# Aggregate filter plugin does not create nested data in Elasticsearch

**URL:** <https://discuss.elastic.co/t/aggregate-filter-plugin-does-not-create-nested-data-in-elasticsearch/211996>\
**Category:** Logstash\
**Created:** [December 16, 2019, 11:37am UTC](https://discuss.elastic.co/t/aggregate-filter-plugin-does-not-create-nested-data-in-elasticsearch/211996 "2019-12-16T11:37:53Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![jtboing](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jtboing/32/59438_2.png) [@jtboing](https://discuss.elastic.co/u/jtboing)\
**Post date:** [December 16, 2019, 11:37am UTC](https://discuss.elastic.co/t/aggregate-filter-plugin-does-not-create-nested-data-in-elasticsearch/211996/1 "2019-12-16T11:37:53Z")

</div>

Hello, everyone. I've been using Logstash to move data from a MySQL server to Elasticsearch. It's been great so far, but I have run into some trouble when using the aggregate filter. Here's the data I'm using:

```
+----+----------------------------+----------------------+
| id | name | email |
+----+----------------------------+----------------------+
| 1 | Name_1 | email_1@email.com |
| 2 | Name_1 | email_2@email.com |
| 3 | Name_2 | NULL |
| 4 | Name_3 | NULL |
+----+----------------------------+----------------------+

```

Here's the Logstash filter

```
filter {
    aggregate {
        task_id => "%{id}"
        code => "
            map['id'] = event.get('id')
            map['name'] = event.get('name')
            map['emails'] ||= []
            map['emails'] << {'email' => event.get('email')}
        "
    }
}

```

The expected result that I would like to get is:

```auto
{
    "id" => 1,
    "emails" => {
        "email" => "email_1@email.com",
        "email" => "email_2@email.com"
    }
    "name" => "Name_1"
}
{
    "id" => 2,
    "emails" => {
        "email" => "null"
    }
    "name" => "Name_2"
}
{
    "id" => 3,
    "emails" => {
        "email" => "null"
    }
    "name" => "Name_3"
}

```

However, the result that I actually got was:

```auto
{
    "id" => 1,
    "email" => "email_1@email.com",
    "name" => "Name_1"
}
{
    "id" => 2,
    "email" => "null"
    "name" => "Name_2"
}
{
    "id" => 3,
    "email" => "null"
    "name" => "Name_3"
}

```

Any help and pointers on where I did wrong would be much appreciated. Thanks.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 13, 2020, 11:45am UTC](https://discuss.elastic.co/t/aggregate-filter-plugin-does-not-create-nested-data-in-elasticsearch/211996/2 "2020-01-13T11:45:25Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
