# Error creating new field with the valu of a nested field

**URL:** <https://discuss.elastic.co/t/error-creating-new-field-with-the-valu-of-a-nested-field/301505>\
**Category:** Logstash\
**Created:** [April 4, 2022, 12:10pm UTC](https://discuss.elastic.co/t/error-creating-new-field-with-the-valu-of-a-nested-field/301505 "2022-04-04T12:10:01Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![S-elk](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/s-elk/32/98464_2.png) [@S-elk](https://discuss.elastic.co/u/S-elk)\
**Post date:** [April 4, 2022, 12:10pm UTC](https://discuss.elastic.co/t/error-creating-new-field-with-the-valu-of-a-nested-field/301505/1 "2022-04-04T12:10:01Z")

</div>

Hello!

im reciving a json with the next format:

```auto
    "field": [
      {
        "context": "CONTEXTLESS",
        "value": "x",
        "key": "subfield1"
      },
      {
        "context": "CONTEXTLESS",
        "value": "y",
        "key": "subfield2"
      },
      {
        "context": "CONTEXTLESS",
        "value": "z",
        "key": "subfield3"
      }`

```

im trying to change it to key:value format with this code:

```auto
  if [field.key] == ["x"]{
    mutate{
      add_field => { "%{[field][key]}" => "%{[field]{value]}"}
    }
  }

```

but it only works if i put something like:

```auto

  if [field.key] == ["x"]{
    mutate{
      add_field => { "%{[field][key]}" => "%{[field][0][value]}"}
    }
  }

```

does anyone have an idea?

Thank you in advanced!

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [April 4, 2022, 5:50pm UTC](https://discuss.elastic.co/t/error-creating-new-field-with-the-valu-of-a-nested-field/301505/2 "2022-04-04T17:50:09Z")

</div>

> [@S-elk](#):
>
> `[field.key] == ["x"]`

That should be `[field][key] == "subfield1"`.

---

<div class="post-metadata">

**Author:** ![S-elk](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/s-elk/32/98464_2.png) [@S-elk](https://discuss.elastic.co/u/S-elk)\
**Post date:** [April 5, 2022, 8:21am UTC](https://discuss.elastic.co/t/error-creating-new-field-with-the-valu-of-a-nested-field/301505/3 "2022-04-05T08:21:42Z")

</div>

Hi badger!

Thanks for answering me . Finally i was able to do it with this ruby ​​code:

```auto
    ruby {
      code => "
        event.get('[topField]').each do |item|
            event.set('[newField]['+item['key']+']', item['value'])
       end
      "
    }

```

this ruby code converts

```auto
topField{
  {
    "key": "field",
    "value": "value"
  }
}

```

to

`{ "newField.key.keyword": "value" }`

sometimes I get the following error:

```auto
[ERROR][logstash.filters.ruby] Ruby exception occurred: undefined method `each' for nil:NilClass 

```

does this occur when an empty value is entered?

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [April 5, 2022, 5:13pm UTC](https://discuss.elastic.co/t/error-creating-new-field-with-the-valu-of-a-nested-field/301505/4 "2022-04-05T17:13:26Z")

</div>

> [@S-elk](#):
>
> does this occur when an empty value is entered?

It happens if [topField] does not exist. You could change the ruby code to be

```
code => '
    topField = event.get("[topField]")
    if topField
        topField.each { |item|
            event.set("[newField][#{item['key']}]", item["value"])
        }
    end
'

```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 3, 2022, 5:13pm UTC](https://discuss.elastic.co/t/error-creating-new-field-with-the-valu-of-a-nested-field/301505/5 "2022-05-03T17:13:44Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
