# Netsted JSON field handling

**URL:** <https://discuss.elastic.co/t/netsted-json-field-handling/136377>\
**Category:** Kibana\
**Created:** [June 18, 2018, 9:57pm UTC](https://discuss.elastic.co/t/netsted-json-field-handling/136377 "2018-06-18T21:57:40Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![kant.gaurav](https://avatars.discourse-cdn.com/v4/letter/k/e47c2d/32.png) [@kant.gaurav](https://discuss.elastic.co/u/kant.gaurav)\
**Post date:** [June 18, 2018, 9:57pm UTC](https://discuss.elastic.co/t/netsted-json-field-handling/136377/1 "2018-06-18T21:57:40Z")

</div>

I am using ELK 6.3.0 version  
My JSON Structure is like below

```auto
{
Field1: Value1
"nestedField":[
                   {
                       "KeyName":"Key1"
                       "KeyValue":"Key1Value1"
                  },{
                       "KeyName":"Key2"
                       "KeyValue":"Key2Value2"
                  }]
}

```

when I am creating a Pie chart on "nestedField.KeyName", graph is including values in both KeyNames. for Example: in Pie chart for KeyName, graph is divided into two parts "Key1" and "Key2". when I further split it by "KeyValue", Key1value1 and Key2value2 are showing at both sides of Keys. Key1 portion showing Keyvalue: Key1Value1 and Key2Value2. same as Key1.

Kindly suggest.

---

<div class="post-metadata">

**Author:** ![bhavyarm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bhavyarm/32/22392_2.png) [@bhavyarm](https://discuss.elastic.co/u/bhavyarm)\
**Post date:** [June 19, 2018, 7:52pm UTC](https://discuss.elastic.co/t/netsted-json-field-handling/136377/2 "2018-06-19T19:52:33Z")

</div>

Hi,

I am going to tag our viz team here: @timroes / @ppisljar

Thanks,  
Bhavya

---

<div class="post-metadata">

**Author:** ![timroes](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/timroes/32/19712_2.png) [@timroes](https://discuss.elastic.co/u/timroes)\
**Post date:** [June 20, 2018, 6:35am UTC](https://discuss.elastic.co/t/netsted-json-field-handling/136377/3 "2018-06-20T06:35:29Z")

</div>

Hi,

this is related to the way Elasticsearch stores these documents. It will actually by default not have the link any more about the individual documents, i.e. your document will look like the following:

```json
{
  "Field1": "Value1",
  "nestedField.KeyName": ["Key1", "Key2"],
  "nestedField.KeyValue": ["Key1Value1", "Key2Value2"]
}

```

That's why filtering by "nestedField.KeyName:Key1" will just retrieve that document, which again has both nested field key values present.

If you need that distinction between original documents you want to look into [Nested datatypes](https://www.elastic.co/guide/en/elasticsearch/reference/current/nested.html). But please be aware, that those are currently not supported by Kibana nateively ([#1084](https://github.com/elastic/kibana/issues/1084)), but you could have a look at the [Kibana Nested Support Plugin](https://github.com/ppadovani/KibanaNestedSupportPlugin) by the community.

Cheers,  
Tim

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 18, 2018, 6:35am UTC](https://discuss.elastic.co/t/netsted-json-field-handling/136377/4 "2018-07-18T06:35:30Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
