# Jdbc\_streaming and mutate

**URL:** <https://discuss.elastic.co/t/jdbc-streaming-and-mutate/287319>\
**Category:** Logstash\
**Created:** [October 21, 2021, 1:20pm UTC](https://discuss.elastic.co/t/jdbc-streaming-and-mutate/287319 "2021-10-21T13:20:19Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![Roberto\_B](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/roberto_b/32/77615_2.png) [@Roberto\_B](https://discuss.elastic.co/u/Roberto_B)\
**Post date:** [October 21, 2021, 1:20pm UTC](https://discuss.elastic.co/t/jdbc-streaming-and-mutate/287319/1 "2021-10-21T13:20:19Z")

</div>

Hi Friends,

I use a jdbc\_streaming filter in order to enrich data.  
This filter produces an array with only 1 document inside. How can I pop out this document in another field? I tried without success with ruby code.  
Just to do an example:  
This is the final output:

```auto
"reg_pro_com" : [
                {
                        "nomeR" : "Sicilia",
                        "nomeC" : "Ragusa",
                        "nomeP" : "Ragusa"
                }
        ],

```

I wish to have:

```auto
"reg_pro_com" : {
                        "nomeR" : "Sicilia",
                        "nomeC" : "Ragusa",
                        "nomeP" : "Ragusa"
                           }
      

```

I have to use add\_field? How can I access the array without Ruby Code?

KR

Roberto

---

<div class="post-metadata">

**Author:** ![aaron-nimocks](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/aaron-nimocks/32/73965_2.png) [@aaron-nimocks](https://discuss.elastic.co/u/aaron-nimocks)\
**Post date:** [October 21, 2021, 1:44pm UTC](https://discuss.elastic.co/t/jdbc-streaming-and-mutate/287319/2 "2021-10-21T13:44:29Z")

</div>

This might give you what you are looking for.

```auto
 mutate {
  update => { "reg_pro_com" => "%{[reg_pro_com][0]}" }
 }

```

**Output**

```auto
"reg_pro_com": "{\"nomeC\":\"Ragusa\",\"nomeP\":\"Ragusa\",\"nomeR\":\"Sicilia\"}"

```

---

<div class="post-metadata">

**Author:** ![Roberto\_B](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/roberto_b/32/77615_2.png) [@Roberto\_B](https://discuss.elastic.co/u/Roberto_B)\
**Post date:** [October 21, 2021, 3:32pm UTC](https://discuss.elastic.co/t/jdbc-streaming-and-mutate/287319/3 "2021-10-21T15:32:49Z")

</div>

but it a string not a subdocument, I need a subdocument.

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [October 21, 2021, 4:14pm UTC](https://discuss.elastic.co/t/jdbc-streaming-and-mutate/287319/4 "2021-10-21T16:14:50Z")

</div>

If mutate does not do what you want (although I think it will) you could use a split filter.

---

<div class="post-metadata">

**Author:** ![Roberto\_B](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/roberto_b/32/77615_2.png) [@Roberto\_B](https://discuss.elastic.co/u/Roberto_B)\
**Post date:** [October 21, 2021, 4:21pm UTC](https://discuss.elastic.co/t/jdbc-streaming-and-mutate/287319/5 "2021-10-21T16:21:24Z")

</div>

Found a solution: (thanks aaron-nimocks for the first step):

```auto
mutate {
update => { "reg_pro_com" => "%{[reg_pro_com][0]}" }
}
json {
source => "reg_pro_com"
target => "reg_pro_com2"
}
mutate{
remove_field => ["reg_pro_com"]
rename=> {"reg_pro_com2"=>"reg_pro_com"}
}

```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 18, 2021, 4:22pm UTC](https://discuss.elastic.co/t/jdbc-streaming-and-mutate/287319/6 "2021-11-18T16:22:15Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
