Use a mutate filter and its add_field option to add the fields you want. See https://www.elastic.co/guide/en/logstash/current/event-dependent-configuration.html#logstash-config-field-references for more on the syntax you should use for nested fields.