# Nested object logstash not parsing correctlly

**URL:** <https://discuss.elastic.co/t/nested-object-logstash-not-parsing-correctlly/366762>\
**Category:** Kibana\
**Created:** [September 18, 2024, 10:36pm UTC](https://discuss.elastic.co/t/nested-object-logstash-not-parsing-correctlly/366762 "2024-09-18T22:36:15Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![miiroslavkardos](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/miiroslavkardos/32/123639_2.png) [@miiroslavkardos](https://discuss.elastic.co/u/miiroslavkardos)\
**Post date:** [September 18, 2024, 10:36pm UTC](https://discuss.elastic.co/t/nested-object-logstash-not-parsing-correctlly/366762/1 "2024-09-18T22:36:15Z")

</div>

Hello , can u help me solve the issue.  
I have nested object "host" =\> { "name" =\> "myserver" } like below

```auto
"cluster" => "xxx-logs",
 "name" => "xxx2",
 "component" => "xxx",
                **"host" => {**
 **"name" => "myserver"**
 **},**

```

If i want to parse it with mutate filter and replace like this :

```auto
 mutate {
                replace => {"host" => "%{[host][name]}"}
                }

```

I got correct value **"host" =\> "myserver"** with output to console like this :

```auto
utput {
                stdout {
                codec => rubydebug
                       }

```

BUT ....  
If I send it to kibana i got this :  
host %{[host][name]}

What am i doing wrong?  
Index field type is text. in index template

---

<div class="post-metadata">

**Author:** ![miiroslavkardos](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/miiroslavkardos/32/123639_2.png) [@miiroslavkardos](https://discuss.elastic.co/u/miiroslavkardos)\
**Post date:** [October 11, 2024, 10:02pm UTC](https://discuss.elastic.co/t/nested-object-logstash-not-parsing-correctlly/366762/2 "2024-10-11T22:02:31Z")

</div>

Anyone?

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [October 12, 2024, 3:33am UTC](https://discuss.elastic.co/t/nested-object-logstash-not-parsing-correctlly/366762/3 "2024-10-12T03:33:51Z")

</div>

You need to share some sample of your logs and your pipeline so people may try to replicate.

Also, share the real output you got on console, you didn't share the output.

And share your index template as well.

Keep in mind that the recommendation is to use ECS fields in the mappings, and `host` is an object in ECS, not a string text.

What is your input? Some inputs will add the `host` field, and it may override and conflict if you also have a host field in your message, but since you didn't provide any information about your input and other filters it is not possible to know.

---

<div class="post-metadata">

**Author:** ![miiroslavkardos](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/miiroslavkardos/32/123639_2.png) [@miiroslavkardos](https://discuss.elastic.co/u/miiroslavkardos)\
**Post date:** [October 14, 2024, 6:45pm UTC](https://discuss.elastic.co/t/nested-object-logstash-not-parsing-correctlly/366762/4 "2024-10-14T18:45:24Z")

</div>

Hello,  
I had wrong name in my filter. Sorry  
Instead of  
`replace => { "host" => "%{[host][hostname]}" }`  
i used  
`replace => { "host" => "%{[host][name]}" }`

This was nested field.

```auto
"host" => {
        "hostname" => "myhostname"

```

And now it is parsed correctly.  
`"hostname" => "myhostname"`

But in Kibana it is still showing like :  
 ![image](https://us1.discourse-cdn.com/elastic/original/3X/4/5/4539567b672f29e52b8a5b1b535c9989f5709242.png)

While rubydebug is correct.  
 ![image](https://us1.discourse-cdn.com/elastic/original/3X/6/5/65704ec01a4ff03fefea7df10dcd0d5b6e6a609b.png)

---

<div class="post-metadata">

**Author:** ![miiroslavkardos](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/miiroslavkardos/32/123639_2.png) [@miiroslavkardos](https://discuss.elastic.co/u/miiroslavkardos)\
**Post date:** [October 14, 2024, 6:52pm UTC](https://discuss.elastic.co/t/nested-object-logstash-not-parsing-correctlly/366762/5 "2024-10-14T18:52:58Z")

</div>

My fields in index linux:  
 ![image](https://us1.discourse-cdn.com/elastic/original/3X/e/9/e952b25acf2446312433f1e153aaac1aec638887.png)

Index template :

```auto
{
  "template": {
    "settings": {
      "index": {
        "lifecycle": {
          "name": "ilm-linux",
          "rollover_alias": "linux"
        },
        "number_of_shards": "10",
        "routing": {
          "allocation": {
            "include": {
              "_tier_preference": "data_content"
            }
          }
        }
      }
    },
    "mappings": {},
    "aliases": {}
  }
}

```

---

<div class="post-metadata">

**Author:** ![miiroslavkardos](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/miiroslavkardos/32/123639_2.png) [@miiroslavkardos](https://discuss.elastic.co/u/miiroslavkardos)\
**Post date:** [October 15, 2024, 6:09pm UTC](https://discuss.elastic.co/t/nested-object-logstash-not-parsing-correctlly/366762/6 "2024-10-15T18:09:18Z")

</div>

And this is event i am trying to parse:  
2024-10-11T13:26:22+02:00 bts-test daemon.info patroni 1328417 - - 2024-10-11 13:26:22,893 INFO: no action. I am (bts-test), a secondary, and following a leader (bts-test2)

---

<div class="post-metadata">

**Author:** ![miiroslavkardos](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/miiroslavkardos/32/123639_2.png) [@miiroslavkardos](https://discuss.elastic.co/u/miiroslavkardos)\
**Post date:** [October 17, 2024, 8:11am UTC](https://discuss.elastic.co/t/nested-object-logstash-not-parsing-correctlly/366762/7 "2024-10-17T08:11:59Z")

</div>

After upgrade to 8.15.2 issue dissaperead maybe bug?
