# How can a heavily nested JSON data structure be displayed/searched in Elasticsearch

**URL:** <https://discuss.elastic.co/t/how-can-a-heavily-nested-json-data-structure-be-displayed-searched-in-elasticsearch/245423>\
**Category:** Elasticsearch\
**Created:** [August 18, 2020, 1:08pm UTC](https://discuss.elastic.co/t/how-can-a-heavily-nested-json-data-structure-be-displayed-searched-in-elasticsearch/245423 "2020-08-18T13:08:35Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![siiman](https://avatars.discourse-cdn.com/v4/letter/s/a9adbd/32.png) [@siiman](https://discuss.elastic.co/u/siiman)\
**Post date:** [August 18, 2020, 1:08pm UTC](https://discuss.elastic.co/t/how-can-a-heavily-nested-json-data-structure-be-displayed-searched-in-elasticsearch/245423/1 "2020-08-18T13:08:35Z")

</div>

Hello, everyone,

I would like to know in general how a nested JSON data structure can most effectively be imported into Elasticsearch.  
I have read some posts on this topic and also tried the approaches with parent/child fields, nested fields, partially denormalized data structure and separate indexes. Unfortunately everything did not lead to the desired success so far.

For example I have the following structure:

```auto
{
  "CVE_Items" : [ {
    "cve" : {
      "data_type" : "CVE",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-1174"
      },
      "references" : {
        "reference_data" : [ {
          "url" : "",
          "name" : "",
          "refsource" : "",
          "tags" : ["Patch", "Vendor Advisory"]
        }, {
          "url" : "",
          "name" : "",
          "refsource" : "",
          "tags" : ["Vendor Advisory"]
        }, {
          "url" : "",
          "name" : "",
          "refsource" : "",
          "tags" : ["Vendor Advisory"]
        }, {
          "url" : "",
          "name" : "",
          "refsource" : "",
          "tags" : ["Exploit"]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : ""
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:debian:shadow:4.0.0:*:*:*:*:*:*:*",
          "vendor" : "debian",
          "version" : "4.0.0"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:debian:shadow:4.0.1:*:*:*:*:*:*:*",
          "vendor" : "debian",
          "version" : "4.0.1"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:debian:shadow:4.0.2:*:*:*:*:*:*:*",
          "vendor" : "debian",
          "version" : "4.0.2"
        } ]
      } ]
    },
    "publishedDate" : "2006-05-28T23:02Z",
    "lastModifiedDate" : "2020-08-11T17:09Z"
  }, {
    "cve" : {
      [...]
  } ]
}

```

The arrays `cpe_match` and `references` can contain about 50 entries.

Planned is a search/visualization for properties in the array `cpe_match` e.g. `vendor` and an output/aggreations of the related information of the uppermost JSON data structure or also from the array "references". Here, further filtering by properties (tags) should also be possible. (e.g. for `CVE_ID: XXX` a `Exploit` and `Patch` is given and `lastModifiedDate` was ...)  
The search should also be possible in reverse.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 15, 2020, 1:08pm UTC](https://discuss.elastic.co/t/how-can-a-heavily-nested-json-data-structure-be-displayed-searched-in-elasticsearch/245423/2 "2020-09-15T13:08:37Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
