# Kibana search nested array of json objects

**URL:** <https://discuss.elastic.co/t/kibana-search-nested-array-of-json-objects/101079>\
**Category:** Kibana\
**Created:** [September 19, 2017, 11:35pm UTC](https://discuss.elastic.co/t/kibana-search-nested-array-of-json-objects/101079 "2017-09-19T23:35:08Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![shrikant0013](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/shrikant0013/32/22429_2.png) [@shrikant0013](https://discuss.elastic.co/u/shrikant0013)\
**Post date:** [September 19, 2017, 11:35pm UTC](https://discuss.elastic.co/t/kibana-search-nested-array-of-json-objects/101079/1 "2017-09-19T23:35:08Z")

</div>

I have documents indexed in ElasticSearch like  
doc1

```javascript
{
   "_index":"logs_2017-07-22",
   "_type":"audit",
   "_id":"K",
   "_score":null,
   "_source":{
      "logName":"",
      "payload":{
         "methodName":"policy",
         "response":{
            "sdata":{
               "pDelta":{
                  "bDeltas":[
                     {
                        "action":"Remove",
                        "member":"user:abc",
                        "role":"viewer"
                     },
                     {
                        "action":"Remove",
                        "member":"user:xyz",
                        "role":"admin"
                     },
                     {
                        "action":"Add",
                        "member":"user:pqr",
                        "role":"deployer"
                     },
                     {
                        "action":"Remove",
                        "member":"user:jkl",
                        "role":"admin"
                     }
                  ]
               }
            }
         }
      }
   }
}

```

doc2

```javascript
{
   "_index":"logs_2017-07-22",
   "_type":"audit",
   "_id":"K",
   "_score":null,
   "_source":{
      "logName":"",
      "payload":{
         "methodName":"policy",
         "response":{
            "sdata":{
               "pDelta":{
                  "bDeltas":[
                     {
                        "action":"Remove",
                        "member":"user:abc",
                        "role":"viewer"
                     },
                     {
                        "action":"Add",
                        "member":"user:xyz",
                        "role":"admin"
                     },
                     {
                        "action":"Add",
                        "member":"user:pqr",
                        "role":"deployer"
                     },
                     {
                        "action":"Remove",
                        "member":"user:jkl",
                        "role":"admin"
                     }
                  ]
               }
            }
         }
      }
   }
}

```

How can I get documents which only has

```auto
            {
              "action": "Remove",
              "member": "user:xyz",
              "role": "admin"
            }

```

I tried this query in **Kibana** , but I get both the documents. I am expecting only first document  
payload.sdata.pDelta.bDeltas.action:Remove AND payload.sdata.pDelta.bDeltas.member:"user:xyz"

---

<div class="post-metadata">

**Author:** ![tsullivan](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tsullivan/32/31077_2.png) [@tsullivan](https://discuss.elastic.co/u/tsullivan)\
**Post date:** [September 20, 2017, 5:37pm UTC](https://discuss.elastic.co/t/kibana-search-nested-array-of-json-objects/101079/2 "2017-09-20T17:37:57Z")

</div>

Hi, it's quite hard to give advice on this since the blob of data you pasted isn't valid JSON. Feel free to add an update that has valid JSON and is formatted with the markup tools available in this forum.

Based on the topic of your question, it looks like you are dealing with the fact that Elasticsearch flattens the arrays in your data objects, which is explained here: [https://www.elastic.co/guide/en/elasticsearch/reference/current/nested.html](https://www.elastic.co/guide/en/elasticsearch/reference/current/nested.html)

Using a nested data type might give you better searching ability, as it would get Elasticsearch to index the arrays independently of each other, but you should be aware that Kibana doesn't have support to do any aggregations on data that has nested type.

---

<div class="post-metadata">

**Author:** ![shrikant0013](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/shrikant0013/32/22429_2.png) [@shrikant0013](https://discuss.elastic.co/u/shrikant0013)\
**Post date:** [September 22, 2017, 4:15pm UTC](https://discuss.elastic.co/t/kibana-search-nested-array-of-json-objects/101079/3 "2017-09-22T16:15:34Z")

</div>

Thanks for the comment @tsullivan. You are right, it was issue of flattening the arrays in data objects.  
I decided to flatten it within my service which processes the json before sending to ElasticSearch.

Btw, about formatting, sorry about that, I have fixed it. I tried earlier and the default editor option '\</\>' menu button is not working. I noticed today that it also supports markdown, hence was able to use it.

---

<div class="post-metadata">

**Author:** ![tsullivan](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tsullivan/32/31077_2.png) [@tsullivan](https://discuss.elastic.co/u/tsullivan)\
**Post date:** [September 22, 2017, 5:04pm UTC](https://discuss.elastic.co/t/kibana-search-nested-array-of-json-objects/101079/4 "2017-09-22T17:04:26Z")

</div>

Interesting to know about the menu button not working. I usually wrap my code sections in triple backticks (```) Anyway, the above code is readable now 😃

Glad your searches working now!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 20, 2017, 5:04pm UTC](https://discuss.elastic.co/t/kibana-search-nested-array-of-json-objects/101079/5 "2017-10-20T17:04:48Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
