# Set all nested fields value into master field

**URL:** <https://discuss.elastic.co/t/set-all-nested-fields-value-into-master-field/257676>\
**Category:** Logstash\
**Created:** [December 4, 2020, 4:01pm UTC](https://discuss.elastic.co/t/set-all-nested-fields-value-into-master-field/257676 "2020-12-04T16:01:17Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Raynald](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/raynald/32/78897_2.png) [@Raynald](https://discuss.elastic.co/u/Raynald)\
**Post date:** [December 4, 2020, 4:01pm UTC](https://discuss.elastic.co/t/set-all-nested-fields-value-into-master-field/257676/1 "2020-12-04T16:01:17Z")

</div>

Hi everyone,  
I have an index that can growth with many nested fileds, and we want to limit nested field to one sub-level for identified fields. But we want to keep value of this nested fields into the master field

Example : we have [Properties][Request] and some nested fields under. We want to merge all nested fields value in this field [Properties][Request]

```
"Properties": {
  "Request": {
    "SourceApplicationName": "Pulsar",
    "_typeTag": "BusMessage",
    "ResponseContent": {
      "TransactionBoutiqueId": "e383cde3-c802-4068-8141-41b3e91614a2"
    },
    "MessageType": "CreationTransactionBoutique"
  },

```

Nested fields created =

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/8/0/803296c681dfbcd2ab8ee39aa85dc43a2d5ecf7b.png)

Is this possible with ruby code ? May I have to change type of this field like object ?  
Please help me 😢

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [December 4, 2020, 5:28pm UTC](https://discuss.elastic.co/t/set-all-nested-fields-value-into-master-field/257676/2 "2020-12-04T17:28:01Z")

</div>

If you use

```
ruby { code => 'event.set("[Properties][Request]", event.get("[Properties][Request]").to_s)' }

```

then you will get

```
"Properties" => {
    "Request" => "{\"ResponseContent\"=>{\"TransactionBoutiqueId\"=>\"e383cde3-c802-4068-8141-41b3e91614a2\"}, \"SourceApplicationName\"=>\"Pulsar\", \"_typeTag\"=>\"BusMessage\", \"MessageType\"=>\"CreationTransactionBoutique\"}"
}

```

Is that what you want?

---

<div class="post-metadata">

**Author:** ![Raynald](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/raynald/32/78897_2.png) [@Raynald](https://discuss.elastic.co/u/Raynald)\
**Post date:** [December 4, 2020, 5:41pm UTC](https://discuss.elastic.co/t/set-all-nested-fields-value-into-master-field/257676/3 "2020-12-04T17:41:44Z")

</div>

> [@Badger](#):
>
> `ruby { code => 'event.set("[Properties][Request]", event.get("[Properties][Request]").to_s)' }`

It seems great, but I have this error now :  
`[2020-12-04T18:32:30,541][WARN][logstash.outputs.elasticsearch][filebeat][6e073c6b616c6ca446d26fab2bb97470efec21ec69c1856a775e76d571d79480] Could not index event to Elasticsearch. {:status=>400, :action=>["index", {:_id=>nil, :_index=>"pulsar", :routing=>nil, :_type=>"_doc"}, #<LogStash::Event:0x5301153d>], :response=>{"index"=>{"_index"=>"pulsar", "_type"=>"_doc", "_id"=>"Sw7PLnYBuisqXDVb-dMb", "status"=>400, "error"=>{"type"=>"mapper_parsing_exception", "reason"=>"object mapping for [Properties.Request] tried to parse field [Request] as object, but found a concrete value"}}}}`

Should I have to change index mapping for this field ?  
Thx Badger.

---

<div class="post-metadata">

**Author:** ![Raynald](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/raynald/32/78897_2.png) [@Raynald](https://discuss.elastic.co/u/Raynald)\
**Post date:** [December 4, 2020, 6:01pm UTC](https://discuss.elastic.co/t/set-all-nested-fields-value-into-master-field/257676/4 "2020-12-04T18:01:42Z")

</div>

Resolved with delete index to have new mapping. And then it is OK.

Thank you !! ☀

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 1, 2021, 6:01pm UTC](https://discuss.elastic.co/t/set-all-nested-fields-value-into-master-field/257676/5 "2021-01-01T18:01:45Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
