# Combine several fields using ruby/merge/aggregate

**URL:** <https://discuss.elastic.co/t/combine-several-fields-using-ruby-merge-aggregate/188747>\
**Category:** Logstash\
**Created:** [July 3, 2019, 2:33pm UTC](https://discuss.elastic.co/t/combine-several-fields-using-ruby-merge-aggregate/188747 "2019-07-03T14:33:57Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![akhilsharma.in](https://avatars.discourse-cdn.com/v4/letter/a/6f9a4e/32.png) [@akhilsharma.in](https://discuss.elastic.co/u/akhilsharma.in)\
**Post date:** [July 3, 2019, 2:33pm UTC](https://discuss.elastic.co/t/combine-several-fields-using-ruby-merge-aggregate/188747/1 "2019-07-03T14:33:57Z")

</div>

Below is the sample log which I get as an output:

{  
"field1": {  
--content--  
{},  
,  
}  
"field2": {  
--content--  
{},  
,  
}  
"field3": {  
--content--  
{},  
,  
}  
}

I want to combine all the fields so that I see output in one single field, like below -

{  
"OneField":  
{  
--content of field1 + field2 + field3--  
{},  
,  
}  
}

Please help out with an example. Would be great.

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [July 3, 2019, 3:03pm UTC](https://discuss.elastic.co/t/combine-several-fields-using-ruby-merge-aggregate/188747/2 "2019-07-03T15:03:08Z")

</div>

Can you provide examples that are valid JSON for both the input and result? It's really unclear what you want.

---

<div class="post-metadata">

**Author:** ![akhilsharma.in](https://avatars.discourse-cdn.com/v4/letter/a/6f9a4e/32.png) [@akhilsharma.in](https://discuss.elastic.co/u/akhilsharma.in)\
**Post date:** [July 5, 2019, 2:35pm UTC](https://discuss.elastic.co/t/combine-several-fields-using-ruby-merge-aggregate/188747/3 "2019-07-05T14:35:11Z")

</div>

Hi Badger - Below I have pasted one log. Please see:

{  
"winlog": {  
"opcode": "Info",  
"keywords": [  
"Audit Success"  
],  
"api": "wineventlog",  
"record\_id": 8217123,  
"event\_data": {  
"TargetDomainName": "Domain",  
"TargetUserName": "Patrik",  
"TargetUserSid": "S-1-5-21-2706447373-3929271640-2302363577-347960",  
"TargetLogonId": "0xc624c9e",  
"LogonType": "3"  
},  
"process": {  
"thread": {  
"id": 80452  
},  
"pid": 1408  
},  
"provider\_name": "Microsoft-Windows-Security-Auditing",  
"task": "Logoff",  
"computer\_name": "hostname",  
"provider\_guid": "{54849625-5478-4994-A5BA-3E3B0328C30D}",  
"channel": "Security",  
"event\_id": 4634  
},  
"@timestamp": "2019-07-03T14:46:57.188Z",  
"ecs": {  
"version": "1.0.0"  
},  
"log": {  
"level": "information"  
},  
"event": {  
"kind": "event",  
"code": 4634,  
"action": "Logoff",  
"created": "2019-07-03T14:47:07.060Z"  
},  
"message": "An account was logged off.\n\nSubject:\n\tSecurity ID:\t\tS-1-5-21-2706447373-3929271640-2302363577-347960\n\tAccount Name:\t\tpatrik\n\tAccount Domain:\t\t\n\tLogon ID:\t\t0xC624C9E\n\nLogon Type:\t\t\t3\n\nThis event is generated when a logon session is destroyed. It may be positively correlated with a logon event using the Logon ID value. Logon IDs are only unique between reboots on the same computer.",  
"@version": "1",  
"agent": {  
"version": "7.1.1",  
"ephemeral\_id": "679c7668-8bec-4026-9e94-87a9fbbe945f",  
"type": "winlogbeat",  
"id": "d7176a05-dd6b-41a7-80a2-0cf04fb9fd79",  
"hostname": "hostname"  
}  
}

Here we have got several fields:

1. winlog
2. ecs
3. event
4. @version
5. log
6. agent
7. message
8. @timestamp

I want to combine all these fields and make it as one field. Can you please help me with this requirement?

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [July 5, 2019, 2:39pm UTC](https://discuss.elastic.co/t/combine-several-fields-using-ruby-merge-aggregate/188747/4 "2019-07-05T14:39:18Z")

</div>

What do you mean by "make it one field"? Do you want to concatentate the strings? Concatentate with a separator? Make them an array? Insert them into a hash?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 2, 2019, 2:39pm UTC](https://discuss.elastic.co/t/combine-several-fields-using-ruby-merge-aggregate/188747/5 "2019-08-02T14:39:20Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
