# Elasticsearch array of an object using logstash

**URL:** <https://discuss.elastic.co/t/elasticsearch-array-of-an-object-using-logstash/314295>\
**Category:** Logstash\
**Created:** [September 13, 2022, 12:37pm UTC](https://discuss.elastic.co/t/elasticsearch-array-of-an-object-using-logstash/314295 "2022-09-13T12:37:27Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![Hamza\_Khalid](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/hamza_khalid/32/103313_2.png) [@Hamza\_Khalid](https://discuss.elastic.co/u/Hamza_Khalid)\
**Post date:** [September 13, 2022, 12:37pm UTC](https://discuss.elastic.co/t/elasticsearch-array-of-an-object-using-logstash/314295/1 "2022-09-13T12:37:27Z")

</div>

I have a mysql database working as a primary database and i'm ingesting data into elasticsearch from mysql using logstash. I have successfully indexed the users table into elasticsearch and it is working perfectly fine however, my users table has fields interest\_id and interest\_name which contains the ids and names of user interests as follows:

"interest\_id" : "1,2",  
"interest\_name" : "Business,Farming"

**What i'm trying to achieve:**  
I want to make an object of interests and this object should contain array of interest ids and interests\_names like so:

interests : {  
[  
"interest\_name" : "Business"  
"interest\_id" : "1"  
],  
[  
"interest\_name" : "Farming"  
"interest\_id" : "2"  
]  
}

**Please let me know if its possible and also what is the best approach to achieve this.**

**My conf:**  
input {  
jdbc {  
jdbc\_driver\_library =\> "/home/logstash-7.16.3/logstash-core/lib/jars/mysql-connector-java-8.0.22.jar"  
jdbc\_driver\_class =\> "com.mysql.jdbc.Driver"  
jdbc\_connection\_string =\> "jdbc:mysql://localhost:3306/"  
jdbc\_user =\> "XXXXX"  
jdbc\_password =\> "XXXXXXX"  
sql\_log\_level =\> "debug"  
clean\_run =\> true  
record\_last\_run =\> false  
statement\_filepath =\> "/home/logstash-7.16.3/config/queries/query.sql"  
}  
}

filter {  
mutate {  
remove\_field =\> ["@version", "@timestamp",]  
}  
}  
output {  
elasticsearch {  
hosts =\> ["[https://XXXXXXXXXXXX:443](https://XXXXXXXXXXXX:443)"]  
index =\> "users"  
action =\> "index"  
user =\> "XXXX"  
password =\> "XXXXXX"  
template\_name =\> "myindex"  
template =\> "/home/logstash-7.16.3/config/my\_mapping.json"  
template\_overwrite =\> true  
}  
}

I have tried doing this by creating a nested field interests in my mapping and then adding mutate filer in my conf file like this:

mutate {  
rename =\> {  
"interest\_id" =\> "[interests][interest\_id]"  
"interest\_name" =\> "[interests][interest\_name]"  
}

**With this i'm only able to get this output:**  
"interests" : {  
"interest\_id" : "1,2",  
"interest\_name" : "Business,Farming"  
}

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 11, 2022, 12:38pm UTC](https://discuss.elastic.co/t/elasticsearch-array-of-an-object-using-logstash/314295/3 "2022-10-11T12:38:19Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
