# Parent-Child Relationship with logstash

**URL:** <https://discuss.elastic.co/t/parent-child-relationship-with-logstash/33545>\
**Category:** Logstash\
**Created:** [November 2, 2015, 5:04pm UTC](https://discuss.elastic.co/t/parent-child-relationship-with-logstash/33545 "2015-11-02T17:04:44Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![Hornov](https://avatars.discourse-cdn.com/v4/letter/h/c67d28/32.png) [@Hornov](https://discuss.elastic.co/u/Hornov)\
**Post date:** [November 2, 2015, 5:04pm UTC](https://discuss.elastic.co/t/parent-child-relationship-with-logstash/33545/1 "2015-11-02T17:04:44Z")

</div>

I try to integrade child data with logstash but I can't.  
For example I tried to use a \_parent field with the value of the parent id but it did'nt work.  
Do you have any idea ?

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [November 3, 2015, 12:43am UTC](https://discuss.elastic.co/t/parent-child-relationship-with-logstash/33545/2 "2015-11-03T00:43:58Z")

</div>

You can't do this with logstash unfortunately.

---

<div class="post-metadata">

**Author:** ![drdebian](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/drdebian/32/5622_2.png) [@drdebian](https://discuss.elastic.co/u/drdebian)\
**Post date:** [November 3, 2015, 6:03am UTC](https://discuss.elastic.co/t/parent-child-relationship-with-logstash/33545/3 "2015-11-03T06:03:34Z")

</div>

This is kinda sad, actually. It appears that some work has already been done in that direction, all that seems to be missing is somebody writing a test: [https://github.com/logstash-plugins/logstash-output-elasticsearch/pull/175](https://github.com/logstash-plugins/logstash-output-elasticsearch/pull/175)

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [November 3, 2015, 7:03am UTC](https://discuss.elastic.co/t/parent-child-relationship-with-logstash/33545/4 "2015-11-03T07:03:07Z")

</div>

Feel free to +1 the PR so it gets some attention 🙂

---

<div class="post-metadata">

**Author:** ![Thorsten\_Nickel](https://avatars.discourse-cdn.com/v4/letter/t/3be4f8/32.png) [@Thorsten\_Nickel](https://discuss.elastic.co/u/Thorsten_Nickel)\
**Post date:** [November 3, 2015, 8:22am UTC](https://discuss.elastic.co/t/parent-child-relationship-with-logstash/33545/5 "2015-11-03T08:22:07Z")

</div>

Perhaps you can 'workaround' using the nested field syntax ?

i.e.

```
%{NUMBER:[cpu][load1]:float}
%{NUMBER:[cpu][load5]:float}
%{NUMBER:[cpu][load15]:float}

```

which should translate to elastic fields like cpu.load1 etc.

Hope to help,  
Thorsten

---

<div class="post-metadata">

**Author:** ![alaviamir](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/alaviamir/32/10167_2.png) [@alaviamir](https://discuss.elastic.co/u/alaviamir)\
**Post date:** [June 27, 2016, 7:52pm UTC](https://discuss.elastic.co/t/parent-child-relationship-with-logstash/33545/6 "2016-06-27T19:52:50Z")

</div>

Wouldn't that be a nested relationship as opposed to parent-child relationship?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 4:50am UTC](https://discuss.elastic.co/t/parent-child-relationship-with-logstash/33545/7 "2017-07-06T04:50:46Z")

</div>


