# Help with nested fields

**URL:** <https://discuss.elastic.co/t/help-with-nested-fields/161255>\
**Category:** Logstash\
**Created:** [December 18, 2018, 7:15am UTC](https://discuss.elastic.co/t/help-with-nested-fields/161255 "2018-12-18T07:15:02Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![LoZio](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/lozio/32/25946_2.png) [@LoZio](https://discuss.elastic.co/u/LoZio)\
**Post date:** [December 18, 2018, 7:15am UTC](https://discuss.elastic.co/t/help-with-nested-fields/161255/1 "2018-12-18T07:15:02Z")

</div>

Hi, I searched the forums with no success, hope someone can help me. I have a CSV from a feedback system, that gives me a CSV like this:

Field1; Field2; Field3; Field4;  
Value1; Val2-1,Val2-2; Val3; Val4-1, Val4-2, Val4-3  
Value1; Val2-1; Val3-1, Val3-2; Val4-1, Val4-2, Val4-3

Basically:  
FieldX are my headers, fixed.  
The values are separated with ";" and inside each value _may_ appear more than one value, separated by ",".  
In the first line of the example, Field2 has two values and only one in the following line.  
In the second row Field4 contains 3 values as in the first line.

I would like to obtain a structured data set, to be able to query/group for single values inside the fields:

> ```
> {
> "Field1": "Value1",
> "Field2": ["Val2-1", "Val2-2"],
> "Field3": ...
> }
> 
> ```

Think about F2 as Countries, F3 as Interests and so on. Multiple choices in the form.  
Hope I was clear enough.  
Thank you

---

<div class="post-metadata">

**Author:** ![HARSH\_GOYAL](https://avatars.discourse-cdn.com/v4/letter/h/a9adbd/32.png) [@HARSH\_GOYAL](https://discuss.elastic.co/u/HARSH_GOYAL)\
**Post date:** [December 18, 2018, 7:18am UTC](https://discuss.elastic.co/t/help-with-nested-fields/161255/2 "2018-12-18T07:18:34Z")

</div>

You can use a CsvFilter

filter {  
csv {  
add\_field =\> {  
"field1" =\> "Hello world, from %{host}"  
"field2" =\> "new\_static\_value"  
}  
}  
}

Also You can remove the used columns using remove\_field after you have created these new fields

---

<div class="post-metadata">

**Author:** ![LoZio](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/lozio/32/25946_2.png) [@LoZio](https://discuss.elastic.co/u/LoZio)\
**Post date:** [December 18, 2018, 7:53am UTC](https://discuss.elastic.co/t/help-with-nested-fields/161255/3 "2018-12-18T07:53:40Z")

</div>

Wow, it was easier than I thought! Logstash packs a lot of power.  
You just need to CSV input the "main" fields (FieldX), then for those fields who can contain multiple values just use Split as  
mutate {  
split =\> ["Field1", ","]  
}

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 15, 2019, 8:04am UTC](https://discuss.elastic.co/t/help-with-nested-fields/161255/4 "2019-01-15T08:04:05Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
