# How to analyse nested fields?

**URL:** <https://discuss.elastic.co/t/how-to-analyse-nested-fields/325944>\
**Category:** Kibana\
**Created:** [February 20, 2023, 9:36am UTC](https://discuss.elastic.co/t/how-to-analyse-nested-fields/325944 "2023-02-20T09:36:23Z")\
**Posts on this page:** 1\
**Showing post:** 2

<div class="post-metadata">

**Author:** ![Amine16](https://avatars.discourse-cdn.com/v4/letter/a/13edae/32.png) [@Amine16](https://discuss.elastic.co/u/Amine16)\
**Post date:** [February 23, 2023, 3:28pm UTC](https://discuss.elastic.co/t/how-to-analyse-nested-fields/325944/2 "2023-02-23T15:28:45Z")

</div>

I had an answer from Customer Success Engineering team of ES. It confirms that nested field cannot be use as 'analysis' in Kibana Discover. This means that we cannot directly build visualizations based on Nested fields directly from the Discover dashboard.  
Two solutions recommended:

1/ The nested fields can be queried or returned as search results, and we can also build aggregations on top of it. The only drawback here is that nested queries might be slower, and visualizations involving nested fields need to be built in Kibana using [vega custom visualization](https://www.elastic.co/guide/en/kibana/current/vega.html). It is not as straightforward as building using Lens, but there is a step by step tutorial in the shared link on how to do so. In short it can still be analysed in any way we would need the nested fields for.  
==\> This solution seems to be complicated to build.

2/ An alternative is to restructure the JSON into a flatter one, which we can then build a search experience without using nested operations. This will create more efficiency in the long term as the search operations will be significantly cheaper.  
==\> this solution may be easier. I used a tool to flat the nested JSON and I had a lot of fields for each field like: "consultation\_1\_IRM\_0\_volumeFlair" and "consultation\_2\_IRM\_0\_volumeFlair" ...  
In Kibana, I should select all fields in relation with IRM.volumeFlair to do the analyse which it is a bad method. Each field will be treated separately while all consultation\_X\_IRM\_X\_volumeFlair fields refer to the same field which is consultation.IRM.volumeFlair.

The last solution is to generate different JSON files from one JSON file. In my example, I will generate MRI JSON file, treatement JSON file ex… for each patient JSON file. Which is not an optimized solution!

Let's take again the example of **group/user** used in ES website ([Nested field type | Elasticsearch Guide [8.6] | Elastic](https://www.elastic.co/guide/en/elasticsearch/reference/8.6/nested.html)).  
In this case, we will generate a JSON file for GROUPs and a JSON file for USERs. In consequence, we will have two indexes: **my\_index\_000001\_group** and **my\_index\_000001\_user**.

How to connect these two indexes in ES? Maybe by using an aliase or we can generate a common field like an ID?

How to generate a Kibana visualisation including two fields (one field from my\_index\_000001\_group and one field from my\_index\_000001\_user)?

For this example, is it possible to display all the **user.first** for **group : “fans”** using Kibana Discover tool?

Thank you in advance for your help!

---

_[View the full topic](https://discuss.elastic.co/t/how-to-analyse-nested-fields/325944)._
