# Logstash csv configuration to access nested json field

**URL:** <https://discuss.elastic.co/t/logstash-csv-configuration-to-access-nested-json-field/82307>\
**Category:** Logstash\
**Created:** [April 13, 2017, 2:03pm UTC](https://discuss.elastic.co/t/logstash-csv-configuration-to-access-nested-json-field/82307 "2017-04-13T14:03:15Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![tejamenneni](https://avatars.discourse-cdn.com/v4/letter/t/96bed5/32.png) [@tejamenneni](https://discuss.elastic.co/u/tejamenneni)\
**Post date:** [April 13, 2017, 2:03pm UTC](https://discuss.elastic.co/t/logstash-csv-configuration-to-access-nested-json-field/82307/1 "2017-04-13T14:03:15Z")

</div>

Following is my logstash configuration to load es data and convert to csv format

input {  
elasticsearch {  
hosts =\> "localhost:9200"  
index =\> "chats"  
query =\> '{ "query": { "range" : {  
"timestamp" : {  
"gte" : "1492080665000",  
"lt" : "1492088665000"  
}  
} }, "\_source": ["timestamp","content.text"] }'  
}  
}

filter {  
date {  
match =\> ["timestamp","UNIX\_MS"]  
target =\> "timestamp\_new"  
remove\_field =\> ["timestamp"]  
}  
csv {  
columns =\> ["timestamp", "content.text"]  
separator =\> ","  
}  
}

output{  
csv {  
fields =\> ["timestamp\_new","content.text"]  
path =\> "/home/ubuntu/chats-content-date-range-v3.csv"  
}  
stdout { codec =\> rubydebug }  
}

Sample input data

"\_source":{"userName": "xxx", "senderType": 3, "spam": 0, "senderId": "1000", "threadId": 101, "userId": "xxx", "sessionId": 115, "content": {"text": "Yes okay", "image": null, "location": null, "card": null}, "receiverId": "xxx", "timestamp": 1453353242657, "type": 0, "id": "0dce30dd-781e-4a42-b230-a988b68fd9ed\_1000\_1453353242657"}

Following is my sample output data

2017-04-13T12:41:34.423Z,"{""text"":""Yes okay""}"

Instead I want following output

2017-04-13T12:41:34.423Z,"Yes okay"

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 11, 2017, 2:04pm UTC](https://discuss.elastic.co/t/logstash-csv-configuration-to-access-nested-json-field/82307/2 "2017-05-11T14:04:52Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
