# Ingest Relational DB data with outer join relationships to Nested objects in Elasticsearch through Logstash

**URL:** <https://discuss.elastic.co/t/ingest-relational-db-data-with-outer-join-relationships-to-nested-objects-in-elasticsearch-through-logstash/81164>\
**Category:** Logstash\
**Created:** [April 4, 2017, 2:22pm UTC](https://discuss.elastic.co/t/ingest-relational-db-data-with-outer-join-relationships-to-nested-objects-in-elasticsearch-through-logstash/81164 "2017-04-04T14:22:28Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![NSK](https://avatars.discourse-cdn.com/v4/letter/n/a4c791/32.png) [@NSK](https://discuss.elastic.co/u/NSK)\
**Post date:** [April 4, 2017, 2:22pm UTC](https://discuss.elastic.co/t/ingest-relational-db-data-with-outer-join-relationships-to-nested-objects-in-elasticsearch-through-logstash/81164/1 "2017-04-04T14:22:28Z")

</div>

Hello All - I am trying to ingest Oracle Data into Elasticsearch. Here is the data structure

number number\_type Comments  
01 S abc  
01 F cbd  
02 A xyz

and wanted to see the output as nested objects  
"mappings": {  
"test": {  
"properties": {  
"NUMBER" : {"type" : "integer"},  
"COMMENTS" :{  
"type": "nested",  
"properties" : {  
"NUMBER\_TYPE" : {"type" : "integer"},  
"COMMENTS" : {"type" : "string"}  
}  
}  
}

How do I parse the NUMBER\_TYPE and COMMENTS column in Nested objects through logstash filters.

I read in a blog, where it talked about mutate filter option but really not sure how to use them in the logstash conf file.

Any pointers or examples on handling outer joins in logstash are greatly appreciated.

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [April 6, 2017, 5:00am UTC](https://discuss.elastic.co/t/ingest-relational-db-data-with-outer-join-relationships-to-nested-objects-in-elasticsearch-through-logstash/81164/2 "2017-04-06T05:00:41Z")

</div>

> How do I parse the NUMBER\_TYPE and COMMENTS column in Nested objects through logstash filters.

> I read in a blog, where it talked about mutate filter option but really not sure how to use them in the logstash conf file.

Use a mutate filter and its rename option. There's an example in the filter's documentation. To created a nested field, use the `[field][subfield]` syntax described here: [Accessing event data and fields | Logstash Reference [8.11] | Elastic](https://www.elastic.co/guide/en/logstash/current/event-dependent-configuration.html#logstash-config-field-references)

---

<div class="post-metadata">

**Author:** ![NSK](https://avatars.discourse-cdn.com/v4/letter/n/a4c791/32.png) [@NSK](https://discuss.elastic.co/u/NSK)\
**Post date:** [April 16, 2017, 9:29pm UTC](https://discuss.elastic.co/t/ingest-relational-db-data-with-outer-join-relationships-to-nested-objects-in-elasticsearch-through-logstash/81164/3 "2017-04-16T21:29:24Z")

</div>

Thanks for the response.

I did try the rename option, however the hlog\_comments fields is not getting displayed.

filter {  
mutate {  
rename =\> {"SEQUENCE\_NUMBER" =\> "[HLOG\_COMMENTS][SEQUENCE\_NUMBER]" }  
rename =\> {"USERID" =\> "[HLOG\_COMMENTS][USERID]" }  
rename =\> {"ACTIVITY" =\> "[HLOG\_COMMENTS][ACTIVITY]" }  
rename =\> {"HEADERLOG\_STATE" =\> "[HLOG\_COMMENTS][HLOG\_STATE]" }  
rename =\> {"HEADERLOG\_STATUS" =\> "[HOG\_COMMENTS][HLOG\_STATUS]" }  
......  
-......  
........

---

<div class="post-metadata">

**Author:** ![NSK](https://avatars.discourse-cdn.com/v4/letter/n/a4c791/32.png) [@NSK](https://discuss.elastic.co/u/NSK)\
**Post date:** [April 16, 2017, 9:30pm UTC](https://discuss.elastic.co/t/ingest-relational-db-data-with-outer-join-relationships-to-nested-objects-in-elasticsearch-through-logstash/81164/4 "2017-04-16T21:30:12Z")

</div>

hlog\_comment is the nested object.

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [April 18, 2017, 5:26am UTC](https://discuss.elastic.co/t/ingest-relational-db-data-with-outer-join-relationships-to-nested-objects-in-elasticsearch-through-logstash/81164/5 "2017-04-18T05:26:41Z")

</div>

Please show what you get from a `stdout { codec => rubydebug }` output so we can see exactly what your events look like.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 16, 2017, 5:30am UTC](https://discuss.elastic.co/t/ingest-relational-db-data-with-outer-join-relationships-to-nested-objects-in-elasticsearch-through-logstash/81164/6 "2017-05-16T05:30:25Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
