# Logstash : How to extract a nested field from Json log and only index the content of the nested field

**URL:** <https://discuss.elastic.co/t/logstash-how-to-extract-a-nested-field-from-json-log-and-only-index-the-content-of-the-nested-field/317617>\
**Category:** Logstash\
**Created:** [October 27, 2022, 1:11pm UTC](https://discuss.elastic.co/t/logstash-how-to-extract-a-nested-field-from-json-log-and-only-index-the-content-of-the-nested-field/317617 "2022-10-27T13:11:29Z")\
**Posts on this page:** 1\
**Showing post:** 3

<div class="post-metadata">

**Author:** ![Ranjith\_kk](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ranjith_kk/32/40809_2.png) [@Ranjith\_kk](https://discuss.elastic.co/u/Ranjith_kk)\
**Post date:** [October 27, 2022, 5:23pm UTC](https://discuss.elastic.co/t/logstash-how-to-extract-a-nested-field-from-json-log-and-only-index-the-content-of-the-nested-field/317617/3 "2022-10-27T17:23:30Z")

</div>

Hello leandrojmp,

Thanks for your support on this. I was able to make some progress with the help of your suggestions. With the new logstash config, I was able to extract only data field, but still encapsulating all the other fields. I want to take all the fields outside the "data" nest

Input message:  
`{"field1":"value1", "field2":"value2", "field3":"value3", "field4":"value4", "data":{"nested_field1":"nested_value1","nested_field2":"nested_value2", "nested_field3":"nested_value3"}}`

Current outpout with the Logstash config below:  
`{"data":{"nested_field3":"nested_value3","nested_field1":"nested_value1","nested_field2":"nested_value2"}}`

Expected output:  
`{"nested_field3":"nested_value3","nested_field1":"nested_value1","nested_field2":"nested_value2"}`  
We would not be able to use static field names as the fields under data{} can be dynamic. I would need something like [data][\*]

New logstash config:

```auto
input {
 file {
   type => "json"
   path => "/home/ranjith/logstash1.log"
   start_position => beginning
   sincedb_path => "/dev/null"
 }
}
filter {
      json {
        source => "message"
      }
      prune {
        whitelist_names => ["data"]
      }

      mutate {
        remove_field => ["message"]
      }
}
output {
stdout { codec => json }
}

```

---

_[View the full topic](https://discuss.elastic.co/t/logstash-how-to-extract-a-nested-field-from-json-log-and-only-index-the-content-of-the-nested-field/317617)._
