# Logstash Nested Fields - Cloudtrail logs - No root field

**URL:** <https://discuss.elastic.co/t/logstash-nested-fields-cloudtrail-logs-no-root-field/309568>\
**Category:** Logstash\
**Tags:** docker\
**Created:** [July 13, 2022, 6:01pm UTC](https://discuss.elastic.co/t/logstash-nested-fields-cloudtrail-logs-no-root-field/309568 "2022-07-13T18:01:00Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![Pedro\_Cabral](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/pedro_cabral/32/103308_2.png) [@Pedro\_Cabral](https://discuss.elastic.co/u/Pedro_Cabral)\
**Post date:** [July 13, 2022, 6:01pm UTC](https://discuss.elastic.co/t/logstash-nested-fields-cloudtrail-logs-no-root-field/309568/1 "2022-07-13T18:01:00Z")

</div>

Hello all,

First of all I'm running version 7.10.2 on a docker.

I have some cloudtrail logs stored as .gz that I'm reading and after parsing I'm renaming the Records fields and build the different nested fields. When I try to see them in Kibana it is not under the root field.

Logstash config:

```auto
input {
    file {
        path => "/tmp/*.gz"
        mode => "read"
        sincedb_path => "/dev/null"
    }
}

filter {
  json {
     source => "message"
  }
  split {
     field => "Records"
  }

   date {
     match => ["[Records][eventTime]", "ISO8601"]
     target => "@timestamp"
     remove_field => ["message", "host", "path"]
   }

    mutate {
     rename => {"[Records][requestID]" => "requestID"}
     rename => {"[Records][eventVersion]" => "eventVersion"}
     rename => {"[Records][sharedEventID]" => "sharedEventID"}
     rename => {"[Records][eventSource]" => "eventSource"}
     rename => {"[Records][eventTime]" => "eventTime"}
     rename => {"[Records][eventID]" => "eventID"}
     rename => {"[Records][userIdentity]" => "userIdentity"}
     rename => {"[Records][awsRegion]" => "awsRegion"}
     rename => {"[Records][resources]" => "resources"}
     rename => {"[Records][eventType]" => "eventType"}
     rename => {"[Records][responseElements]" => "responseElements"}
     rename => {"[Records][assumedRoleUser]" => "assumedRoleUser"}
     rename => {"[Records][sourceIPAddress]" => "sourceIPAddress"}
     rename => {"[Records][eventName]" => "eventName"}
     rename => {"[Records][userAgent]" => "userAgent"}
     rename => {"[Records][recipientAccountId]" => "recipientAccountId"}
     rename => {"[Records][requestParameters]" => "requestParameters"}
     rename => {"[Records][readOnly]" => "readOnly"}
     rename => {"[Records][additionalEventData]" => "additionalEventData"}
     rename => {"[Records][apiVersion]" => "apiVersion"}
     rename => {"[Records][errorCode]" => "errorCode"}
     rename => {"[Records][errorMessage]" => "errorMessage"}
     rename => {"[Records][managementEvent]" => "managementEvent"}
     rename => {"[Records][vpcEndpointId]" => "vpcEndpointId"}
     }
}

}
 
output {
# stdout { codec => rubydebug }
    elasticsearch {
        hosts => 'http://localhost:9200'
        index => 'cloudtrail-2022'
    }
} 

```

I know that after doing this fields like userIdentity are nested fields. I tried forcing the mapping but still didn't work:

```auto
{
"properties": {
  "userIdentity": {
    "type": "nested",
    "properties" : {
      "accessKeyId" : {"type" : "keyword" },
      "accountId" : { "type" : "keyword"},
      "arn" : { "type" : "keyword"},
      "identityProvider" : { "type" : "keyword"},
      "invokedBy" : { "type" : "keyword"},
      "principalId" : { "type" : "keyword"},
      "type" : { "type" : "keyword"},
      "userName" : { "type" : "keyword"},
      "sessionContext" : {
        "type" : "nested",
        "properties" : {
            "attributes" : {
                "type" : "nested",
                "properties" : {
                    "mfaAuthenticated" : { "type" : "keyword"}
                }
            },
            "sessionIssuer" : {
                "type" : "nested",
                    "properties" : {
                        "accountId" : { "type" : "keyword"},
                        "arn" : { "type" : "keyword"},
                        "principalId" : { "type" : "keyword"},
                        "type" : { "type" : "keyword"},
                        "userName" : { "type" : "keyword"}
                    }
            }
        }
      }
    }
    }
  }
}

```

Below you have the kibana screenshot.

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/0/3/035b7190c860daac3ccdf7aa6c8f5e6cb9bc2bc6.png)

I would like to have some guidance on this.  
Thanks in advance for your help.

Best Regards.  
Pedro Cabral

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 10, 2022, 6:01pm UTC](https://discuss.elastic.co/t/logstash-nested-fields-cloudtrail-logs-no-root-field/309568/2 "2022-08-10T18:01:15Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
