# Prevent nested json from appearing in elasticsaerch field

**URL:** <https://discuss.elastic.co/t/prevent-nested-json-from-appearing-in-elasticsaerch-field/310328>\
**Category:** Logstash\
**Created:** [July 21, 2022, 5:48pm UTC](https://discuss.elastic.co/t/prevent-nested-json-from-appearing-in-elasticsaerch-field/310328 "2022-07-21T17:48:15Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![mikhatanu](https://avatars.discourse-cdn.com/v4/letter/m/ba8739/32.png) [@mikhatanu](https://discuss.elastic.co/u/mikhatanu)\
**Post date:** [July 21, 2022, 5:48pm UTC](https://discuss.elastic.co/t/prevent-nested-json-from-appearing-in-elasticsaerch-field/310328/1 "2022-07-21T17:48:16Z")

</div>

Hello, i'm using http filter to do api call to a rest api server. The data returned is json. it looks like this example:

```auto
{
    a:{
        b:{
            c:{}
            d:{}
            e:{}
        }
    }
}

```

I want to prevent logstash from inputing c, d, and e to the elasticsearch field, so the field in elasticsearch will be a and a.b, with a.b field containing value of c,d,e. Any suggestion on how to do this?

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [July 21, 2022, 7:05pm UTC](https://discuss.elastic.co/t/prevent-nested-json-from-appearing-in-elasticsaerch-field/310328/2 "2022-07-21T19:05:56Z")

</div>

So you want to change [a][b] from a hash into a string formed by concatenating the keys from that hash?

---

<div class="post-metadata">

**Author:** ![mikhatanu](https://avatars.discourse-cdn.com/v4/letter/m/ba8739/32.png) [@mikhatanu](https://discuss.elastic.co/u/mikhatanu)\
**Post date:** [July 22, 2022, 2:07am UTC](https://discuss.elastic.co/t/prevent-nested-json-from-appearing-in-elasticsaerch-field/310328/3 "2022-07-22T02:07:58Z")

</div>

the key is automatically mapped to a field in elasticsearch using dynamic mapping. What i want is the dynamic mapping to stop at field [a][b], and let the value of [a][b] to c,d,e, so it doesnt map [a][b][c], [a][b][d], [a][b][e] to a field. Can i do this at logstash level, or should i edit in the elasticsearch template?

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [July 22, 2022, 2:48am UTC](https://discuss.elastic.co/t/prevent-nested-json-from-appearing-in-elasticsaerch-field/310328/4 "2022-07-22T02:48:13Z")

</div>

Can you show the data structure you want as JSON?

---

<div class="post-metadata">

**Author:** ![mikhatanu](https://avatars.discourse-cdn.com/v4/letter/m/ba8739/32.png) [@mikhatanu](https://discuss.elastic.co/u/mikhatanu)\
**Post date:** [July 22, 2022, 3:20am UTC](https://discuss.elastic.co/t/prevent-nested-json-from-appearing-in-elasticsaerch-field/310328/5 "2022-07-22T03:20:29Z")

</div>

I want data c,d,e not to be indexed as a field by elasticsearch, so in kibana the field is only [a][b], not [a][b][c], [a][b][d]. or [a][b][e]

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [July 22, 2022, 3:57am UTC](https://discuss.elastic.co/t/prevent-nested-json-from-appearing-in-elasticsaerch-field/310328/6 "2022-07-22T03:57:26Z")

</div>

It is really unclear what you want. Do you want [a][b][c] to be present on the event but not indexed, or do want to change the value of [a][b]?

> [@](#):
>
> let the value of [a][b] to c,d,e,

I do not understand what you mean by that.

---

<div class="post-metadata">

**Author:** ![mikhatanu](https://avatars.discourse-cdn.com/v4/letter/m/ba8739/32.png) [@mikhatanu](https://discuss.elastic.co/u/mikhatanu)\
**Post date:** [July 22, 2022, 4:04am UTC](https://discuss.elastic.co/t/prevent-nested-json-from-appearing-in-elasticsaerch-field/310328/7 "2022-07-22T04:04:11Z")

</div>

i found the solution to what i want, although i found another problem. basically i want to make c,d,e not indexed as field column. So i use json\_encode filter on field [a][b] to target field [a][`x`] and remove [a][b].  
my json\_encode:

```auto
json_encode {
        source => "[a][b]"
        target => "[a][x]"
  }

```

next, i use gsub to clean/remove the backslash due to json\_encode, but it's not working.  
my gsub filter is:

```auto
mutate{
    gsub => ["[a][x]","[\\]",""]
  }

```

\*\*edit: nvm it's working. It displays correctly in kibana.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 19, 2022, 4:05am UTC](https://discuss.elastic.co/t/prevent-nested-json-from-appearing-in-elasticsaerch-field/310328/8 "2022-08-19T04:05:02Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
