# Access to nested fields' values in logstash

**URL:** <https://discuss.elastic.co/t/access-to-nested-fields-values-in-logstash/362845>\
**Category:** Logstash\
**Created:** [July 10, 2024, 7:03am UTC](https://discuss.elastic.co/t/access-to-nested-fields-values-in-logstash/362845 "2024-07-10T07:03:40Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![sahere37](https://avatars.discourse-cdn.com/v4/letter/s/b2d939/32.png) [@sahere37](https://discuss.elastic.co/u/sahere37)\
**Post date:** [July 10, 2024, 7:03am UTC](https://discuss.elastic.co/t/access-to-nested-fields-values-in-logstash/362845/1 "2024-07-10T07:03:40Z")

</div>

Hi, I have these fields and values in my log in differnet lines::

line 1:  
date ==\> "z\_ac"  
z\_ac ==\> "2024-07"

line 2:  
date ==\> "z\_bc"  
z\_bc ==\> "2024-07"

line 3:  
date ==\> "z\_dc"  
z\_dc ==\> "2024-07"  
...............................................

and I want to used "date" to access to "2024-07", can i use nested field's values?

if I use %{%{date}} , the output will be %{%{date}}, while it is expected to be "2024-07"  
any guild will be so appreciated

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [July 10, 2024, 12:19pm UTC](https://discuss.elastic.co/t/access-to-nested-fields-values-in-logstash/362845/2 "2024-07-10T12:19:54Z")

</div>

I cannot think of a way to do it without using ruby

```
ruby { code => 'event.set("someField", event.get(event.get("date")))' }

```

---

<div class="post-metadata">

**Author:** ![sahere37](https://avatars.discourse-cdn.com/v4/letter/s/b2d939/32.png) [@sahere37](https://discuss.elastic.co/u/sahere37)\
**Post date:** [July 11, 2024, 7:21am UTC](https://discuss.elastic.co/t/access-to-nested-fields-values-in-logstash/362845/3 "2024-07-11T07:21:41Z")

</div>

thanks for your reply. it doesn't work . I used below code

```auto
   ruby { 
   code => 'event.set("MyDate", event.get(event.get("date")))' 
   }

```

and output is 'nil'

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [July 11, 2024, 10:04am UTC](https://discuss.elastic.co/t/access-to-nested-fields-values-in-logstash/362845/4 "2024-07-11T10:04:31Z")

</div>

The code works, but you may need to add error checking. For example,

```
input { generator { count => 1 lines => [
    '{ "date": "z_ac", "z_ac": "2024-07" }',
    '{ "date": "z_bc" }' ] codec => json }
}

output { stdout { codec => rubydebug { metadata => false } } }
filter {
    ruby { code => 'event.set("someField", event.get(event.get("date")))' }
}

```

will produce

```
{
"@timestamp" => 2024-07-11T10:02:19.930464180Z,
      "z_ac" => "2024-07",
 "someField" => "2024-07",
      "date" => "z_ac",
  "@version" => "1"
}
{
"@timestamp" => 2024-07-11T10:02:19.932857099Z,
 "someField" => nil,
      "date" => "z_bc",
  "@version" => "1"
}

```
