# Can I rename Suricata fields in Eve.json. And where I can get all possible fields

**URL:** https://forum.suricata.io/t/can-i-rename-suricata-fields-in-eve-json-and-where-i-can-get-all-possible-fields/2055
**Category:** Help
**Created:** [December 24, 2021, 5:41am UTC](https://forum.suricata.io/t/can-i-rename-suricata-fields-in-eve-json-and-where-i-can-get-all-possible-fields/2055 "2021-12-24T05:41:09Z")
**Posts on this page:** 5
**Page:** 1

<div class="post-metadata">

### Author: ![ashokdev7](https://yyz2.discourse-cdn.com/flex030/user_avatar/forum.suricata.io/ashokdev7/32/1143_2.png) [@ashokdev7](https://forum.suricata.io/u/ashokdev7)
#### Post date: [December 24, 2021, 5:41am UTC](https://forum.suricata.io/t/can-i-rename-suricata-fields-in-eve-json-and-where-i-can-get-all-possible-fields/2055/1 "2021-12-24T05:41:09Z")

</div>

Hi ,  
I am creating a database using eve.json.  
I want to rename few fields in eve.json , Can I do that .  
If Yes , what’s the process .

Secondly not all fields are required at time but I want to include all the fields that eve.json can provide me so that in future if I enable something it doesn’t effect my database.  
Where I can get a list of all fields possible in eve.json.

Thanks

---

<div class="post-metadata">

### Author: ![Jeff\_Lucovsky](https://yyz2.discourse-cdn.com/flex030/user_avatar/forum.suricata.io/jeff_lucovsky/32/11_2.png) [@Jeff\_Lucovsky](https://forum.suricata.io/u/Jeff_Lucovsky)
#### Post date: [December 26, 2021, 8:07pm UTC](https://forum.suricata.io/t/can-i-rename-suricata-fields-in-eve-json-and-where-i-can-get-all-possible-fields/2055/2 "2021-12-26T20:07:34Z")

</div>

You could start by proposing the field name changes in the forum (with an appropriate title) as a first step to see what folks are thinking. It’s possible that more folks share your thoughts on field renames.

We don’t have a definitive list of field names except in the code. Look at the `output-json*.c` modules as well as source code modules in `rust/src/xxx/*.rs`.

Many (but not all) fields are established with a function like `jb_set_<type>` or `JB_SET` in the `src` directory (C code). There are many places in `rust/src` where fields are created (but the function used is different).

The JSON builder code is 100% rust – see `rust/src/jsonbuilder.rs`

---

<div class="post-metadata">

### Author: ![ish](https://yyz2.discourse-cdn.com/flex030/user_avatar/forum.suricata.io/ish/32/8_2.png) [@ish](https://forum.suricata.io/u/ish)
#### Post date: [December 26, 2021, 9:27pm UTC](https://forum.suricata.io/t/can-i-rename-suricata-fields-in-eve-json-and-where-i-can-get-all-possible-fields/2055/3 "2021-12-26T21:27:23Z")

</div>

There is a Suricata-Verify pull request that has an almost complete (if not complete) JSON schema of eve.json… The pull request is [GitHub ci jsonschema/v7 by catenacyber · Pull Request #590 · OISF/suricata-verify · GitHub](https://github.com/OISF/suricata-verify/pull/590)), but here’s a link to the schema file that will give you all the fields and possible data types: [suricata-verify/schema.json at c24bdd98c881af8f3e8a4d296d38872096bd5539 · OISF/suricata-verify · GitHub](https://github.com/OISF/suricata-verify/blob/c24bdd98c881af8f3e8a4d296d38872096bd5539/schema.json)

We don’t provide any ability to rename fields in Suricata itself, thats often best left to external tools…

With respect to storing eve records in a database, I’ve had good luck using the JSON datatypes in PostgreSQL and SQLite.

---

<div class="post-metadata">

### Author: ![pevma](https://yyz2.discourse-cdn.com/flex030/user_avatar/forum.suricata.io/pevma/32/29_2.png) [@pevma](https://forum.suricata.io/u/pevma)
#### Post date: [December 28, 2021, 12:46pm UTC](https://forum.suricata.io/t/can-i-rename-suricata-fields-in-eve-json-and-where-i-can-get-all-possible-fields/2055/4 "2021-12-28T12:46:46Z")

</div>

Also just for info, some fields can be dynamically generated - like for example the ones resulting from enabling the `dump-all-headers` option in http : [suricata/suricata.yaml.in at master · OISF/suricata · GitHub](https://github.com/OISF/suricata/blob/master/suricata.yaml.in#L209)

---

<div class="post-metadata">

### Author: ![IDSTower](https://yyz2.discourse-cdn.com/flex030/user_avatar/forum.suricata.io/idstower/32/861_2.png) [@IDSTower](https://forum.suricata.io/u/IDSTower)
#### Post date: [January 2, 2022, 6:20pm UTC](https://forum.suricata.io/t/can-i-rename-suricata-fields-in-eve-json-and-where-i-can-get-all-possible-fields/2055/5 "2022-01-02T18:20:53Z")

</div>

There are several option on how to modify the json output of Suricata, one common approach is to do this in the logshipper, for example [filebeat can rename fields](https://www.elastic.co/guide/en/beats/filebeat/current/rename-fields.html).

it all dep
