# \[Logstash\] Aggregate Filter Plugin with Nested Fields

**URL:** <https://discuss.elastic.co/t/logstash-aggregate-filter-plugin-with-nested-fields/263591>\
**Category:** Logstash\
**Created:** [February 8, 2021, 11:45am UTC](https://discuss.elastic.co/t/logstash-aggregate-filter-plugin-with-nested-fields/263591 "2021-02-08T11:45:47Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![jeduguim](https://avatars.discourse-cdn.com/v4/letter/j/ea5d25/32.png) [@jeduguim](https://discuss.elastic.co/u/jeduguim)\
**Post date:** [February 8, 2021, 11:45am UTC](https://discuss.elastic.co/t/logstash-aggregate-filter-plugin-with-nested-fields/263591/1 "2021-02-08T11:45:48Z")

</div>

Hi, I'm trying to use aggregate filter plugin with nested fields on a logstash config file. But I have a nested field inside other nested field. Is it possible to do in logstash? Maybe with multiple aggregate filters? My input is an oracle bd and I'd like to do something like this:

```auto
    aggregate {
    task_id => "%{id_proc}"
    code => "
      map['id_proc'] = event.get('id_proc')
      map['co_uuid_unid'] = event.get('co_uuid_unid')
      map['dt_reg'] = event.get('dt_reg')
  
      map['peopleList'] ||= []
      map['people'] ||= []
      if (event.get('id_pp_person') != nil)
        if !( map['peopleList'].include? event.get('id_pp_person') ) 
          map['peopleList'] << event.get('id_pp_person')
  
          map['people'] << {
            'id_pp_person' => event.get('id_pp_person'), 
            'name_person' => event.get('name_person'),
   	    {    
	      map['docsList'] ||= []
	      map['docs'] ||= []
	      if (event.get('id_pp_doc') != nil)
		if !( map['docsList'].include? event.get('id_pp_doc') ) 
		  map['docsList'] << event.get('id_pp_doc')
		  map['docs'] << {
		    'id_pp_doc' => event.get('id_pp_doc'), 
		    'number_doc' => event.get('number_doc')
		  }
		end
	      end 
             }
          }
        end
      end

      event.cancel()
    "
    push_previous_map_as_event => true
    timeout => 5
  }

```

Thanks!!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 8, 2021, 11:46am UTC](https://discuss.elastic.co/t/logstash-aggregate-filter-plugin-with-nested-fields/263591/2 "2021-03-08T11:46:23Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
