m really struggling to find a way to rename multiple field names. I’v scoured the support site but to no avail. I was wondering if anyone can point me in the right direction. I have a large list which I’ve reduced below, that I need to remove what essentially is a prefix from the field. I’m shipping this over via Beats from a Linux box using the Sidecar. It starts out as json so I’m using the “json.keys\_under\_root: true” and “json.add\_error\_key: true” to parse it prior to arriving in Graylog. When it arrives in Graylog, each line/field is populated with something like this:

remove\_this\_prefix\_agent\_red

I’ve used the pipeline code below but it only works on one line, not all.

* * *

## rule rule “remove\_this\_prefix\_ from fields” when has\_field(“remove\_this\_prefix\_red”) then rename\_field(“remove\_this\_prefix\_agent\_red”, “red”); end

What I’d like to be able to do is have a then statement that covers all of it but I’m not sure what code needs to go in “when” (see below). I’ve messed around with regex and other assorted ways to rename the field but I know I’m missing something.

* * *

rule “remove\_this\_prefix\_ from fields”

when  
What goes here???

## then rename\_field(“remove\_this\_prefix\_agent\_red”, “red”); rename\_field(“remove\_this\_prefix\_agent\_blue”, “blue”); rename\_field(“remove\_this\_prefix\_agent\_green”, “green”); rename\_field(“remove\_this\_prefix\_light\_blue”, “light\_blue”);

---

<div class="post-metadata">

**Author:** ![megan201296](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/megan201296/32/2847_2.png) [@megan201296](https://community.graylog.org/u/megan201296)\
**Post date:** [April 26, 2019, 10:27pm UTC](https://community.graylog.org/t/rename-multiple-fields-using-pipeline-rule/10160/2 "2019-04-26T22:27:21Z")

</div>

@libertasfox have you tried putting in the when field something like the source of the logs (or the input, etc etc) that contains those fields? Something like `$message.source == <source>`. The when section doesn’t have to reference the prefix fields at all, it just has to return “true” for any logs containing those fields you want to rename.

---

<div class="post-metadata">

**Author:** ![libertasfox](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/libertasfox/32/4310_2.png) [@libertasfox](https://community.graylog.org/u/libertasfox)\
**Post date:** [April 26, 2019, 11:20pm UTC](https://community.graylog.org/t/rename-multiple-fields-using-pipeline-rule/10160/3 "2019-04-26T23:20:21Z")

</div>

Hi Megan,  
Thank you!! I don’t know why I didn’t think of that but that worked perfectly! You saved my sanity rolling into this weekend. I really appreciate your help. Have a good one!

-Joe

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/flex016/uploads/graylog/original/3X/c/7/c7c09c6b5099570133d6502b83f50ba4430de5b6.png) [@system](https://community.graylog.org/u/system)\
**Post date:** [May 10, 2019, 11:29pm UTC](https://community.graylog.org/t/rename-multiple-fields-using-pipeline-rule/10160/4 "2019-05-10T23:29:57Z")

</div>

This topic was automatically closed 14 days after the last reply. New replies are no longer allowed.
