# Formatting jdbc-streaming filter result as a field instead of a list

**URL:** <https://discuss.elastic.co/t/formatting-jdbc-streaming-filter-result-as-a-field-instead-of-a-list/170305>\
**Category:** Logstash\
**Created:** [February 28, 2019, 9:34am UTC](https://discuss.elastic.co/t/formatting-jdbc-streaming-filter-result-as-a-field-instead-of-a-list/170305 "2019-02-28T09:34:23Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![yayun](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yayun/32/44085_2.png) [@yayun](https://discuss.elastic.co/u/yayun)\
**Post date:** [February 28, 2019, 9:34am UTC](https://discuss.elastic.co/t/formatting-jdbc-streaming-filter-result-as-a-field-instead-of-a-list/170305/1 "2019-02-28T09:34:23Z")

</div>

Hi,

I trying to enrich the log with data (username) from postgres by user id.  
However I didn't find a way to add the result as a field instead of a list. Is there a way to do so with the jdbc\_streaming filter?

Actual result:

```auto
{
  "id" => "id1",
  "username" => [
    [0] {
      "username" => "user1"
    } 
  ]
}

```

Desired format:

```auto
{
  "id" => "id1",
  "username" => "user1"
}

```

The current pipeline:

```auto
input {
  http {
  }
}

filter {
  jdbc_streaming {
    jdbc_driver_library => "/.../postgresql-42.2.5.jar"
    jdbc_driver_class => "org.postgresql.Driver"
    jdbc_connection_string => "jdbc:postgresql://..."
    jdbc_user => "..."
    jdbc_password => "..."
    statement => "select username from users where id = :id"
    parameters => { "id" => "id"}
    target => "username"
  }
}

output {
  stdout {}
}

```

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [February 28, 2019, 2:23pm UTC](https://discuss.elastic.co/t/formatting-jdbc-streaming-filter-result-as-a-field-instead-of-a-list/170305/2 "2019-02-28T14:23:19Z")

</div>

I believe that will always give you an array. You can replace the array with the first member using

```
mutate { replace => { "username" => "%{[username][0][username]}" } }
```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 28, 2019, 2:23pm UTC](https://discuss.elastic.co/t/formatting-jdbc-streaming-filter-result-as-a-field-instead-of-a-list/170305/3 "2019-03-28T14:23:20Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
