# Logstash nested array with special key value pair

**URL:** <https://discuss.elastic.co/t/logstash-nested-array-with-special-key-value-pair/357726>\
**Category:** Logstash\
**Created:** [April 18, 2024, 3:02pm UTC](https://discuss.elastic.co/t/logstash-nested-array-with-special-key-value-pair/357726 "2024-04-18T15:02:04Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![PieterF](https://avatars.discourse-cdn.com/v4/letter/p/b5e925/32.png) [@PieterF](https://discuss.elastic.co/u/PieterF)\
**Post date:** [April 18, 2024, 3:02pm UTC](https://discuss.elastic.co/t/logstash-nested-array-with-special-key-value-pair/357726/1 "2024-04-18T15:02:04Z")

</div>

Hi,

We ingest Firebase logs with format json.  
Now there are some properties that have an array of objects with the following structure: the key is always a string but the value is saved depending on type.

```auto
event_params": [
        {
            "key": "firebase_screen_class",
            "value": {
                "double_value": null,
                "float_value": null,
                "int_value": null,
                "string_value": "Controller"
            }
        },
        {
            "key": "skipAllowed",
            "value": {
                "double_value": null,
                "float_value": null,
                "int_value": null,
                "string_value": "no"
            }
        },
        {
            "key": "firebase_id",
            "value": {
                "double_value": null,
                "float_value": null,
                "int_value": 99465839919,
                "string_value": null
            }
        },

```

All Strings, Ints, are grouped now which is unwanted.  
I want to bring the "key" with the "value" thats not null to a new field.

```auto
filter {
   if [fields][type] == "firebase"{
      grok {
         match => { "message" => "%{SPACE}%{GREEDYDATA:JSON}%{SPACE}"}
      }
      json{
         source => "JSON"
         target => "FB"
      }
      ruby {
          code => "event.set('log_time_MS', event.get('[FB][event_timestamp]') / 1000)"
      }
      date{
         match => ["log_time_MS","UNIX_MS"]
         target => "log_time"
      }
   }
}

```

who can put me in the right direction of approaching this problem.

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [April 18, 2024, 5:05pm UTC](https://discuss.elastic.co/t/logstash-nested-array-with-special-key-value-pair/357726/2 "2024-04-18T17:05:12Z")

</div>

Not sure if this is what you want, but if you use

```
    ruby {
        code => '
            event_params = event.get("event_params")
            event_params.each { |x|
                puts x["value"].find(ifnone = nil) { |k, v| v != nil }[1]
                event.set(x["key"], x["value"].find(ifnone = nil) { |k, v| v != nil }[1])
            }
        '
    }

```

you will get

```
"firebase_screen_class" => "Controller",
          "firebase_id" => 99465839919,
           "@timestamp" => 2024-04-18T17:04:26.617552505Z,
          "skipAllowed" => "no"

```

---

<div class="post-metadata">

**Author:** ![PieterF](https://avatars.discourse-cdn.com/v4/letter/p/b5e925/32.png) [@PieterF](https://discuss.elastic.co/u/PieterF)\
**Post date:** [May 6, 2024, 8:43am UTC](https://discuss.elastic.co/t/logstash-nested-array-with-special-key-value-pair/357726/3 "2024-05-06T08:43:05Z")

</div>

Thanks Badger, will try this!

---

<div class="post-metadata">

**Author:** ![vahagg1](https://avatars.discourse-cdn.com/v4/letter/v/7feea3/32.png) [@vahagg1](https://discuss.elastic.co/u/vahagg1)\
**Post date:** [May 15, 2024, 10:38am UTC](https://discuss.elastic.co/t/logstash-nested-array-with-special-key-value-pair/357726/4 "2024-05-15T10:38:21Z")

</div>

Hi Badger,  
Thanks for your help I also face this problem and with this it solved but what if we have two values in same array what we should do. something like this and is there any way to add string before key like PJ.EventParam

```auto
event_params": [
        {
            "key": "firebase_screen_class",
            "value": {
                "double_value": null,
                "float_value": null,
                "int_value": 123,
                "string_value": "Controller"
            }
        },
        {
            "key": "skipAllowed",
            "value": {
                "double_value": null,
                "float_value": null,
                "int_value": 123,
                "string_value": "no"
            }
        },
        {
            "key": "firebase_id",
            "value": {
                "double_value": null,
                "float_value": null,
                "int_value": 99465839919,
                "string_value": Google
            }
        },

```

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [May 15, 2024, 1:35pm UTC](https://discuss.elastic.co/t/logstash-nested-array-with-special-key-value-pair/357726/5 "2024-05-15T13:35:01Z")

</div>

You could try

```
    ruby {
        code => '
            event_params = event.get("event_params")
            event_params.each { |x|
                # This returns arrays like
                # []
                # [["string_value", "Controller"], ["int_value", 123]]
                # [["string_value", "no"]]
                entries = x["value"].find_all { |k, v| v != nil }

                entries.each { |y|
                    type = y[0].sub(/_value$/, "")
                    oldK = x["key"]
                    newK = "#{oldK}_#{type}"

                    event.set(newK, y[1])
                }
            }
        '
    }

```

which would result in events like

```
          "skipAllowed_string" => "no",
             "firebase_id_int" => 99465839919,
   "firebase_screen_class_int" => 123,
"firebase_screen_class_string" => "Controller"

```
