# Logstash : How to extract a nested field from Json log and only index the content of the nested field

**URL:** <https://discuss.elastic.co/t/logstash-how-to-extract-a-nested-field-from-json-log-and-only-index-the-content-of-the-nested-field/317617>\
**Category:** Logstash\
**Created:** [October 27, 2022, 1:11pm UTC](https://discuss.elastic.co/t/logstash-how-to-extract-a-nested-field-from-json-log-and-only-index-the-content-of-the-nested-field/317617 "2022-10-27T13:11:29Z")\
**Posts on this page:** 1\
**Showing post:** 4

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [October 27, 2022, 5:34pm UTC](https://discuss.elastic.co/t/logstash-how-to-extract-a-nested-field-from-json-log-and-only-index-the-content-of-the-nested-field/317617/4 "2022-10-27T17:34:33Z")

</div>

I think that you will need to use the ruby filter to put the nested fields under data into the root level of the document.

I'm not an expert in ruby, but this [other question](https://discuss.elastic.co/t/move-subarrays-to-document-root/143876/2) has an example that may work in your case.

It would be somehint like this, but you will need to test it out.

```auto
ruby { 
    code => 'event.get("data").each { | k, v| event.set(k, v) }' 
}
mutate { 
    remove_field => ["data"] 
}

```

Those filters would need to be after the `prune` filter.

---

_[View the full topic](https://discuss.elastic.co/t/logstash-how-to-extract-a-nested-field-from-json-log-and-only-index-the-content-of-the-nested-field/317617)._
