# Logstash - Nested fields?

**URL:** <https://discuss.elastic.co/t/logstash-nested-fields/266851>\
**Category:** Logstash\
**Created:** [March 10, 2021, 6:00pm UTC](https://discuss.elastic.co/t/logstash-nested-fields/266851 "2021-03-10T18:00:07Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![SaraC](https://avatars.discourse-cdn.com/v4/letter/s/41988e/32.png) [@SaraC](https://discuss.elastic.co/u/SaraC)\
**Post date:** [March 10, 2021, 6:00pm UTC](https://discuss.elastic.co/t/logstash-nested-fields/266851/1 "2021-03-10T18:00:07Z")

</div>

Hi,

I have the following sample of log:

```auto
{
    "@timestamp": "2021-03-10T17:30:58.899Z",
    "@version": "1",
    "Actor": [
        {
            "ID": "Microsoft Intune",
            "Type": 1
        },
        {
            "ID": "0000000a-0000-0000-c000-000000000000",
            "Type": 2
        },
        {
            "ID": "00000000000000000000000000000000000000000000000000000",
            "Type": 2
        },
        {
            "ID": "000000000000000000000000000000000000",
            "Type": 2
        },
        {
            "ID": "ServicePrincipal",
            "Type": 2
        }
    ],
    "ActorContextId": "000000000000000000000000000000000000",
}

```

And I want to drop all the logs that have `"Microsoft Intune"` as `[Actor][ID]`.

I tried different ways through `filter` but nothing worked:  
`if [Actor.ID] == "Microsoft Intune" { drop{} }`  
or  
`if [Actor][ID] == "Microsoft Intune" { drop{} }`  
or  
`if "Microsoft Intune" in [Actor.ID] { drop{} }`

Someone can help me?

Thanks,  
Sara

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [March 10, 2021, 6:15pm UTC](https://discuss.elastic.co/t/logstash-nested-fields/266851/2 "2021-03-10T18:15:52Z")

</div>

I think you would have to use ruby to do that

```
filter {
    ruby {
        code => '
            actor = event.get("Actor")
            if actor.is_a? Array
                actor.each { |x|
                    if actor["ID"] == "Microsoft Intune"
                        event.cancel
                    end
                }
            end
        '
    }
}
```

---

<div class="post-metadata">

**Author:** ![SaraC](https://avatars.discourse-cdn.com/v4/letter/s/41988e/32.png) [@SaraC](https://discuss.elastic.co/u/SaraC)\
**Post date:** [March 10, 2021, 6:31pm UTC](https://discuss.elastic.co/t/logstash-nested-fields/266851/3 "2021-03-10T18:31:41Z")

</div>

Hi @Badger,

thanks for reply. If I would add a field, for example:  
`drop:yes`  
how could the code change?

Anyway I tried to change my pipeline but I obtain the following error:  
`[ERROR][logstash.filters.ruby] Ruby exception occurred: no implicit conversion of String into Integer`

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [March 10, 2021, 7:10pm UTC](https://discuss.elastic.co/t/logstash-nested-fields/266851/4 "2021-03-10T19:10:32Z")

</div>

> [@Badger](#):
>
> `if actor["ID"] == "Microsoft Intune"`

That should be `if x["ID"] == "Microsoft Intune"`. actor is an array, so it has to be indexed using an integer. x is a hash, so it is indexed using a key.

I do not understand your question about adding a field.

---

<div class="post-metadata">

**Author:** ![SaraC](https://avatars.discourse-cdn.com/v4/letter/s/41988e/32.png) [@SaraC](https://discuss.elastic.co/u/SaraC)\
**Post date:** [March 10, 2021, 7:47pm UTC](https://discuss.elastic.co/t/logstash-nested-fields/266851/5 "2021-03-10T19:47:51Z")

</div>

Instead of directly deleting the log whose `ID` field was `"Microsoft Intune"`, I thought of "marking" it with a `drop` field.  
How can I do it in ruby?

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [March 10, 2021, 7:49pm UTC](https://discuss.elastic.co/t/logstash-nested-fields/266851/6 "2021-03-10T19:49:46Z")

</div>

Use the [event api](https://www.elastic.co/guide/en/logstash/current/event-api.html)

```
event.set("drop", true)
```

---

<div class="post-metadata">

**Author:** ![SaraC](https://avatars.discourse-cdn.com/v4/letter/s/41988e/32.png) [@SaraC](https://discuss.elastic.co/u/SaraC)\
**Post date:** [March 11, 2021, 10:51am UTC](https://discuss.elastic.co/t/logstash-nested-fields/266851/7 "2021-03-11T10:51:20Z")

</div>

Thank you very much @Badger  
With your solution I solved my issue.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 8, 2021, 10:51am UTC](https://discuss.elastic.co/t/logstash-nested-fields/266851/8 "2021-04-08T10:51:32Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
