# Logstash elasticsearch ruby filter issues

**URL:** <https://discuss.elastic.co/t/logstash-elasticsearch-ruby-filter-issues/179820>\
**Category:** Logstash\
**Created:** [May 6, 2019, 5:10pm UTC](https://discuss.elastic.co/t/logstash-elasticsearch-ruby-filter-issues/179820 "2019-05-06T17:10:02Z")\
**Posts on this page:** 1\
**Showing post:** 8

<div class="post-metadata">

**Author:** ![raged](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/raged/32/45722_2.png) [@raged](https://discuss.elastic.co/u/raged)\
**Post date:** [May 8, 2019, 2:35pm UTC](https://discuss.elastic.co/t/logstash-elasticsearch-ruby-filter-issues/179820/8 "2019-05-08T14:35:44Z")

</div>

I tried this as well:

```
fields => { "[wmi][Win32_Computersystem][0][Model]" => zz }

```

But I end up with this event:

`"model": null,`

I have been digging into this and I found this post (I am not sure how to mutate like he mentioned, I did message him 😄) :

> [@Getting Nested Fields Elasticsearch Filter](https://discuss.elastic.co/t/getting-nested-fields-elasticsearch-filter/118223):
>
> I using the logstash-elasticsearch-filter to correlate events from Elasticsearch. Some of the fields that I need to return from the Elasticsearch hit are nested. I have been unable to retrieve these docs and the result is always null. I am using Logstash 5.6.5 and ES 5.6.5. Here is my configuration: "fields" =\> { "field.otherField.anotherField" =\> "p\_time\_gmt" } I have also tried: [field][otherField][anotherField] [field][otherField][0][anotherField] …

Is there a limitation for logstash using a nested array property in a elasticsearch field property?

We are currently using version 6.4.3 of logstash.

---

_[View the full topic](https://discuss.elastic.co/t/logstash-elasticsearch-ruby-filter-issues/179820)._
