# How to filter by the nested values in the "message" field?

**URL:** <https://discuss.elastic.co/t/how-to-filter-by-the-nested-values-in-the-message-field/325277>\
**Category:** Kibana\
**Created:** [February 10, 2023, 3:05pm UTC](https://discuss.elastic.co/t/how-to-filter-by-the-nested-values-in-the-message-field/325277 "2023-02-10T15:05:04Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![Shiva\_Subramaniyan](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/shiva_subramaniyan/32/81251_2.png) [@Shiva\_Subramaniyan](https://discuss.elastic.co/u/Shiva_Subramaniyan)\
**Post date:** [February 10, 2023, 3:05pm UTC](https://discuss.elastic.co/t/how-to-filter-by-the-nested-values-in-the-message-field/325277/1 "2023-02-10T15:05:04Z")

</div>

Hi,

I have a "message" field in my "filebeat\*" index.

This "message" field, particularly has nested fields like "httpRequest" and a "country" field in it. The value of this "country" field is 'US'

I want to use a query in Kibana to filter out the various values for this "country" field.

Can someone guide us here?

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/9/a/9aafc7acb4efdda0894cac43a4e1dec2715d0a08.png)

---

<div class="post-metadata">

**Author:** ![cheiligers](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/cheiligers/32/73114_2.png) [@cheiligers](https://discuss.elastic.co/u/cheiligers)\
**Post date:** [February 10, 2023, 8:02pm UTC](https://discuss.elastic.co/t/how-to-filter-by-the-nested-values-in-the-message-field/325277/2 "2023-02-10T20:02:12Z")

</div>

Hy @Shiva_Subramaniyan we added [KQL support for querying nested](https://www.elastic.co/guide/en/kibana/8.5/patterns.html#scoped-services) fields in Kibana 7.6 and these are still supported in the current version (8.6). The examples should get you started: [Kibana Query Language | Kibana Guide [8.6] | Elastic](https://www.elastic.co/guide/en/kibana/current/kuery-query.html#_querying_nested_fields)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 10, 2023, 8:02pm UTC](https://discuss.elastic.co/t/how-to-filter-by-the-nested-values-in-the-message-field/325277/3 "2023-02-10T20:02:12Z")

</div>

Kibana 7.6 is [EOL](https://www.elastic.co/support/eol) and no longer supported. Please upgrade ASAP.

(This is an automated response from your friendly Elastic bot. Please report this post if you have any suggestions or concerns :elasticheart: )

---

<div class="post-metadata">

**Author:** ![Shiva\_Subramaniyan](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/shiva_subramaniyan/32/81251_2.png) [@Shiva\_Subramaniyan](https://discuss.elastic.co/u/Shiva_Subramaniyan)\
**Post date:** [February 11, 2023, 2:48pm UTC](https://discuss.elastic.co/t/how-to-filter-by-the-nested-values-in-the-message-field/325277/4 "2023-02-11T14:48:41Z")

</div>

Hi Cheiligers,

Many thanks for your response. When I use the filter as showm in the attachment, i get the following error

 ![wafprod](https://us1.discourse-cdn.com/elastic/original/3X/d/8/d8101dad7059839a2d0287b9854f1bada5001274.jpeg)

failed to create query: [nested] failed to find nested object under path [message]

Please advise.

---

<div class="post-metadata">

**Author:** ![cheiligers](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/cheiligers/32/73114_2.png) [@cheiligers](https://discuss.elastic.co/u/cheiligers)\
**Post date:** [February 11, 2023, 8:36pm UTC](https://discuss.elastic.co/t/how-to-filter-by-the-nested-values-in-the-message-field/325277/5 "2023-02-11T20:36:51Z")

</div>

We typically get that type of error when the [nested fields you're querying](https://www.elastic.co/guide/en/elasticsearch/reference/current/query-dsl-nested-query.html#query-dsl-nested-query) on are either not mapped or not mapped as nested properties.  
Can you check your mapping and see if the `country` is mapped as a nested property of `httpRequest`? if it is, then it also means it's mapped so the query might need to change a bit".

To [check your mapping](https://www.elastic.co/guide/en/elasticsearch/reference/current/indices-get-mapping.html#indices-get-mapping) (you can use Kibana's Console app for these requests):

```auto
GET /filebeat*/_mapping

```

The mapping might have any fields, so you can narrow down the results to only include the `httpRequest` using:

```auto
GET /filebeat*/_mapping/field/httpRequest

```

or just the mapping for the `country` field:

```auto
GET /filebeat*/_mapping/field/httpRequest.country

```

**Note** : I've given links for the 8/6 version (the most recent), so you might need to change the stack version on the pages that the links points to.

There's way more info in the docs that [including examples](https://www.elastic.co/guide/en/elasticsearch/reference/current/indices-get-field-mapping.html#get-field-mapping-api-basic-ex) and things to watch out for, in case you get stuck.

---

<div class="post-metadata">

**Author:** ![Shiva\_Subramaniyan](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/shiva_subramaniyan/32/81251_2.png) [@Shiva\_Subramaniyan](https://discuss.elastic.co/u/Shiva_Subramaniyan)\
**Post date:** [February 12, 2023, 8:24am UTC](https://discuss.elastic.co/t/how-to-filter-by-the-nested-values-in-the-message-field/325277/6 "2023-02-12T08:24:00Z")

</div>

Hi Cheiligers,

Many thanks for your response.

The API request gives this response. Is this correct?

What should I do if it is not mapped?

 ![Mapping](https://us1.discourse-cdn.com/elastic/original/3X/3/0/303704fd66c43c3ddc99a52fb78a10a6f3f123f8.jpeg)

---

<div class="post-metadata">

**Author:** ![cheiligers](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/cheiligers/32/73114_2.png) [@cheiligers](https://discuss.elastic.co/u/cheiligers)\
**Post date:** [February 12, 2023, 7:57pm UTC](https://discuss.elastic.co/t/how-to-filter-by-the-nested-values-in-the-message-field/325277/7 "2023-02-12T19:57:11Z")

</div>

Hi @Shiva_Subramaniyan you'll need to map it as a nested field in your index.

One can't change the mapping for a field that already exists in the index, so you'll first need to see if the parent (httpRequest) is mapped.

If it is, then you [won't be able to _change_ it](https://www.elastic.co/guide/en/elasticsearch/reference/current/indices-put-mapping.html#updating-field-mappings) to a nested field containing `country`. You'll need to create a new index with a nested field type for `httpRequest` and then reindex all your data from the current index into the new one.

There's a section in the Update mapping API docs that explains how to [create a new index and reindex your data into the new one](https://www.elastic.co/guide/en/elasticsearch/reference/current/indices-put-mapping.html#updating-field-mappings). The docs also gives examples.

What I recommend you do is:

1. [Get the mapping of your existing index](https://www.elastic.co/guide/en/elasticsearch/reference/current/indices-get-mapping.html#indices-get-mapping)
2. Use the mapping that you got in 1 as the basis for the new index and then declare `httpRequest` as a `nested` field with the properties `country` and `clientIp`, `headers` and any others that are also nested in `httpRequest`.

You can use the same mappings for all the other fields in your index that you don't need to change.

I hope that helps!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 12, 2023, 7:57pm UTC](https://discuss.elastic.co/t/how-to-filter-by-the-nested-values-in-the-message-field/325277/8 "2023-03-12T19:57:52Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
