# Filter mutate add\_field to create a nested field

**URL:** <https://discuss.elastic.co/t/filter-mutate-add-field-to-create-a-nested-field/357091>\
**Category:** Logstash\
**Created:** [April 9, 2024, 4:44pm UTC](https://discuss.elastic.co/t/filter-mutate-add-field-to-create-a-nested-field/357091 "2024-04-09T16:44:14Z")\
**Posts on this page:** 1\
**Showing post:** 2

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [April 9, 2024, 5:40pm UTC](https://discuss.elastic.co/t/filter-mutate-add-field-to-create-a-nested-field/357091/2 "2024-04-09T17:40:42Z")

</div>

You should be getting the error message

[2024-04-09T13:39:00,820][WARN][logstash.filters.mutate][main][8bc32b302327baed89200cd426ab77a8c3d27a62890a06a7d84f32da3b340613] Exception caught while applying mutate filter {:exception=\>"Could not set field 'userType' on object '%{[individual][user]}' to value 'SUBSCRIBER'.This is probably due to trying to set a field like [foo][bar] = someValuewhen [foo] is not either a map or a string"}

Your first mutate sets [user] to be a string, but your second mutate tries to make it an object with nested fields. You cannot do that. See [this](https://discuss.elastic.co/t/how-to-run-down-source-of-mutate-error/285500/3) thread.

---

_[View the full topic](https://discuss.elastic.co/t/filter-mutate-add-field-to-create-a-nested-field/357091)._
