# Logstash elasticsearch filter, query with nested field

**URL:** <https://discuss.elastic.co/t/logstash-elasticsearch-filter-query-with-nested-field/189093>\
**Category:** Logstash\
**Created:** [July 5, 2019, 12:03pm UTC](https://discuss.elastic.co/t/logstash-elasticsearch-filter-query-with-nested-field/189093 "2019-07-05T12:03:51Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![gyterpena](https://avatars.discourse-cdn.com/v4/letter/g/a9a28c/32.png) [@gyterpena](https://discuss.elastic.co/u/gyterpena)\
**Post date:** [July 5, 2019, 12:03pm UTC](https://discuss.elastic.co/t/logstash-elasticsearch-filter-query-with-nested-field/189093/1 "2019-07-05T12:03:51Z")

</div>

Hello

I have issue running query with nested field.  
Sample input data:  
{"url\_details":{"\_id":"1c928bb630eaf248"},"usernameID":"test1"}

Filter config:

```
        if [url_details][_id] {
        elasticsearch {
           hosts => ["127.0.0.1"]
           index => "index*"
           query => "url_details._id:%{[url_details][_id]} AND _exists_:usernameID"
           result_size => 1
           fields => { "[usernameID]" => "[foobar]" }
        }
        if [usernameID] not in [foobar] {
            mutate {
                merge => { "[usernameID]" => "[foobar]" }
            }
        }

```

Results in this query:  
GET /index%2A/\_search?q=url\_details.\_id%3A%25%7B%5Burl\_details.\_id%5D%7D+AND+_exists_%3AusernameID&size=1&sort=%40timestamp%3Adesc HTTP/1.1

Changing input data to this:  
{"url\_details":"1c928bb630eaf248","usernameID":"test1"}

And filter to this:

```
    if [url_details] {
    elasticsearch {
       hosts => ["127.0.0.1"]
       index => "matomo*"
       query => "url_details._id:%{[url_details]} AND _exists_:usernameID"
       result_size => 1
       fields => { "[usernameID]" => "[foobar]" }
    }
    if [usernameID] not in [foobar] {
        mutate {
            merge => { "[usernameID]" => "[foobar]" }
        }
    }

```

Works as expected

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [July 5, 2019, 3:24pm UTC](https://discuss.elastic.co/t/logstash-elasticsearch-filter-query-with-nested-field/189093/2 "2019-07-05T15:24:29Z")

</div>

> [@gyterpena](#):
>
> GET /index%2A/\_search?q=url\_details.\_id%3A%25%7B%5Burl\_details.\_id%5D%7D+AND+ _exists_ %3AusernameID&size=1&sort=%40timestamp%3Adesc HTTP/1.1

You are asserting that the sprintf reference %{[url\_details][\_id]} gets converted to %{[url\_details.\_id]} in the URL sent to ES? You might want to double check that.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 2, 2019, 3:24pm UTC](https://discuss.elastic.co/t/logstash-elasticsearch-filter-query-with-nested-field/189093/3 "2019-08-02T15:24:41Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
