# Logstash - Nested fields

**URL:** <https://discuss.elastic.co/t/logstash-nested-fields/100201>\
**Category:** Logstash\
**Created:** [September 12, 2017, 11:37am UTC](https://discuss.elastic.co/t/logstash-nested-fields/100201 "2017-09-12T11:37:53Z")\
**Posts on this page:** 1\
**Showing post:** 3

<div class="post-metadata">

**Author:** ![NerdSec](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nerdsec/32/22056_2.png) [@NerdSec](https://discuss.elastic.co/u/NerdSec)\
**Post date:** [September 13, 2017, 8:33am UTC](https://discuss.elastic.co/t/logstash-nested-fields/100201/3 "2017-09-13T08:33:58Z")

</div>

I think what i want to achieve is a Nested datatype.  
Alright, now that I have realized my mistake, let me rephrase it. How do i create nested documents in Elasticssearch using Logstash?

I realize that you might need to use the Ruby filter. Any pointers or sample filter that I can refer? Not very familiar with Ruby.

> Here are some links I found:

> [@Best Way to create nested field](https://discuss.elastic.co/t/best-way-to-create-nested-field/26757/3):
>
> Is it possible to do the same thing with the all body message? (without to to it for all single fields) Example: "something1":"11111", "something2":"22222", "something3":"33333" transform it in: event{ payload{ "something1":"11111", "something2":"22222", "something3":"33333" } }

[https://discuss.elastic.co/t/field-name-cannot-contain/33251/49](https://discuss.elastic.co/t/field-name-cannot-contain/33251/49)

---

_[View the full topic](https://discuss.elastic.co/t/logstash-nested-fields/100201)._
