Using grok on just one field

To refer to a nested field, you specify the full path to that field: [top-level field][nested field].

But _source is an elasticsearch concept. It is not present in logstash.

1 Like