# How to construct JSON using filter{} and input data?

**URL:** <https://discuss.elastic.co/t/how-to-construct-json-using-filter-and-input-data/294867>\
**Category:** Logstash\
**Created:** [January 19, 2022, 6:53pm UTC](https://discuss.elastic.co/t/how-to-construct-json-using-filter-and-input-data/294867 "2022-01-19T18:53:08Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![AshwinMS](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ashwinms/32/85362_2.png) [@AshwinMS](https://discuss.elastic.co/u/AshwinMS)\
**Post date:** [January 19, 2022, 6:53pm UTC](https://discuss.elastic.co/t/how-to-construct-json-using-filter-and-input-data/294867/1 "2022-01-19T18:53:08Z")

</div>

Hi , im new to logstash and found it to be super useful to loadup data from different sources to an es cluster ! But ive run into one problem which ive been stuck with for a while now and would really love some help.

Im trying to construct and store a json object in using the data from input and transformed in filter before sending them to my es output. I was following along this tutorial [How to keep Elasticsearch synced with a RDBMS using Logstash and JDBC | Elastic Blog](https://www.elastic.co/blog/how-to-keep-elasticsearch-synchronized-with-a-relational-database-using-logstash) .

Heres the gist of the transformation i want to perform. I would like to have a json object constructed using the input.  
Assuming the above mentioned tutorial is followed, and we have some more columns in rdbms table such as `DoB` ,data i want to load to es is as follows:

```auto
{
    "id": "123",
    "name": "John",
    "details": {
        "DoB": "01/01/2000",
    }
}

```

as i have defined my index mapping as below:

```auto
{
    "mappings": {
        "properties": {
            "id": {
                "type": "keyword"
            },
            "name": {
                "type": "search_as_you_type"
            },
            "details": {
                "properties": {
                    "DoB": {
                        "type": "date",
                    }
                }
            }
        }
    }
}

```

But when i tried to run my own logstash pipeline by adding this filter:

```auto
mutate {
        replace => {
            "DoB" => 
                { "DoB" => "%{DoB}" }
            
        }
    }

```

, i keep running into the following error:

```auto
"error"=>{"type"=>"mapper_parsing_exception", "reason"=>"object mapping for [details] tried to parse field [details] as object, but found a concrete value"}}}}

```

Is this not a desirable way to do index data on Elasticsearch ? Even so , how would one populate object type mapping on elastic using logstash? Would be super helpful if anyone could help me understand how to go about this.

---

<div class="post-metadata">

**Author:** ![Tomo\_M](https://avatars.discourse-cdn.com/v4/letter/t/848f3c/32.png) [@Tomo\_M](https://discuss.elastic.co/u/Tomo_M)\
**Post date:** [January 20, 2022, 4:19am UTC](https://discuss.elastic.co/t/how-to-construct-json-using-filter-and-input-data/294867/2 "2022-01-20T04:19:34Z")

</div>

The error looks about [details] field of output and nothing to do with the DoB replace pipline. Maybe you need to explain more about your pipeline.

---

<div class="post-metadata">

**Author:** ![AshwinMS](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ashwinms/32/85362_2.png) [@AshwinMS](https://discuss.elastic.co/u/AshwinMS)\
**Post date:** [January 20, 2022, 5:30pm UTC](https://discuss.elastic.co/t/how-to-construct-json-using-filter-and-input-data/294867/3 "2022-01-20T17:30:28Z")

</div>

yes , i agree. Just having a root level DoB field works just fine. The main problem i encounter is when i try to construct a object type using the input fields. I'm unable to achieve this.

---

<div class="post-metadata">

**Author:** ![aaron-nimocks](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/aaron-nimocks/32/73965_2.png) [@aaron-nimocks](https://discuss.elastic.co/u/aaron-nimocks)\
**Post date:** [January 20, 2022, 5:43pm UTC](https://discuss.elastic.co/t/how-to-construct-json-using-filter-and-input-data/294867/4 "2022-01-20T17:43:53Z")

</div>

When I see this issue it usually means 1 thing. You are trying to send data on a root level field that your mapping is not setup to receive.

So in your pipeline I think it's creating data that looks like this.

```auto
{
  "details": "some value", <--- this is the issue
  "details" : {
    "DoB": "some value"
  }
}

```

The error is saying you can't have a key/value for the field `details`. If you change your output to `stdout` and post a sample of that data and complete conf here it would help troubleshooting.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 17, 2022, 5:44pm UTC](https://discuss.elastic.co/t/how-to-construct-json-using-filter-and-input-data/294867/5 "2022-02-17T17:44:23Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
