# Add Nested Field Value to a new field using Logstash Filter

**URL:** <https://discuss.elastic.co/t/add-nested-field-value-to-a-new-field-using-logstash-filter/239151>\
**Category:** Logstash\
**Created:** [June 29, 2020, 3:56pm UTC](https://discuss.elastic.co/t/add-nested-field-value-to-a-new-field-using-logstash-filter/239151 "2020-06-29T15:56:20Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![Kevin\_f](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kevin_f/32/72456_2.png) [@Kevin\_f](https://discuss.elastic.co/u/Kevin_f)\
**Post date:** [June 29, 2020, 3:56pm UTC](https://discuss.elastic.co/t/add-nested-field-value-to-a-new-field-using-logstash-filter/239151/1 "2020-06-29T15:56:20Z")

</div>

Hello All,

I hope someone here could help me as I have been stuck for days on this issue I am facing. I have got the kibana output as shown below:

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/1/8/187c3e3abca5c387d052b6b02c4135465e2641d3.png)

I am trying to add the nested field value of "key" into a new field called key. This is what I am trying to do using logstash filter:

```auto
filter {
   mutate {
       add_field => {
          "key" => "%{[properties][additionalDetails][key]}"
      }
   }
}

```

However the below is giving me the output:

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/0/4/040bc92d9b8662cd1fad5f26db53fb21999ac9d4.png)

Any ideas, where I am going wrong with this one? Any help would be much appreciated. Thanks.

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [June 29, 2020, 6:11pm UTC](https://discuss.elastic.co/t/add-nested-field-value-to-a-new-field-using-logstash-filter/239151/2 "2020-06-29T18:11:20Z")

</div>

It is inconceivable to me that

```
add_field => { "key" => "%{[properties][additionalDetails][key]}" }

```

would result in key being set to

```
"%{[properties.additionalDetails][key]}"

```

logstash is not going to replace the ][ with .

Most likely that mutate will work as is.

---

<div class="post-metadata">

**Author:** ![Kevin\_f](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kevin_f/32/72456_2.png) [@Kevin\_f](https://discuss.elastic.co/u/Kevin_f)\
**Post date:** [June 29, 2020, 6:26pm UTC](https://discuss.elastic.co/t/add-nested-field-value-to-a-new-field-using-logstash-filter/239151/3 "2020-06-29T18:26:09Z")

</div>

Hi Badger,

Thank you for coming back to me. Much appreciated

Sorry for the confusion. The last screenshot is incorrect. The actual output in Kibana is showing:

```auto
key "%{[properties][additionalDetails][key]}" 

```

instead of:

```auto
key User-Agent

```

I have edited my original post with the correct screenshot (error)

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [June 29, 2020, 6:40pm UTC](https://discuss.elastic.co/t/add-nested-field-value-to-a-new-field-using-logstash-filter/239151/4 "2020-06-29T18:40:00Z")

</div>

Can you run logstash with

```
output { stdout { codec => rubydebug } }

```

and show us that the [properties] field looks like?

---

<div class="post-metadata">

**Author:** ![Kevin\_f](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kevin_f/32/72456_2.png) [@Kevin\_f](https://discuss.elastic.co/u/Kevin_f)\
**Post date:** [June 29, 2020, 6:53pm UTC](https://discuss.elastic.co/t/add-nested-field-value-to-a-new-field-using-logstash-filter/239151/5 "2020-06-29T18:53:49Z")

</div>

Hi Badger,

Seems like I am not getting any console output with the debugging.

I have even done:

```auto
output {
  stdout {
      path => /var/log/logstash/tmp/ruby_output
      codec => rubydebug
 }
}

```

Still nothing in the file and looking in the logstash-plain.log, nothing related to stdout is in there. The last log just states "successfully started logstash API endpoint"

Even ran logstash as:  
/usr/share/logstash/bin/logstash -f /etc/logstash/conf.d/output.conf

and no joy with stdout

i can show you the json output of what kibana is showing me instead if that helps?

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/7/a/7a692a377c67d2502c28fd9cd59eede6c43dbb81.png)

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [June 29, 2020, 8:03pm UTC](https://discuss.elastic.co/t/add-nested-field-value-to-a-new-field-using-logstash-filter/239151/6 "2020-06-29T20:03:03Z")

</div>

The stdout output does not have a path output. Use a file output if you want to specify a path.

The JSON from kibana does tell me enough. Note that additionalDetails is an array. Try

```
add_field => { "key" => "%{[properties][additionalDetails][0][key]}" }
```

---

<div class="post-metadata">

**Author:** ![Kevin\_f](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kevin_f/32/72456_2.png) [@Kevin\_f](https://discuss.elastic.co/u/Kevin_f)\
**Post date:** [June 29, 2020, 8:26pm UTC](https://discuss.elastic.co/t/add-nested-field-value-to-a-new-field-using-logstash-filter/239151/7 "2020-06-29T20:26:14Z")

</div>

Hi Badger,

Ahhh perfect. That worked! Thank you.

I should have tried that before but instead I put it as:

```auto
add_field => { "key" => "%{[properties][additionalDetails][key][0]}" }

```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 27, 2020, 8:26pm UTC](https://discuss.elastic.co/t/add-nested-field-value-to-a-new-field-using-logstash-filter/239151/8 "2020-07-27T20:26:20Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
