# Nested JSON flattened in Logstash Filter

**URL:** <https://discuss.elastic.co/t/nested-json-flattened-in-logstash-filter/281502>\
**Category:** Logstash\
**Created:** [August 16, 2021, 5:57am UTC](https://discuss.elastic.co/t/nested-json-flattened-in-logstash-filter/281502 "2021-08-16T05:57:41Z")\
**Posts on this page:** 1\
**Showing post:** 2

<div class="post-metadata">

**Author:** ![Divyank\_Mahalle](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/divyank_mahalle/32/91240_2.png) [@Divyank\_Mahalle](https://discuss.elastic.co/u/Divyank_Mahalle)\
**Post date:** [August 16, 2021, 8:11am UTC](https://discuss.elastic.co/t/nested-json-flattened-in-logstash-filter/281502/2 "2021-08-16T08:11:47Z")

</div>

Updated Filter which flattens double nested JSON-

Ref link-[https://discuss.elastic.co/t/flatten-json-array-in-logstash-filter/124562](https://discuss.elastic.co/t/flatten-json-array-in-logstash-filter/124562)

```auto
filter{

 split { field => "[resources]" }

  mutate {
    add_field => {
      "resource_price_per_hour" => "%{[resources][price_per_hour]}"
      "resource_instance_count" => "%{[resources][instance_count]}"
      "resource_name" => "%{[resources][name]}"
       "resource_sku" => "%{[resources][sku]}"
       "resource_price" => "%{[resources][price]}"
       "resource_hours" => "%{[resources][hours]}"
       "resource_kind" => "%{[resources][kind]}"
      "resource_period_start" => "%{[resources][period][start]}"
      "resource_period_end" => "%{[resources][period][end]}"

    }
    remove_field => ["[resources]" ]
  }

   split { field => "[data_transfer_and_storage]" }

  mutate {
    add_field => {
      "data_name" => "%{[data_transfer_and_storage][name]}"
      "data_sku" => "%{[data_transfer_and_storage][sku]}"
      "data_cost" => "%{[data_transfer_and_storage][cost]}"
      "data_type" => "%{[data_transfer_and_storage][type]}"
      "data_quantity1" => "%{[data_transfer_and_storage][quantity][formatted_value]}"
      "data_quantity2" => "%{[data_transfer_and_storage][quantity][value]}"
     "data_rate1" => "%{[data_transfer_and_storage][rate][formatted_value]}"
      "data_rate2" => "%{[data_transfer_and_storage][rate][value]}"

 }
    remove_field => ["[data_transfer_and_storage]" ]
  }
}

```

---

_[View the full topic](https://discuss.elastic.co/t/nested-json-flattened-in-logstash-filter/281502)._
