# Nested object visualization

**URL:** <https://discuss.elastic.co/t/nested-object-visualization/192377>\
**Category:** Kibana\
**Created:** [July 26, 2019, 7:48am UTC](https://discuss.elastic.co/t/nested-object-visualization/192377 "2019-07-26T07:48:37Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![theo1991](https://avatars.discourse-cdn.com/v4/letter/t/4da419/32.png) [@theo1991](https://discuss.elastic.co/u/theo1991)\
**Post date:** [July 26, 2019, 7:48am UTC](https://discuss.elastic.co/t/nested-object-visualization/192377/1 "2019-07-26T07:48:37Z")

</div>

Hello,

Is it possible to select a nested object to visualize in Kibana ? I want to select the first field in this nested object.  
Here is my filter :

grok :

`u'rules': \[(?<[@metadata][rules]>[^\]]+)\]`

ruby :

```
rules = event.get('[@metadata][rules]')
		if rules
			rule = rules.scan(/{u'type': u'([^']+)', u'id': ([0-9]+)}/)
			event.set('rule', rule)
		end

```

Index mapped by elasticsearch :

```
"rule": {
        "type": "text",
        "fields": {
          "keyword": {
            "type": "keyword",
            "ignore_above": 256
          }
        }
      }, 

```

In the visualization, when I select rule.keyword, I'm not able to select which field I want :

![image](https://us1.discourse-cdn.com/elastic/original/3X/b/c/bc41d1c0e60b7b9e5657d494fffe1713ff5522ed.png)

Do I have to add something in JSON input in the advanced settings of the visualization ?

---

<div class="post-metadata">

**Author:** ![wylie](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/wylie/32/81794_2.png) [@wylie](https://discuss.elastic.co/u/wylie)\
**Post date:** [July 26, 2019, 4:23pm UTC](https://discuss.elastic.co/t/nested-object-visualization/192377/2 "2019-07-26T16:23:23Z")

</div>

I don't think what you are describing is a "Nested object", what you have is a dual mapping. If you want to select specific terms, you can either:

- Use the Terms aggregation and specify specific Include/Exclude values in the additional options menu for that aggregation
- Use a Filters aggregation and specify a query that filters only the documents you want to match.

If you are actually intending to create a nested object mapping, your configuration is not correct: [https://www.elastic.co/guide/en/elasticsearch/reference/current/nested.html](https://www.elastic.co/guide/en/elasticsearch/reference/current/nested.html) (but if you are trying to do this, Kibana does not currently supported that kind of mapping)

---

<div class="post-metadata">

**Author:** ![theo1991](https://avatars.discourse-cdn.com/v4/letter/t/4da419/32.png) [@theo1991](https://discuss.elastic.co/u/theo1991)\
**Post date:** [August 8, 2019, 2:18pm UTC](https://discuss.elastic.co/t/nested-object-visualization/192377/3 "2019-08-08T14:18:12Z")

</div>

Hello wylie,

Sorry for the delay, and thank you for your answer.  
My results are like this in discovery when I click on rules :  
["RULE","888821"]  
["OTHER\_RULE","888822"]

So I think you're right, it's a dual mapping.  
But how can I tell to kibana when I want to make my visualization, to do not use the first field (here "RULE" "OTHER\_RULE" etc) ?

Thank you

---

<div class="post-metadata">

**Author:** ![wylie](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/wylie/32/81794_2.png) [@wylie](https://discuss.elastic.co/u/wylie)\
**Post date:** [August 8, 2019, 3:21pm UTC](https://discuss.elastic.co/t/nested-object-visualization/192377/4 "2019-08-08T15:21:48Z")

</div>

You might be able to construct a scripted field to access the value you want using painless scripting. I'm not sure I can provide an exact script for you to try, but that approach would give you more control over the value.

Also, it looks like this is an array field, I would highly recommend reading the limitations Elasticsearch has for that kind of data: [https://www.elastic.co/guide/en/elasticsearch/reference/current/array.html](https://www.elastic.co/guide/en/elasticsearch/reference/current/array.html)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 5, 2019, 3:21pm UTC](https://discuss.elastic.co/t/nested-object-visualization/192377/5 "2019-09-05T15:21:50Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
