# Logstash:event api to get nested fields with attribute values in ruby filter

**URL:** <https://discuss.elastic.co/t/logstash-event-api-to-get-nested-fields-with-attribute-values-in-ruby-filter/269665>\
**Category:** Logstash\
**Created:** [April 9, 2021, 6:46am UTC](https://discuss.elastic.co/t/logstash-event-api-to-get-nested-fields-with-attribute-values-in-ruby-filter/269665 "2021-04-09T06:46:20Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![prathibha](https://avatars.discourse-cdn.com/v4/letter/p/5f8ce5/32.png) [@prathibha](https://discuss.elastic.co/u/prathibha)\
**Post date:** [April 9, 2021, 6:46am UTC](https://discuss.elastic.co/t/logstash-event-api-to-get-nested-fields-with-attribute-values-in-ruby-filter/269665/1 "2021-04-09T06:46:20Z")

</div>

Hello Team,

I would like to use an event api inside ruby filter to get nested fields with attribute value. I have a sample here as below:

> ```
> "Event1" => {
> "Event2" => {
> "name" => "ABC",
> "Property" => [
> [0] {
> "name" => "ABC",
> "flag" => "false",
> }
> ]
> }
> }
> }
> 
> ```

and the ruby filter code used to capture as below:

> ruby {  
> code =\> '  
> entry = event.get("[Event][Event1][Event2 @name="ABC"][Property]"])  
> ...  
> ...  
> event.set("field", value)  
> }  
> '  
> }

Thanks in advance...Your feedback will be appreciated

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [April 9, 2021, 4:10pm UTC](https://discuss.elastic.co/t/logstash-event-api-to-get-nested-fields-with-attribute-values-in-ruby-filter/269665/2 "2021-04-09T16:10:12Z")

</div>

> [@prathibha](#):
>
> entry = event.get("[Event][Event1][Event2 @name="ABC"][Property]"])

You cannot do xpath-like references in ruby.

If you want the whole of the Property array you would do

```
entry = event.get("[Event][Event1][Event2][Property]")

```

(that's assuming that the [Event1] field is nested inside a top-level [Event] field). If you want the first entry of the array then use

```
entry = event.get("[Event][Event1][Event2][Property][0]")

```

If there are multiple entries in the Property array and you want to select one by name then you would need to iterate over the array. There are many ways to do that. I have not tested this one, it is just an example

```
ruby {
    code => '
        entry = event.get("[Event][Event1][Event2][Property]
        if entry
            index = entry.index { |x| x["name"] == "ABC" }
            theOneYouWant = entry[index]
        end
        ...
    '
}

```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 7, 2021, 4:10pm UTC](https://discuss.elastic.co/t/logstash-event-api-to-get-nested-fields-with-attribute-values-in-ruby-filter/269665/3 "2021-05-07T16:10:56Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
