# Extract data from nested json output and assign to new felids

**URL:** <https://discuss.elastic.co/t/extract-data-from-nested-json-output-and-assign-to-new-felids/361901>\
**Category:** Logstash\
**Created:** [June 23, 2024, 11:07am UTC](https://discuss.elastic.co/t/extract-data-from-nested-json-output-and-assign-to-new-felids/361901 "2024-06-23T11:07:31Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![vijjigani](https://avatars.discourse-cdn.com/v4/letter/v/3d9bf3/32.png) [@vijjigani](https://discuss.elastic.co/u/vijjigani)\
**Post date:** [June 23, 2024, 11:07am UTC](https://discuss.elastic.co/t/extract-data-from-nested-json-output-and-assign-to-new-felids/361901/1 "2024-06-23T11:07:31Z")

</div>

Dear team , i want to extract the details ,description,sourceDescription and map to other fields . here i am using the http\_poller plug in .i need the filter section , can anyone help here ?i have tried in multiple ways , but didnt worked .

{  
"incidents" =\> [  
[0] {  
"details" =\> "Entuity Server disconnected from network? ",  
"state" =\> "open",  
"objectKeyInfo" =\> {  
"swId" =\> 0,  
"compId" =\> {  
"ids" =\> [  
[0] 2048,  
[1] 2130706433,  
[2] 0,  
[3] 0  
]  
}  
},  
"eventCount" =\> 3,  
"timeStamp" =\> 1718275681,  
"extraAttribs" =\> nil,  
"severity" =\> 10,  
"sourceDescription" =\> "127.0.0.1",  
"impactDescription" =\> "",  
"id" =\> 4,  
"annotation" =\> nil,  
"description" =\> "Network Outage"  
},  
[1] {  
"details" =\> "Process [diskmonitor]",  
"state" =\> "open",  
"objectKeyInfo" =\> {  
"swId" =\> 0,  
"compId" =\> {  
"ids" =\> [  
[0] 4096,  
[1] 0,  
[2] 0,  
[3] 0  
]  
}  
},  
"eventCount" =\> 5,  
"timeStamp" =\> 1719111431,  
"extraAttribs" =\> nil,  
"severity" =\> 10,  
"sourceDescription" =\> "Entuity server DESKTOP-CE118LN",  
"impactDescription" =\> "",  
"id" =\> 6,  
"annotation" =\> nil,  
"description" =\> "Entuity Server Component Problem"  
},  
[2] {  
"details" =\> "ifIndex=16",  
"state" =\> "open",  
"objectKeyInfo" =\> {  
"swId" =\> 901,  
"compId" =\> {  
"ids" =\> [  
[0] 1,  
[1] 1,  
[2] 14,  
[3] 0  
]  
}  
},  
"eventCount" =\> 1,  
"timeStamp" =\> 1719123783,  
"extraAttribs" =\> nil,  
"severity" =\> 10,  
"sourceDescription" =\> "192.168.91.1 [wireless\_32768] Intel(R) Wi-Fi 6 AX201 160MHz",  
"impactDescription" =\> "",  
"id" =\> 19,  
"annotation" =\> nil,  
"description" =\> "Port Status Problem"  
},  
}

---

<div class="post-metadata">

**Author:** ![jessgarson](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jessgarson/32/129841_2.png) [@jessgarson](https://discuss.elastic.co/u/jessgarson)\
**Post date:** [June 25, 2024, 2:22pm UTC](https://discuss.elastic.co/t/extract-data-from-nested-json-output-and-assign-to-new-felids/361901/2 "2024-06-25T14:22:04Z")

</div>

Hi @vijjigani,

This [related post](https://discuss.elastic.co/t/logstash-how-to-extract-a-nested-field-from-json-log-and-only-index-the-content-of-the-nested-field/317617/3) on this subject could be helpful here.
