# Dynamically move nested fields to the top level

**URL:** <https://discuss.elastic.co/t/dynamically-move-nested-fields-to-the-top-level/253504>\
**Category:** Logstash\
**Created:** [October 28, 2020, 12:02am UTC](https://discuss.elastic.co/t/dynamically-move-nested-fields-to-the-top-level/253504 "2020-10-28T00:02:44Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![jiacob](https://avatars.discourse-cdn.com/v4/letter/j/c6cbf5/32.png) [@jiacob](https://discuss.elastic.co/u/jiacob)\
**Post date:** [October 28, 2020, 12:02am UTC](https://discuss.elastic.co/t/dynamically-move-nested-fields-to-the-top-level/253504/1 "2020-10-28T00:02:44Z")

</div>

Hello,

I am trying to parse an XML message with lots of nested fields. I am using the XML filter to parse the data and send it to Elasticsearch. The issue that I am having is that the XML path to the value is too large.

For example, this is what is being shown in the Kibana discover: These are nested array fields

```auto
parsed.Invoices.Invoice.Header.InvoiceId
parsed.Invoices.Invoice.Receiver.CustomerInformation.CustomerName
parsed.Invoices.Invoice.Receiver.CustomerInformation.CustomerID
parsed.Invoices.Invoice.Receiver.CustomerInformation.Address.StreetAddress1
parsed.Invoices.Invoice.Rows.Row.RowNumber
parsed.Invoices.Invoice.Rows.Row.Product.ProductId

```

Is there a way to use the ruby filter to move these fields up such as below **without explicitly specifying each path in the ruby code**?

I would like it to be like:

```auto
Header.InvoiceId
CustomerInformation.CustomerName
CustomerInformation.CustomerID
Address.StreetAddress1
Row.RowNumber
Product.ProductId

```

This is what I have for the ruby code:

```auto
ruby {
    code => '
        event.get("parsed").each { |k, v|
            event.set(k,v)
        }
        event.remove("parsed")
    '
}

```

This will move everything just one level up such as below but still lost on how to move the rest of the fields up more levels **dynamically**.

```auto
   Invoices.Invoice.Header.InvoiceId
   Invoices.Invoice.Receiver.CustomerInformation.CustomerName

```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 25, 2020, 12:02am UTC](https://discuss.elastic.co/t/dynamically-move-nested-fields-to-the-top-level/253504/2 "2020-11-25T00:02:54Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
