# Logstash ruby filter - put all event fields to dynamic name nested field

**URL:** <https://discuss.elastic.co/t/logstash-ruby-filter-put-all-event-fields-to-dynamic-name-nested-field/146513>\
**Category:** Logstash\
**Created:** [August 29, 2018, 10:43am UTC](https://discuss.elastic.co/t/logstash-ruby-filter-put-all-event-fields-to-dynamic-name-nested-field/146513 "2018-08-29T10:43:34Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![milkamar](https://avatars.discourse-cdn.com/v4/letter/m/e79b87/32.png) [@milkamar](https://discuss.elastic.co/u/milkamar)\
**Post date:** [August 29, 2018, 10:43am UTC](https://discuss.elastic.co/t/logstash-ruby-filter-put-all-event-fields-to-dynamic-name-nested-field/146513/1 "2018-08-29T10:43:34Z")

</div>

Hey,  
to keep it short, I will simplify things a bit.

Let's say I have two filebeats.  
Each filebeat has json output codec and outputs completely different set of fields.  
But, there is a rule - that messages can be paired based on some attribute between those two filebeats.

These two filebeats output to single kafka topic, where-from it reads logstash - and that's where I want to pair my documents.

Also, each filebeat outputs custom field "type", identifying type of the message.

Example:  
Filebeat 1 output:  
{  
"type": "dog\_source\_filebeat01"  
"does\_like\_ham": true  
"likes\_cat\_with\_id": 666  
}

Filebeat 2 output:  
{  
"type": "cat\_source\_filebeat02"  
"meows\_often": false  
"cat\_id": 666  
}

Now I want to process these with logstash and save it together (to single document) in ES in following format:  
{  
"\_id": 666  
"\_source": {  
"cat": { "type": "cat\_source\_filebeat02", "meows\_often": false, "cat\_id": 666 },  
"dog": { "type": "dog\_source\_filebeat01", "does\_like\_ham": true", likes\_cat\_with\_id": 666  
}  
}  
}

So, my questions:

- based on "type" field from filebeat, how can I put all fields in logstash event to nested document ("cat" or "dog") - ideally by ruby code, because there are many fields ? Can you write some example for me ?

Thanks for any response 🙂

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 26, 2018, 10:43am UTC](https://discuss.elastic.co/t/logstash-ruby-filter-put-all-event-fields-to-dynamic-name-nested-field/146513/2 "2018-09-26T10:43:49Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
