# Logstash conditional for nested field

**URL:** <https://discuss.elastic.co/t/logstash-conditional-for-nested-field/131042>\
**Category:** Logstash\
**Created:** [May 8, 2018, 5:09pm UTC](https://discuss.elastic.co/t/logstash-conditional-for-nested-field/131042 "2018-05-08T17:09:14Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![rmac](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rmac/32/30897_2.png) [@rmac](https://discuss.elastic.co/u/rmac)\
**Post date:** [May 8, 2018, 5:09pm UTC](https://discuss.elastic.co/t/logstash-conditional-for-nested-field/131042/1 "2018-05-08T17:09:14Z")

</div>

I understand in Logstash you can access nested fields, for example like this in a filter block

```
 mutate {
    replace => { "timestamp" => "%{timestamp} %{[beat][timezone]}" }
 }

```

However I seem to be unable to access the field "fileset.module" like this in an output block:

```
if [fileset][module] == "osquery" {
  elasticsearch {
      hosts => ["192.168.x.x", "192.168.y.y"]
      index => "osquery-%{+YYYY.MM.dd}"
      }
}

```

The events I'm pushing into logstash from filebeat never end up in the index I'm attempting to create here, though the field does definitely exist.  
Anyone know what I may be doing wrong?

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [May 8, 2018, 7:31pm UTC](https://discuss.elastic.co/t/logstash-conditional-for-nested-field/131042/2 "2018-05-08T19:31:36Z")

</div>

There's nothing wrong with the syntax. What does an example event look like?

---

<div class="post-metadata">

**Author:** ![rmac](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rmac/32/30897_2.png) [@rmac](https://discuss.elastic.co/u/rmac)\
**Post date:** [May 11, 2018, 5:05pm UTC](https://discuss.elastic.co/t/logstash-conditional-for-nested-field/131042/3 "2018-05-11T17:05:32Z")

</div>

This was due to user error, sorry for wasting your time. Filebeat wasn't configured properly. I had multiple hosts shipping stuff in, but the one host that wasn't had an incorrect filebeat config. Thought configs were identical but I made a mistake.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 8, 2018, 5:19pm UTC](https://discuss.elastic.co/t/logstash-conditional-for-nested-field/131042/4 "2018-06-08T17:19:51Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
