# Nested Field Different Data Types

**URL:** <https://discuss.elastic.co/t/nested-field-different-data-types/131422>\
**Category:** Logstash\
**Created:** [May 11, 2018, 7:25am UTC](https://discuss.elastic.co/t/nested-field-different-data-types/131422 "2018-05-11T07:25:46Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Johnnycc1](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/johnnycc1/32/26069_2.png) [@Johnnycc1](https://discuss.elastic.co/u/Johnnycc1)\
**Post date:** [May 11, 2018, 7:25am UTC](https://discuss.elastic.co/t/nested-field-different-data-types/131422/1 "2018-05-11T07:25:47Z")

</div>

Heya, I have a source document that fails to load into elastic search.  
The reason is that the source document contains text in a nested field that should be of type boolean.

I would like to process this log in logstash to make it loadable in elastic. This is what the source document looks like --\>

```
{
  "date": "2018-01-01",
  "source": "ABC",
  "data": [
    {
      "id": 1,
      "field1": true,
      "field2": false,
      "field3": true
    },
    {
      "id": 2,
      "field1": true,
      "field2": false,
      "field3": nil
    }
  ]
}

```

Logically what I want to do is check if the nested field is "True" and if not set the value to "False". However I have not been able to break into the nested document to do any checks. I think it should look something like this however I'm just guessing --\>

```
ruby => "
  k = event.get('[data]')
  k.to_hash.each do { 
  | index | 
  if event.get('[data][index][field3]') == "True"
      event.set('[data][index][field3]', "True")
  else
      event.set('[data][index][field3]', "False")
  end
        }"

```

I would love some help.

---

<div class="post-metadata">

**Author:** ![paz](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/paz/32/28003_2.png) [@paz](https://discuss.elastic.co/u/paz)\
**Post date:** [May 11, 2018, 8:34am UTC](https://discuss.elastic.co/t/nested-field-different-data-types/131422/2 "2018-05-11T08:34:48Z")

</div>

Your base logic is indeed correct, minor Ruby script errors aside. Something like this should do what you want

```auto
    ruby {
        code => "
            k = event.get('[data]')
            k.each_index { | index |
                if event.get('[data]['+index.to_s+'][field3]') == 'true'
                    event.set('[data]['+index.to_s+'][field3]', true)
                else
                    event.set('[data]['+index.to_s+'][field3]', false)
                end
            }
        "
    }
```

---

<div class="post-metadata">

**Author:** ![Johnnycc1](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/johnnycc1/32/26069_2.png) [@Johnnycc1](https://discuss.elastic.co/u/Johnnycc1)\
**Post date:** [May 11, 2018, 9:03am UTC](https://discuss.elastic.co/t/nested-field-different-data-types/131422/3 "2018-05-11T09:03:11Z")

</div>

Wow - thanks for the response Paz.

It runs perfectly.

I must say I would never have got that - thank you so much.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 8, 2018, 9:03am UTC](https://discuss.elastic.co/t/nested-field-different-data-types/131422/4 "2018-06-08T09:03:22Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
