# Logstash Mutate Arrays

**URL:** <https://discuss.elastic.co/t/logstash-mutate-arrays/362813>\
**Category:** Logstash\
**Created:** [July 9, 2024, 5:15pm UTC](https://discuss.elastic.co/t/logstash-mutate-arrays/362813 "2024-07-09T17:15:16Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![erikg](https://avatars.discourse-cdn.com/v4/letter/e/91b2a8/32.png) [@erikg](https://discuss.elastic.co/u/erikg)\
**Post date:** [July 9, 2024, 5:15pm UTC](https://discuss.elastic.co/t/logstash-mutate-arrays/362813/1 "2024-07-09T17:15:16Z")

</div>

Hello,

I have a simple question on arrays coming into Logstash.  
Lets say I have this example:

| | |
| --- | --- |
| Field | Value |
| data.root | [true, false] |

This is expected behavior.

**What I want to do** :  
Copy the first value of data root to a new field, how would I do it?  
I tried to do mutate filter:

```auto
mutate {
        copy => { "[data][root][0]" => "[data][first]"}
      }

```

But it's not working, I assume I am not identifying it correctly?

---

<div class="post-metadata">

**Author:** ![erikg](https://avatars.discourse-cdn.com/v4/letter/e/91b2a8/32.png) [@erikg](https://discuss.elastic.co/u/erikg)\
**Post date:** [July 9, 2024, 5:42pm UTC](https://discuss.elastic.co/t/logstash-mutate-arrays/362813/2 "2024-07-09T17:42:07Z")

</div>

I figured it out!  
The issue was the field name was not identified correctly.

Based on my data structure, the array was parsed from data.

```auto
data {
   [0] { "root": "true"}
   [1] { "root": "false"}
}

```

So it worked by:  
`[data][0][root]`
