# Nested field in a grok filter

**URL:** <https://discuss.elastic.co/t/nested-field-in-a-grok-filter/190758>\
**Category:** Logstash\
**Created:** [July 16, 2019, 2:37pm UTC](https://discuss.elastic.co/t/nested-field-in-a-grok-filter/190758 "2019-07-16T14:37:22Z")\
**Posts on this page:** 1\
**Showing post:** 2

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [July 16, 2019, 3:05pm UTC](https://discuss.elastic.co/t/nested-field-in-a-grok-filter/190758/2 "2019-07-16T15:05:13Z")

</div>

```
    grok { match => { "message" => "^inactive: %{WORD:inactive}, sources : \[(?<[@metadata][sources]>[^\]]+)\], assigned: %{WORD:assigned}" } }
    ruby {
        code => '
            matches = event.get("[@metadata][sources]").scan(/{id:\s*([0-9]+), type:\s*([a-zA-Z0-9]+), name:\s*([a-zA-Z0-9]+)}/)
            event.set("matches", matches)
        '
    }

```

will get you to

```
   "matches" => [
    [0] [
        [0] "1",
        [1] "fr",
        [2] "custom"
    ],
    [1] [
        [0] "2",
        [1] "fr",
        [2] "random"
    ]
]

```

It is unclear what structure you want that data in, so you might be able to move stuff around using mutate, or you may need ruby.

---

_[View the full topic](https://discuss.elastic.co/t/nested-field-in-a-grok-filter/190758)._
