# Merge multiple fields in document into json array

**URL:** <https://discuss.elastic.co/t/merge-multiple-fields-in-document-into-json-array/266036>\
**Category:** Logstash\
**Created:** [March 3, 2021, 2:02am UTC](https://discuss.elastic.co/t/merge-multiple-fields-in-document-into-json-array/266036 "2021-03-03T02:02:12Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![mussa572](https://avatars.discourse-cdn.com/v4/letter/m/a698b9/32.png) [@mussa572](https://discuss.elastic.co/u/mussa572)\
**Post date:** [March 3, 2021, 2:02am UTC](https://discuss.elastic.co/t/merge-multiple-fields-in-document-into-json-array/266036/1 "2021-03-03T02:02:12Z")

</div>

Hi,

I have following document Ingesting into Elasticsearch using the logstash

```auto
    _source": {
           "server_name": "abc",
           "server_ip": "0.0.0.0",
           "server_location: "us"
           "type" : "laptop"
         }

```

I am looking to use logstash to convert the document fields into json object similar to following output for all the fields related to server . I would appreciate if someone can please point the right direction to find the right solution

```auto
    _source": {
          "server { 
             "name" : "abc",
             "ip": "0.0.0.0",
             "location": "us"
                }
          type: laptop

```

---

<div class="post-metadata">

**Author:** ![aaron-nimocks](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/aaron-nimocks/32/73965_2.png) [@aaron-nimocks](https://discuss.elastic.co/u/aaron-nimocks)\
**Post date:** [March 3, 2021, 2:21am UTC](https://discuss.elastic.co/t/merge-multiple-fields-in-document-into-json-array/266036/2 "2021-03-03T02:21:50Z")

</div>

Not sure if your data source actually has `_source` or not. But this should give you an idea.

**Config**

```auto
filter {
  mutate {
    rename => { "server_name" => "[server][name]" }
    rename => { "server_ip" => "[server][ip]" }
    rename => { "server_location" => "[server][location]" }
  }
}

```

**Output**

```auto
{
    "server": {
        "name": "abc",
        "ip": "0.0.0.0",
        "location": "us"
    },
    "type": "laptop"
}

```

---

<div class="post-metadata">

**Author:** ![mussa572](https://avatars.discourse-cdn.com/v4/letter/m/a698b9/32.png) [@mussa572](https://discuss.elastic.co/u/mussa572)\
**Post date:** [March 3, 2021, 5:09pm UTC](https://discuss.elastic.co/t/merge-multiple-fields-in-document-into-json-array/266036/3 "2021-03-03T17:09:56Z")

</div>

Thanks Aaron , Worked as expected

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 31, 2021, 5:10pm UTC](https://discuss.elastic.co/t/merge-multiple-fields-in-document-into-json-array/266036/4 "2021-03-31T17:10:52Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
