# Report based on json field cn

**URL:** <https://discuss.elastic.co/t/report-based-on-json-field-cn/152408>\
**Category:** Kibana\
**Created:** [October 14, 2018, 9:01pm UTC](https://discuss.elastic.co/t/report-based-on-json-field-cn/152408 "2018-10-14T21:01:18Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![atj5206](https://avatars.discourse-cdn.com/v4/letter/a/ecd19e/32.png) [@atj5206](https://discuss.elastic.co/u/atj5206)\
**Post date:** [October 14, 2018, 9:01pm UTC](https://discuss.elastic.co/t/report-based-on-json-field-cn/152408/1 "2018-10-14T21:01:18Z")

</div>

Hello, we are trying to create a report from a JSON log field that contain nested objects. Aggregation is not necessary, but that'd be a plus (ideally we could have a count).

JSON log sample for "cookie" field

"cookie":[{"name":"cookie1","a":11,"b":11,"c":11},{"name":"cookie2","a":22,"b":22,"c":22},{"name":"cookie3","a":3,"b":3,"c":3}]}

We want our report to look like:

cookie | a | b | c (header row)

cookie1 11 11 11

cookie2 22 22 22

cookie3 3 3 3

It'd be great if the cookie names and values could be delimited into separate columns, but even if this data were all dumped into a one-column report, that would be fine.

Is this possible?

Many thanks!

---

<div class="post-metadata">

**Author:** ![jbudz](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jbudz/32/45922_2.png) [@jbudz](https://discuss.elastic.co/u/jbudz)\
**Post date:** [October 15, 2018, 10:49pm UTC](https://discuss.elastic.co/t/report-based-on-json-field-cn/152408/2 "2018-10-15T22:49:25Z")

</div>

Unfortunately Kibana's going to struggle with this format, I'm having a hard time thinking of a way. Without aggregations, reports are going to be one row per document. With aggregations, there's limited support for nested fields.

Is reformatting the data an option? If we work backwards from this format, something like below would work:

```auto
{
  name: cookie1,
  a: 11,
  b: 11,
  c: 11
}

```

---

<div class="post-metadata">

**Author:** ![atj5206](https://avatars.discourse-cdn.com/v4/letter/a/ecd19e/32.png) [@atj5206](https://discuss.elastic.co/u/atj5206)\
**Post date:** [October 15, 2018, 11:00pm UTC](https://discuss.elastic.co/t/report-based-on-json-field-cn/152408/3 "2018-10-15T23:00:32Z")

</div>

Thank you for getting back, Jon.

We do have the flexibility to change the log format. However, we need to include information on multiple cookies in each log record. (We cannot split out the log to one cookie per record, it will be too noisy.)

How would the format you proposed look if there is more than one cookie?

Please let me know if you have any suggestion or ideas.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 12, 2018, 11:07pm UTC](https://discuss.elastic.co/t/report-based-on-json-field-cn/152408/4 "2018-11-12T23:07:40Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
