# Unable to create nested json output (aggregated) from csv input

**URL:** <https://discuss.elastic.co/t/unable-to-create-nested-json-output-aggregated-from-csv-input/162630>\
**Category:** Logstash\
**Created:** [January 2, 2019, 10:05am UTC](https://discuss.elastic.co/t/unable-to-create-nested-json-output-aggregated-from-csv-input/162630 "2019-01-02T10:05:56Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![Deepak\_Singhal](https://avatars.discourse-cdn.com/v4/letter/d/bcef8e/32.png) [@Deepak\_Singhal](https://discuss.elastic.co/u/Deepak_Singhal)\
**Post date:** [January 2, 2019, 10:05am UTC](https://discuss.elastic.co/t/unable-to-create-nested-json-output-aggregated-from-csv-input/162630/1 "2019-01-02T10:05:56Z")

</div>

Issue I am facing is I need aggregation of Csv inputs on ID, and it contains multiple nesting , I am able to perform single nesting , but on further nesting, I am not able to write correct syntax.

PFA input, output I am getting , and output I want:

\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\* INPUT \*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*

input {  
generator {  
id =\> "first"  
type =\> 'csv'  
message =\> '829cd0e0-8d24-4f25-92e1-724e6bd811e0,GSIH1,2017-10-10 00:00:00.000,HCC,0.83,COMMUNITYID1'  
count =\> 1  
}  
generator {  
id =\> "second"  
type =\> 'csv'  
message =\> '829cd0e0-8d24-4f25-92e1-724e6bd811e0,GSIH1,2017-10-10 00:00:00.000,LACE,12,COMMUNITYID1'  
count =\> 1  
}  
generator {  
id =\> "third"  
type =\> 'csv'  
message =\> '829cd0e0-8d24-4f25-92e1-724e6bd811e0,GSIH1,2017-10-10 00:00:00.000,CCI,0.23,COMMUNITYID1'  
count =\> 1  
}  
}

filter  
{  
csv {  
columns =\> ['id', 'reference', 'occurrenceDateTime', 'code', 'probabilityDecimal', 'comment']  
}  
mutate {  
rename =\> {  
"reference" =\> "[subject][reference]"  
"code" =\> "[prediction][outcome][coding][code]"  
"probabilityDecimal" =\> "[prediction][probabilityDecimal]"  
}  
}  
mutate {  
add\_field =\> {  
"[resourceType]" =\> "RiskAssessment"  
"[prediction][outcome][text]" =\> "Member HCC score based on CMS HCC V22 risk adjustment model"  
"[status]" =\> "final"  
}  
}  
mutate {  
update =\> {  
"[subject][reference]" =\> "Patient/%{[subject][reference]}"  
"[comment]" =\> "CommunityId/%{[comment]}"  
}  
}  
mutate {  
remove\_field =\> ["@timestamp", "sequence", "@version", "message", "host", "type"]  
}  
}

filter {  
aggregate {  
task\_id =\> "%{id}"  
code =\> "  
map['resourceType'] = event.get('resourceType')  
map['id'] = event.get('id')  
map['status'] = event.get('status')  
map['occurrenceDateTime'] = event.get('occurrenceDateTime')  
map['comment'] = event.get('comment')  
map['[reference]'] = event.get('[subject][reference]')  
map['[prediction]'] ||=   
map['[prediction]'] \<\< {  
'code' =\> event.get('[prediction][outcome][coding][code]'),  
'text' =\> event.get('[prediction][outcome][text]'),  
'probabilityDecimal'=\> event.get('[prediction][probabilityDecimal]')  
}  
event.cancel()  
"  
push\_previous\_map\_as\_event =\> true  
timeout =\> 3  
}  
mutate {  
remove\_field =\> ["@timestamp", "tags", "@version"]  
}  
}

output{  
elasticsearch {  
template =\> "templates/riskFactor.json"  
template\_name =\> "riskFactor"  
action =\> "index"  
hosts =\> ["localhost:9201"]  
index =\> ["deepak"]  
}  
stdout {  
codec =\> json{}  
}  
}

\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\* OUTPUT \*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*

{  
"reference": "Patient/GSIH1",  
"comment": "CommunityId/COMMUNITYID1",  
"id": "829cd0e0-8d24-4f25-92e1-724e6bd811e0",  
"status": "final",  
"resourceType": "RiskAssessment",  
"occurrenceDateTime": "2017-10-10 00:00:00.000",  
"prediction": [{  
"probabilityDecimal": "0.83",  
"code": "HCC",  
"text": "Member HCC score based on CMS HCC V22 risk adjustment model"  
}, {  
"probabilityDecimal": "0.23",  
"code": "CCI",  
"text": "Member HCC score based on CMS HCC V22 risk adjustment model"  
}, {  
"probabilityDecimal": "12",  
"code": "LACE",  
"text": "Member HCC score based on CMS HCC V22 risk adjustment model"  
}]  
}

\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\* REQUIRED OUTPUT \*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*

{  
"resourceType": "RiskAssessment",  
"id": "829cd0e0-8d24-4f25-92e1-724e6bd811e0",  
"status": "final",  
"subject": {  
"reference": "Patient/GSIH1"  
},  
"occurrenceDateTime": "2017-10-10 00:00:00.000",  
"prediction": [{  
"outcome": {  
"coding": [{  
"code": "HCC"  
}],  
"text": "Member HCC score based on CMS HCC V22 risk adjustment model"  
},  
"probabilityDecimal": 0.83  
},  
{  
"outcome": {  
"coding": [{  
"code": "CCI"  
}],  
"text": "Member HCC score based on CMS HCC V22 risk adjustment model"  
},  
"probabilityDecimal": 0.83  
}

```
],
"comment": "CommunityId/COMMUNITYID1"

```

}

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 30, 2019, 10:19am UTC](https://discuss.elastic.co/t/unable-to-create-nested-json-output-aggregated-from-csv-input/162630/2 "2019-01-30T10:19:56Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
