# How to dynamically move nested key value to root level

**URL:** <https://discuss.elastic.co/t/how-to-dynamically-move-nested-key-value-to-root-level/180006>\
**Category:** Logstash\
**Created:** [May 7, 2019, 2:30pm UTC](https://discuss.elastic.co/t/how-to-dynamically-move-nested-key-value-to-root-level/180006 "2019-05-07T14:30:54Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![arefeh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/arefeh/32/45732_2.png) [@arefeh](https://discuss.elastic.co/u/arefeh)\
**Post date:** [May 7, 2019, 2:30pm UTC](https://discuss.elastic.co/t/how-to-dynamically-move-nested-key-value-to-root-level/180006/1 "2019-05-07T14:30:54Z")

</div>

This is my logstash config file:

```
input {
   http {
    id => bulkHttpInput
    port => 8088
    additional_codecs => {"application/json" => "es_bulk"}
    codec => es_bulk
  }
}
filter {
  mutate {
    remove_field => ["headers"] 
  }
}
output {
  elasticsearch {
   id => elasticOutputOfHttp
   index => "%{[@metadata][_index]}"
   document_type => "%{[@metadata][_type]}"
   document_id => "%{[doc][docID]}"
   doc_as_upsert => "true"
  }
}

```

and the output is like :  
{  
"host" =\> "127.0.0.1",  
"@timestamp" =\> 2019-05-07T14:22:58.364Z,  
"@version" =\> "1",  
"doc" =\> {  
"field1" =\> "my\_field1",  
"field2" =\> "my\_field2",  
"field3" =\> "my\_field3"  
}  
}

I wanna move all fields within doc to root level. This is possible by defining `add_field` and move all nesteds fields from `doc` but field names are dynamic for-example "field4" may be added and some other fields may be removed . How to do it dynamically?

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [May 7, 2019, 3:14pm UTC](https://discuss.elastic.co/t/how-to-dynamically-move-nested-key-value-to-root-level/180006/2 "2019-05-07T15:14:28Z")

</div>

```
    ruby {
        code => '
            event.get("doc").each { |k, v|
                event.set(k,v)
            }
            event.remove("doc")
        '
    }
```

---

<div class="post-metadata">

**Author:** ![arefeh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/arefeh/32/45732_2.png) [@arefeh](https://discuss.elastic.co/u/arefeh)\
**Post date:** [May 8, 2019, 4:56am UTC](https://discuss.elastic.co/t/how-to-dynamically-move-nested-key-value-to-root-level/180006/3 "2019-05-08T04:56:31Z")

</div>

It works,  
Thank you

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 5, 2019, 5:02am UTC](https://discuss.elastic.co/t/how-to-dynamically-move-nested-key-value-to-root-level/180006/4 "2019-06-05T05:02:05Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
