# Handle Nested data in elasticsearch

**URL:** <https://discuss.elastic.co/t/handle-nested-data-in-elasticsearch/241401>\
**Category:** Elasticsearch\
**Created:** [July 16, 2020, 7:15am UTC](https://discuss.elastic.co/t/handle-nested-data-in-elasticsearch/241401 "2020-07-16T07:15:41Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![mathur7vidit](https://avatars.discourse-cdn.com/v4/letter/m/d07c76/32.png) [@mathur7vidit](https://discuss.elastic.co/u/mathur7vidit)\
**Post date:** [July 16, 2020, 7:15am UTC](https://discuss.elastic.co/t/handle-nested-data-in-elasticsearch/241401/1 "2020-07-16T07:15:41Z")

</div>

Hi All,

I have a json Input file where I have a field namely error. this error is basically nested and has 3 sub-fields namely error.message, error.stacktrace and error.class. Currently i am able to use filters with these 3 fields, but these 3 fields are not showing as a seperate field in kibana (under Available Fields in Kibana) and all these are showcasing under error field only. How this can be solved. My template is as below. ES version 7.4.2

```auto
{
  "evergreen-7.4.2" : {
    "order" : 3,
    "index_patterns" : [
      "test-*"
    ],
    "settings" : {
      "index" : {
        "lifecycle" : {
          "name" : "rollover",
          "rollover_alias" : "test-write-target"
        }
      }
    },
    "mappings" : {
      "dynamic" : true,
      "properties" : {
        "fields" : {
          "properties" : {
            "index_suffix" : {
              "type" : "keyword"
            },
            "cloudstack" : {
              "type" : "keyword"
            },
            "index" : {
              "type" : "keyword"
            }
          }
        },
        "error" : {
          "type" : "nested"
        },
        "timestamp" : {
          "type" : "date_nanos"
        }
      }
    },
    "aliases" : { }
  }
}

```

Sample log:

```auto
{"timestamp":"2020-07-14T02:00:04.462871Z","logging":{"level":"error","type":"app","name":"EnrollmentService","file_path":"/tmp/jetty-0_0_0_0-8080-evergreen-2020_07_13+1511-25f8472f_war-_-any-8444767333112902468.dir/webapp/WEB-INF/backend/helpers/diagnostics.rb","line":192,"thread":{"name":"rpc.poll"}},"message":"poller_error","context":{"tenant":"53aba09c-be06-11e9-bda3-0680c5280fdc"},"error":[{"class":"Circuitbox::FaradayMiddleware::RequestFailed","message":"Request failed: status(503) rate limit()","stacktrace":["/tmp/jetty-0_0_0_0-8080-evergreen-2020_07_13+1511-25f8472f_war-_-any-8444767333112902468.dir/webapp/WEB-INF/gems/gems/mdm-client-12.7.107/lib/mdm/client/open_circuit_response_middleware.rb:32:in `on_complete'","/tmp/jetty-0_0_0_0-8080-evergreen-2020_07_13+1511-25f8472f_war-_-any-8444767333112902468.dir/webapp/WEB-INF/gems/gems/faraday-0.17.3/lib/faraday/response.rb:9:in `block in call'""]}]}

```

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [July 21, 2020, 6:39am UTC](https://discuss.elastic.co/t/handle-nested-data-in-elasticsearch/241401/2 "2020-07-21T06:39:17Z")

</div>

Kibana [does not support nested mappings well](https://github.com/elastic/kibana/issues/1084) so if you want to work with Kibana my recommendation would be to avoid them.

---

<div class="post-metadata">

**Author:** ![mathur7vidit](https://avatars.discourse-cdn.com/v4/letter/m/d07c76/32.png) [@mathur7vidit](https://discuss.elastic.co/u/mathur7vidit)\
**Post date:** [July 21, 2020, 7:04am UTC](https://discuss.elastic.co/t/handle-nested-data-in-elasticsearch/241401/3 "2020-07-21T07:04:08Z")

</div>

Hi Christian,

correct. i found this same github issue raised. thanks anyways!! [https://github.com/elastic/kibana/issues/1084#issuecomment-585178079](https://github.com/elastic/kibana/issues/1084#issuecomment-585178079).

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 18, 2020, 7:04am UTC](https://discuss.elastic.co/t/handle-nested-data-in-elasticsearch/241401/4 "2020-08-18T07:04:28Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
