# Logstash. Export data from Elasticsearch's nested field

**URL:** <https://discuss.elastic.co/t/logstash-export-data-from-elasticsearchs-nested-field/240354>\
**Category:** Logstash\
**Created:** [July 8, 2020, 1:33pm UTC](https://discuss.elastic.co/t/logstash-export-data-from-elasticsearchs-nested-field/240354 "2020-07-08T13:33:52Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![Alex\_D](https://avatars.discourse-cdn.com/v4/letter/a/f0a364/32.png) [@Alex\_D](https://discuss.elastic.co/u/Alex_D)\
**Post date:** [July 8, 2020, 1:33pm UTC](https://discuss.elastic.co/t/logstash-export-data-from-elasticsearchs-nested-field/240354/1 "2020-07-08T13:33:53Z")

</div>

Hi all !

I'am trying to export data from ElasticSearch into csv-file.  
I installed plugins "logstash-input-elasticsearch", "logstash-output-csv" before.

Part of my ES data scheme:

```auto
mappings: {
      properties: {
        books: {
          type: 'nested',
          properties: {
            bookId: { type: 'short' },
            bookTitle: { type: 'text'},
            bookAuthor: {type: 'text'}
          }
        }

```

I want to receive "bookId","bookTitle","bookAuthor" separately.

Now I can access only top-level field "book".  
Part of my current logstash configuration file:

```auto
output {
  csv {
    # elastic field name
    fields => ["books"]
    # This is path where we store output.   
    path => "/Users/user/Desktop/csv-export.csv"
  }
}

```

I tried many different options, for example "[books][bookId]", ["books"]["bookId"] or ["books"."bookId"] , but this does not work.  
Would be grateful for any advice.

// Using Logstash ver. 7.8.0 and ElasticSearch ver. 7.7.0

---

<div class="post-metadata">

**Author:** ![grumo35](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/grumo35/32/59451_2.png) [@grumo35](https://discuss.elastic.co/u/grumo35)\
**Post date:** [July 8, 2020, 2:26pm UTC](https://discuss.elastic.co/t/logstash-export-data-from-elasticsearchs-nested-field/240354/2 "2020-07-08T14:26:05Z")

</div>

Hi,

Correct syntax for nested fields :

```auto
"[books][bookid]"

```

Tell me if it is working !

---

<div class="post-metadata">

**Author:** ![Alex\_D](https://avatars.discourse-cdn.com/v4/letter/a/f0a364/32.png) [@Alex\_D](https://discuss.elastic.co/u/Alex_D)\
**Post date:** [July 8, 2020, 3:00pm UTC](https://discuss.elastic.co/t/logstash-export-data-from-elasticsearchs-nested-field/240354/3 "2020-07-08T15:00:25Z")

</div>

@grumo35, checked your suggestion.  
Unfortunately it doesn't work.  
Thanks for the idea 🙂

Although the documentation for the plugin ("logstash-output-csv") really does specify this syntax:  
[https://www.elastic.co/guide/en/logstash/current/plugins-outputs-csv.html#plugins-outputs-csv-fields](https://www.elastic.co/guide/en/logstash/current/plugins-outputs-csv.html#plugins-outputs-csv-fields)

---

<div class="post-metadata">

**Author:** ![grumo35](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/grumo35/32/59451_2.png) [@grumo35](https://discuss.elastic.co/u/grumo35)\
**Post date:** [July 8, 2020, 3:33pm UTC](https://discuss.elastic.co/t/logstash-export-data-from-elasticsearchs-nested-field/240354/4 "2020-07-08T15:33:53Z")

</div>

Oh sorry i thought the top field was properties,

"[books][bookid]" should work ??

---

<div class="post-metadata">

**Author:** ![Alex\_D](https://avatars.discourse-cdn.com/v4/letter/a/f0a364/32.png) [@Alex\_D](https://discuss.elastic.co/u/Alex_D)\
**Post date:** [July 8, 2020, 6:58pm UTC](https://discuss.elastic.co/t/logstash-export-data-from-elasticsearchs-nested-field/240354/5 "2020-07-08T18:58:01Z")

</div>

@grumo35, unfortunately no )  
I guess that the problem is that I use a non-standard data source - ElasticSearch (through the corresponding plugin).  
Typically, an ES is a data receiver.  
Probably the plugin "logstash-output-csv" can only parse simple json objects, not ES documents.

Will try to find a workaround 🙂

---

<div class="post-metadata">

**Author:** ![grumo35](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/grumo35/32/59451_2.png) [@grumo35](https://discuss.elastic.co/u/grumo35)\
**Post date:** [July 8, 2020, 7:33pm UTC](https://discuss.elastic.co/t/logstash-export-data-from-elasticsearchs-nested-field/240354/6 "2020-07-08T19:33:15Z")

</div>

Ok final try

what's the output like with ?

```auto
filter{
  json{
    source => "books"
  }

}

```

Tough day today, i failed to fully understand your problem.

We can sort this out !

---

<div class="post-metadata">

**Author:** ![Alex\_D](https://avatars.discourse-cdn.com/v4/letter/a/f0a364/32.png) [@Alex\_D](https://discuss.elastic.co/u/Alex_D)\
**Post date:** [July 8, 2020, 8:33pm UTC](https://discuss.elastic.co/t/logstash-export-data-from-elasticsearchs-nested-field/240354/7 "2020-07-08T20:33:33Z")

</div>

@grumo35, now I have some errors with json parsing.  
But the error description contains information about nested attributes.  
So, I guess now I have access to nested field "books"  
and have to change my output block in logstash config file.

Will try to fix it ) Thanks.

---

<div class="post-metadata">

**Author:** ![Alex\_D](https://avatars.discourse-cdn.com/v4/letter/a/f0a364/32.png) [@Alex\_D](https://discuss.elastic.co/u/Alex_D)\
**Post date:** [July 16, 2020, 7:18am UTC](https://discuss.elastic.co/t/logstash-export-data-from-elasticsearchs-nested-field/240354/8 "2020-07-16T07:18:39Z")

</div>

JFYI.  
Solved the problem using the Python client.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 13, 2020, 7:18am UTC](https://discuss.elastic.co/t/logstash-export-data-from-elasticsearchs-nested-field/240354/9 "2020-08-13T07:18:42Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
