# 2.3.4 - Adding Nested Fields to Events

**URL:** <https://discuss.elastic.co/t/2-3-4-adding-nested-fields-to-events/64252>\
**Category:** Logstash\
**Created:** [October 28, 2016, 6:52am UTC](https://discuss.elastic.co/t/2-3-4-adding-nested-fields-to-events/64252 "2016-10-28T06:52:31Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![dawiro](https://avatars.discourse-cdn.com/v4/letter/d/71e660/32.png) [@dawiro](https://discuss.elastic.co/u/dawiro)\
**Post date:** [October 28, 2016, 6:52am UTC](https://discuss.elastic.co/t/2-3-4-adding-nested-fields-to-events/64252/1 "2016-10-28T06:52:31Z")

</div>

Hi,  
I'm trying to add a k/v pair of type:

type.field.size

to events using the ruby filter and it is failing. My latest attempt looks like this:

```
ruby {
  code => "
    event.append({'document' =>{'message' => {'size' => event['message'].bytesize}}})
  "
}

```

Can someone clarify for me how I should be doing this?

Regards,  
David

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [October 28, 2016, 11:19am UTC](https://discuss.elastic.co/t/2-3-4-adding-nested-fields-to-events/64252/2 "2016-10-28T11:19:04Z")

</div>

Not sure why you're using append. I'd expect

```
event['document'] = {'message' => {'size' => event['message'].bytesize}}

```

to work (in Logstash 2.4 and earlier at least).

---

<div class="post-metadata">

**Author:** ![dawiro](https://avatars.discourse-cdn.com/v4/letter/d/71e660/32.png) [@dawiro](https://discuss.elastic.co/u/dawiro)\
**Post date:** [October 28, 2016, 2:18pm UTC](https://discuss.elastic.co/t/2-3-4-adding-nested-fields-to-events/64252/3 "2016-10-28T14:18:48Z")

</div>

It doesn't appear to be working although it's not logging errors either:

ruby {  
code =\> "  
event['document'] = {'message' =\> {'size' =\> event['message'].bytesize}}  
event['message'] = event['message'][0..1000]  
event['document'] = {'message' =\> {'action' =\> 'truncated'}}  
"  
}

"document.message.action" is working but "document.message.size" is not with no errors reported by logstash or on the es master node. Am I referencing the size of the message field properly?

---

<div class="post-metadata">

**Author:** ![dawiro](https://avatars.discourse-cdn.com/v4/letter/d/71e660/32.png) [@dawiro](https://discuss.elastic.co/u/dawiro)\
**Post date:** [October 30, 2016, 10:04am UTC](https://discuss.elastic.co/t/2-3-4-adding-nested-fields-to-events/64252/4 "2016-10-30T10:04:43Z")

</div>

I figured it out. Need to add size and action as part of the same update...

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 4:32am UTC](https://discuss.elastic.co/t/2-3-4-adding-nested-fields-to-events/64252/5 "2017-07-06T04:32:02Z")

</div>


