# Best Way to create nested field

**URL:** <https://discuss.elastic.co/t/best-way-to-create-nested-field/26757>\
**Category:** Logstash\
**Created:** [August 3, 2015, 10:42pm UTC](https://discuss.elastic.co/t/best-way-to-create-nested-field/26757 "2015-08-03T22:42:05Z")\
**Posts on this page:** 11\
**Page:** 1

<div class="post-metadata">

**Author:** ![DavidL](https://avatars.discourse-cdn.com/v4/letter/d/ecc23a/32.png) [@DavidL](https://discuss.elastic.co/u/DavidL)\
**Post date:** [August 3, 2015, 10:42pm UTC](https://discuss.elastic.co/t/best-way-to-create-nested-field/26757/1 "2015-08-03T22:42:06Z")

</div>

I successfully parsed out some fields, and am trying to aggregate some of them into one fields. Anyone suggestions on how to to that would be really appreciated. I haven't found a way to do so, but I assume this must be supported as nested JSON are commonly handled by elasticsearch. Thanks

for example:

status:\*\*\*  
action:###  
object:###  
path:\*\*\*

into

status:\*\*\*  
operation{  
action:###  
object:###  
}  
path:\*\*\*

Thanks!

---

<div class="post-metadata">

**Author:** ![pemontto](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/pemontto/32/3908_2.png) [@pemontto](https://discuss.elastic.co/u/pemontto)\
**Post date:** [August 4, 2015, 1:34am UTC](https://discuss.elastic.co/t/best-way-to-create-nested-field/26757/2 "2015-08-04T01:34:11Z")

</div>

Take a look at the syntax for [nested fields](https://www.elastic.co/guide/en/logstash/current/configuration.html#logstash-config-field-references). Then look at using [mutate](https://www.elastic.co/guide/en/logstash/current/plugins-filters-mutate.html#plugins-filters-mutate-rename) to rename the fields, for example:

```
filter {
  mutate {
    rename => { "action" => "[operation][action]" }
    rename => { "object" => "[operation][object]" }
  }
}

```

---

<div class="post-metadata">

**Author:** ![motodaddo](https://avatars.discourse-cdn.com/v4/letter/m/7993a0/32.png) [@motodaddo](https://discuss.elastic.co/u/motodaddo)\
**Post date:** [August 4, 2015, 1:58pm UTC](https://discuss.elastic.co/t/best-way-to-create-nested-field/26757/3 "2015-08-04T13:58:06Z")

</div>

Is it possible to do the same thing with the all body message?  
(without to to it for all single fields)  
Example:

"something1":"11111",  
"something2":"22222",  
"something3":"33333"

transform it in:

event{  
payload{  
"something1":"11111",  
"something2":"22222",  
"something3":"33333"  
}  
}

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [August 4, 2015, 2:08pm UTC](https://discuss.elastic.co/t/best-way-to-create-nested-field/26757/4 "2015-08-04T14:08:50Z")

</div>

Yes, but the stock filters don't have the kind of wildcard functionality that you'd need for that. You'll have to write a small snippet of Ruby and put it in a [ruby filter](https://www.elastic.co/guide/en/logstash/current/plugins-filters-ruby.html).

---

<div class="post-metadata">

**Author:** ![motodaddo](https://avatars.discourse-cdn.com/v4/letter/m/7993a0/32.png) [@motodaddo](https://discuss.elastic.co/u/motodaddo)\
**Post date:** [August 4, 2015, 2:14pm UTC](https://discuss.elastic.co/t/best-way-to-create-nested-field/26757/5 "2015-08-04T14:14:18Z")

</div>

i'm very new on ruby and logstash and i'm studying about it.  
Any suggestions?

thank you

---

<div class="post-metadata">

**Author:** ![DavidL](https://avatars.discourse-cdn.com/v4/letter/d/ecc23a/32.png) [@DavidL](https://discuss.elastic.co/u/DavidL)\
**Post date:** [August 4, 2015, 3:35pm UTC](https://discuss.elastic.co/t/best-way-to-create-nested-field/26757/6 "2015-08-04T15:35:31Z")

</div>

Thank you, this is confirmed to work !

---

<div class="post-metadata">

**Author:** ![DavidL](https://avatars.discourse-cdn.com/v4/letter/d/ecc23a/32.png) [@DavidL](https://discuss.elastic.co/u/DavidL)\
**Post date:** [August 4, 2015, 3:40pm UTC](https://discuss.elastic.co/t/best-way-to-create-nested-field/26757/7 "2015-08-04T15:40:21Z")

</div>

Daniele, I would start with watching the webinar and the "Get Started" section on the documentaiton page, it's what got me started! And If you run into questions, try googling first, I found more than half my answers from google around logstash, and you can always come back here if you don't find them on Google. I'm no expert like Magnus, but you can message me, and I'll do what I can to help. Good luck!

---

<div class="post-metadata">

**Author:** ![motodaddo](https://avatars.discourse-cdn.com/v4/letter/m/7993a0/32.png) [@motodaddo](https://discuss.elastic.co/u/motodaddo)\
**Post date:** [August 4, 2015, 3:44pm UTC](https://discuss.elastic.co/t/best-way-to-create-nested-field/26757/8 "2015-08-04T15:44:02Z")

</div>

Thank You so much for your advices.  
I wrote my previous question just because i didn't find nothing on the net.

---

<div class="post-metadata">

**Author:** ![juerkan](https://avatars.discourse-cdn.com/v4/letter/j/4491bb/32.png) [@juerkan](https://discuss.elastic.co/u/juerkan)\
**Post date:** [October 29, 2015, 1:35pm UTC](https://discuss.elastic.co/t/best-way-to-create-nested-field/26757/9 "2015-10-29T13:35:01Z")

</div>

Hi  
We have the Same Problem, have you a solution with the Ruby Code?  
Thank you very much  
Juergen

---

<div class="post-metadata">

**Author:** ![juerkan](https://avatars.discourse-cdn.com/v4/letter/j/4491bb/32.png) [@juerkan](https://discuss.elastic.co/u/juerkan)\
**Post date:** [November 4, 2015, 7:22pm UTC](https://discuss.elastic.co/t/best-way-to-create-nested-field/26757/10 "2015-11-04T19:22:11Z")

</div>

solved in:

> [@Field name cannot contain '.'](https://discuss.elastic.co/t/field-name-cannot-contain/33251/13):
>
> Hi, Thank you very much, it works. Just a little issue with more then one dot in a field -\> the ruby code replace just the first dot in a fieldname. But that is not really a problem, because i insert the ruby filter twice. many thanks juergen

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 5:24am UTC](https://discuss.elastic.co/t/best-way-to-create-nested-field/26757/11 "2017-07-06T05:24:02Z")

</div>


