# Extract nested fields into new fields

**URL:** <https://discuss.elastic.co/t/extract-nested-fields-into-new-fields/209026>\
**Category:** Logstash\
**Created:** [November 22, 2019, 7:50am UTC](https://discuss.elastic.co/t/extract-nested-fields-into-new-fields/209026 "2019-11-22T07:50:26Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![a.kuz](https://avatars.discourse-cdn.com/v4/letter/a/b5ac83/32.png) [@a.kuz](https://discuss.elastic.co/u/a.kuz)\
**Post date:** [November 22, 2019, 7:50am UTC](https://discuss.elastic.co/t/extract-nested-fields-into-new-fields/209026/1 "2019-11-22T07:50:26Z")

</div>

Hi! I have json input like:

> **Summary**
>
> {  
> "Parameters": [  
> {  
> "Name": "SentTo",  
> "Value": "User User"  
> },  
> {  
> "Name": "BlindCopyTo",  
> "Value": "Username Username"  
> },  
> {  
> "Name": "Name",  
> "Value": "user\_to\_username"  
> },  
> {  
> "Name": "StopRuleProcessing",  
> "Value": "False"  
> },  
> {  
> "Name": "Mode",  
> "Value": "Enforce"  
> },  
> {  
> "Name": "Comments",  
> "Value": ""  
> },  
> {  
> "Name": "RuleErrorAction",  
> "Value": "Ignore"  
> },  
> {  
> "Name": "SenderAddressLocation",  
> "Value": "Header"  
> }  
> ],  
> },  
> }

I can access to those fields and extract them into new fields by:

> **Summary**
>
> mutate {  
> add\_field =\> { "[ParametersActionName]" =\> "%{[Parameters][0][Name]}" }  
> add\_field =\> { "[Parameters][ActionName]" =\> "%{[Parameters][0][Name]}" }  
> add\_field =\> { "[ParametersExt][ActionName]" =\> "%{[Parameters][0][Name]}" }  
> add\_field =\> { "[ParametersActionType]" =\> "%{[Parameters][0][Value]}" }  
> add\_field =\> { "[ParametersToType]" =\> "%{[Parameters][1][Name]}" }  
> add\_field =\> { "[ParametersRecipient]" =\> "%{[Parameters][1][Value]}" }  
> add\_field =\> { "[ParametersRuleName]" =\> "%{[Parameters][2][Name]}" }  
> add\_field =\> { "[ParametersRuleNameValue]" =\> "%{[Parameters][2][Value]}" }  
> add\_field =\> { "[ParametersRuleProcessing]" =\> "%{[Parameters][3][Name]}" }  
> add\_field =\> { "[ParametersIsStop]" =\> "%{[Parameters][3][Value]}" }  
> add\_field =\> { "[ParametersMode]" =\> "%{[Parameters][4][Name]}" }  
> add\_field =\> { "[ParametersActionMode]" =\> "%{[Parameters][4][Value]}" }  
> add\_field =\> { "[ParametersComments]" =\> "%{[Parameters][5][Name]}" }  
> add\_field =\> { "[ParametersCommentsVal]" =\> "%{[Parameters][5][Value]}" }  
> add\_field =\> { "[ParametersRuleError]" =\> "%{[Parameters][6][Name]}" }  
> add\_field =\> { "[ParametersRuleErrorAction]" =\> "%{[Parameters][6][Value]}" }  
> add\_field =\> { "[ParametersSenderAddressHeader]" =\> "%{[Parameters][7][Name]}" }  
> add\_field =\> { "[ParametersSenderAddressHeaderLocation]" =\> "%{[Parameters][7][Value]}" }  
> }

But it actual only on current event and number of fields as some fields in Parameters are changes. So, i want to make new fields depends on value of nested Name and Value, for example:

> **Summary**
>
> add\_field =\> { "[%{[Parameters][0][Name]}]" =\> "%{[Parameters][0][Value]}" } as SentTo: User User  
> add\_field =\> { "[%{[Parameters][1][Name]}]" =\> "%{[Parameters][1][Value]}" } as BlindCopyTo: Username Username  
> add\_field =\> { "[%{[Parameters][2][Name]}]" =\> "%{[Parameters][2][Value]}" } as Name: user\_to\_username

...  
How can i make a loop and accessing to index of Parameters?  
Thanks in Advance.

---

<div class="post-metadata">

**Author:** ![rameshkr1994](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rameshkr1994/32/59029_2.png) [@rameshkr1994](https://discuss.elastic.co/u/rameshkr1994)\
**Post date:** [November 22, 2019, 8:37am UTC](https://discuss.elastic.co/t/extract-nested-fields-into-new-fields/209026/2 "2019-11-22T08:37:48Z")

</div>

Hi @a.kuz.

i think you can do this withing elastic query!!!.

`same like sql query for concatenate your columns then and make as single column.`

Thanks  
HadoopHelp

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [November 22, 2019, 9:33am UTC](https://discuss.elastic.co/t/extract-nested-fields-into-new-fields/209026/3 "2019-11-22T09:33:23Z")

</div>

I would recommend you use the ruby filter.

---

<div class="post-metadata">

**Author:** ![a.kuz](https://avatars.discourse-cdn.com/v4/letter/a/b5ac83/32.png) [@a.kuz](https://discuss.elastic.co/u/a.kuz)\
**Post date:** [November 22, 2019, 10:46am UTC](https://discuss.elastic.co/t/extract-nested-fields-into-new-fields/209026/4 "2019-11-22T10:46:00Z")

</div>

That is a problem, i don't know how to do it with ruby

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [November 22, 2019, 2:30pm UTC](https://discuss.elastic.co/t/extract-nested-fields-into-new-fields/209026/5 "2019-11-22T14:30:16Z")

</div>

You could start with something like [this](https://discuss.elastic.co/t/solved-split-filter-question-a-k-a-flatten-json-sub-array/130481/12).

---

<div class="post-metadata">

**Author:** ![a.kuz](https://avatars.discourse-cdn.com/v4/letter/a/b5ac83/32.png) [@a.kuz](https://discuss.elastic.co/u/a.kuz)\
**Post date:** [November 25, 2019, 7:28am UTC](https://discuss.elastic.co/t/extract-nested-fields-into-new-fields/209026/6 "2019-11-25T07:28:23Z")

</div>

Solution is [here](https://discuss.elastic.co/t/logstash-xml-parsing-issues-trying-to-send-to-graylog-part-2/193209/3)  
@Badger thanks!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 23, 2019, 7:28am UTC](https://discuss.elastic.co/t/extract-nested-fields-into-new-fields/209026/7 "2019-12-23T07:28:29Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
