Index Joined sql data in Elasticsearch via logstash

Hello ,

I am trying to index already joined sql data into elastic search via logstash

the data I read look like this

{"family": "ABC", "person":{"name":"aaa","surname":"bbb"}} 
{"family": "ABC", "person":{"name":"ccc","surname":"ddd"}} 

I want it to be indexed like this considering that family is my "document_id"

{ 
   "family":"ABC",
   "person":[ 
      { 
         "name":"aaa",
         "surname":"bbb"
      },
      { 
         "name":"ccc",
         "surname":"ddd"
      }
   ]
}

and if I receive a new event for family ABC the new person goes to the list

What will be the logstash filter??

Any help will be appreciated

Thanks

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.