# If in json nested field

**URL:** <https://discuss.elastic.co/t/if-in-json-nested-field/260343>\
**Category:** Logstash\
**Created:** [January 6, 2021, 1:07pm UTC](https://discuss.elastic.co/t/if-in-json-nested-field/260343 "2021-01-06T13:07:07Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![probson](https://avatars.discourse-cdn.com/v4/letter/p/e47c2d/32.png) [@probson](https://discuss.elastic.co/u/probson)\
**Post date:** [January 6, 2021, 1:07pm UTC](https://discuss.elastic.co/t/if-in-json-nested-field/260343/1 "2021-01-06T13:07:07Z")

</div>

Hi,

I am trying to use logstash to create a field of dns.type based on the types within dns.answers. This is from event.code 22 from sysmon.

i have tried:

```auto
      if "AAAA" in [dns][answers] {
          mutate {
              add_field => {"[dns][type]" => "AAAA"}
            }
        }

```

also tried KV with no joy.  
Any suggestions

```auto
dns.answers
	
{
  "type": "AAAA",
  "data": "2a04:4e42::81"
},
{
  "type": "AAAA",
  "data": "2a04:4e42:200::81"
},
{
  "type": "AAAA",
  "data": "2a04:4e42:400::81"
},
{
  "type": "AAAA",
  "data": "2a04:4e42:600::81"
},
{
  "type": "A",
  "data": "151.101.64.81"
},
{
  "type": "A",
  "data": "151.101.128.81"
},
{
  "type": "A",
  "data": "151.101.192.81"
},
{
  "type": "A",
  "data": "151.101.0.81"
}

```

---

<div class="post-metadata">

**Author:** ![aaron-nimocks](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/aaron-nimocks/32/73965_2.png) [@aaron-nimocks](https://discuss.elastic.co/u/aaron-nimocks)\
**Post date:** [January 6, 2021, 1:12pm UTC](https://discuss.elastic.co/t/if-in-json-nested-field/260343/2 "2021-01-06T13:12:48Z")

</div>

Have you tried

```auto
if "AAAA" in [dns][answers][type] {

```

If that doesn't work can you post an example of your data set?

---

<div class="post-metadata">

**Author:** ![probson](https://avatars.discourse-cdn.com/v4/letter/p/e47c2d/32.png) [@probson](https://discuss.elastic.co/u/probson)\
**Post date:** [January 6, 2021, 1:50pm UTC](https://discuss.elastic.co/t/if-in-json-nested-field/260343/3 "2021-01-06T13:50:20Z")

</div>

> [@probson](#):
>
> ```auto
> dns.answers
> 	
> {
> "type": "AAAA",
> "data": "2a04:4e42::81"
> },
> {
> "type": "AAAA",
> "data": "2a04:4e42:200::81"
> },
> {
> "type": "AAAA",
> "data": "2a04:4e42:400::81"
> },
> {
> "type": "AAAA",
> "data": "2a04:4e42:600::81"
> },
> {
> "type": "A",
> "data": "151.101.64.81"
> },
> {
> "type": "A",
> "data": "151.101.128.81"
> },
> {
> "type": "A",
> "data": "151.101.192.81"
> },
> {
> "type": "A",
> "data": "151.101.0.81"
> }
> 
> ```

Hi @aaron-nimocks,

sysmon with winlogbeats does not give a [dns][answers][type] only the [dns][answers] as below

```auto
dns.answers
	
{
  "type": "AAAA",
  "data": "2a04:4e42::81"
},
{
  "type": "AAAA",
  "data": "2a04:4e42:200::81"
},
{
  "type": "AAAA",
  "data": "2a04:4e42:400::81"
},
{
  "type": "AAAA",
  "data": "2a04:4e42:600::81"
},
{
  "type": "A",
  "data": "151.101.64.81"
},
{
  "type": "A",
  "data": "151.101.128.81"
},
{
  "type": "A",
  "data": "151.101.192.81"
},
{
  "type": "A",
  "data": "151.101.0.81"
}

```

I am trying to end up with the type extracted from that [dns][answers], even if i end up with [dns][answers][type]: AAAA, A

Thanks

---

<div class="post-metadata">

**Author:** ![ylasri](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ylasri/32/86120_2.png) [@ylasri](https://discuss.elastic.co/u/ylasri)\
**Post date:** [January 6, 2021, 2:25pm UTC](https://discuss.elastic.co/t/if-in-json-nested-field/260343/4 "2021-01-06T14:25:17Z")

</div>

That will need a ruby filter, try this one

```auto
ruby { 
		code => "
				dns_type = event.get('[dns][answers]').find {|h| h['type'] == 'AAAA'}['type'];
				event.set('[dns][type]', dns_type)
				"
	}

```

---

<div class="post-metadata">

**Author:** ![ylasri](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ylasri/32/86120_2.png) [@ylasri](https://discuss.elastic.co/u/ylasri)\
**Post date:** [January 6, 2021, 2:26pm UTC](https://discuss.elastic.co/t/if-in-json-nested-field/260343/5 "2021-01-06T14:26:19Z")

</div>

Check this thread

> [@I would like to access nested data from an array](https://discuss.elastic.co/t/i-would-like-to-access-nested-data-from-an-array/71432):
>
> I have a data structure looking like this: printed as codec =\> rubydebug { "sequence\_number" =\> 557, "event\_tags" =\> [[0] { "value" =\> "nacl-st-qkrrfq-ppu-server-6y35vxntjont", "key" =\> "originhost" } ] . . . . } or printed as codec =\> line "event\_tags":[{"value":"nacl-st-alcags-ppu-server-zwul4nphc2lc","key":"originhost"}] or from kibana: event\_tags { "value": "nacl-st-ibgki7-ppu-server-bl46vcsakx5f", "key": "originhost" } I would like ta add a field calld "originho…

---

<div class="post-metadata">

**Author:** ![probson](https://avatars.discourse-cdn.com/v4/letter/p/e47c2d/32.png) [@probson](https://discuss.elastic.co/u/probson)\
**Post date:** [January 6, 2021, 3:22pm UTC](https://discuss.elastic.co/t/if-in-json-nested-field/260343/6 "2021-01-06T15:22:08Z")

</div>

Hi @ylasri

i removed the =='AAAA' so that it now pulls the type from the array, now need to get it to loop through and append as dns.answers may include multiple types

```auto
    ruby { 
		code => "
				dns_type = event.get('[dns][answers]').find {|h| h['type']}['type'];
				event.set('[dns][answers.type]', dns_type)
				"
	    }

```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 3, 2021, 3:22pm UTC](https://discuss.elastic.co/t/if-in-json-nested-field/260343/7 "2021-02-03T15:22:13Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
