# How to make Ruby selectively remove the top level field from a specific nested field pattern

**URL:** <https://discuss.elastic.co/t/how-to-make-ruby-selectively-remove-the-top-level-field-from-a-specific-nested-field-pattern/232733>\
**Category:** Logstash\
**Created:** [May 15, 2020, 1:51am UTC](https://discuss.elastic.co/t/how-to-make-ruby-selectively-remove-the-top-level-field-from-a-specific-nested-field-pattern/232733 "2020-05-15T01:51:46Z")\
**Posts on this page:** 1\
**Showing post:** 5

<div class="post-metadata">

**Author:** ![Jenni](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jenni/32/29684_2.png) [@Jenni](https://discuss.elastic.co/u/Jenni)\
**Post date:** [June 9, 2020, 8:53am UTC](https://discuss.elastic.co/t/how-to-make-ruby-selectively-remove-the-top-level-field-from-a-specific-nested-field-pattern/232733/5 "2020-06-09T08:53:10Z")

</div>

I'm pretty sure that `event.to_hash` gives you a multidimensional data structure, so there would be a key "data", not "[data][ecs]". But I think you would only need ruby for this kind of action if your target is the root level of the event (many threads for this, e.g.: [Move subarrays to document root](https://discuss.elastic.co/t/move-subarrays-to-document-root/143876)). If there is a target field, simply renaming your field should work:

```
mutate {
    rename => {
        "[data][ecs]" => "ecs"
    }
}
```

---

_[View the full topic](https://discuss.elastic.co/t/how-to-make-ruby-selectively-remove-the-top-level-field-from-a-specific-nested-field-pattern/232733)._
