# Filter mutate add\_field to create a nested field

**URL:** <https://discuss.elastic.co/t/filter-mutate-add-field-to-create-a-nested-field/357091>\
**Category:** Logstash\
**Created:** [April 9, 2024, 4:44pm UTC](https://discuss.elastic.co/t/filter-mutate-add-field-to-create-a-nested-field/357091 "2024-04-09T16:44:14Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Armalyca](https://avatars.discourse-cdn.com/v4/letter/a/aeb1de/32.png) [@Armalyca](https://discuss.elastic.co/u/Armalyca)\
**Post date:** [April 9, 2024, 4:44pm UTC](https://discuss.elastic.co/t/filter-mutate-add-field-to-create-a-nested-field/357091/1 "2024-04-09T16:44:14Z")

</div>

Hello,  
I am new to logstash and I have a question about creating nested field with the add\_field filter

I use logstash 7.17.

I want to create a nested field from a string, but it doesn't work. The other way around (create a string from a nested array), it does work. Here is a snippet of my code :

```auto
mutate {
    replace => { 
        "user" => "%{[individual][user]}"
    }
}
mutate {
    add_field => {
        "[user][userType]" => "SUBSCRIBER"
    }
}

[...]

if (![user]) {
    drop {
        id => "No_user"
    }
} else if (![user][userType]) {
    drop {
        id => "No_userType"
    }
}

```

But this code drop with the id _No\_userType_  
I did this code following the documentation about [creating a field from a nested\_field](https://discuss.elastic.co/t/filter-mutate-add-field-from-nested-field/170231), and I also tried to create it inside the ruby plugin with event.set from the forum [here](https://discuss.elastic.co/t/add-nested-field-array-value-based-on-array-string/239286) but I have the same drop

Any help would be appreciated, thank you in advance

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [April 9, 2024, 5:40pm UTC](https://discuss.elastic.co/t/filter-mutate-add-field-to-create-a-nested-field/357091/2 "2024-04-09T17:40:42Z")

</div>

You should be getting the error message

[2024-04-09T13:39:00,820][WARN][logstash.filters.mutate][main][8bc32b302327baed89200cd426ab77a8c3d27a62890a06a7d84f32da3b340613] Exception caught while applying mutate filter {:exception=\>"Could not set field 'userType' on object '%{[individual][user]}' to value 'SUBSCRIBER'.This is probably due to trying to set a field like [foo][bar] = someValuewhen [foo] is not either a map or a string"}

Your first mutate sets [user] to be a string, but your second mutate tries to make it an object with nested fields. You cannot do that. See [this](https://discuss.elastic.co/t/how-to-run-down-source-of-mutate-error/285500/3) thread.

---

<div class="post-metadata">

**Author:** ![Armalyca](https://avatars.discourse-cdn.com/v4/letter/a/aeb1de/32.png) [@Armalyca](https://discuss.elastic.co/u/Armalyca)\
**Post date:** [April 10, 2024, 12:43pm UTC](https://discuss.elastic.co/t/filter-mutate-add-field-to-create-a-nested-field/357091/3 "2024-04-10T12:43:50Z")

</div>

Thank you for the response. The following code work :

```auto
mutate {
    replace=> {
        "[user][userType]" => "SUBSCRIBER"
    }
}

[...]

if (![user]) {
    drop {
        id => "No_user"
    }
} else if (![user][userType]) {
    drop {
        id => "No_userType"
    }
}

```
