# Using "key/value with nested fields" with logstash

**URL:** <https://discuss.elastic.co/t/using-key-value-with-nested-fields-with-logstash/95340>\
**Category:** Logstash\
**Created:** [August 1, 2017, 1:02pm UTC](https://discuss.elastic.co/t/using-key-value-with-nested-fields-with-logstash/95340 "2017-08-01T13:02:31Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![widhalmt](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/widhalmt/32/8237_2.png) [@widhalmt](https://discuss.elastic.co/u/widhalmt)\
**Post date:** [August 1, 2017, 1:02pm UTC](https://discuss.elastic.co/t/using-key-value-with-nested-fields-with-logstash/95340/1 "2017-08-01T13:02:31Z")

</div>

Hi,

I have a problem where someone logs lots of different JSON logs into Logstash which forwards them to Elasticsearch. There are so many fields that we hit the 1000 threshold of fields per index. To prevent mapping explosion we don't want to raise this limit.

I read about using "key/value with nested fields" in [Limit of total fields [1000] in index has been exceeded](https://discuss.elastic.co/t/limit-of-total-fields-1000-in-index-has-been-exceeded/87280) and saw an example in [https://www.elastic.co/blog/found-crash-elasticsearch#mapping-explosion](https://www.elastic.co/blog/found-crash-elasticsearch#mapping-explosion) but I wonder how I would achieve that with Logstash.

Could anyone give me a hint how to split long fieldnames (containing .) in a way I can avoid mapping explosion?

My problem is that there might come in new field names any time so I need an automatic way of splitting.

Thanks in advance!

---

<div class="post-metadata">

**Author:** ![widhalmt](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/widhalmt/32/8237_2.png) [@widhalmt](https://discuss.elastic.co/u/widhalmt)\
**Post date:** [August 1, 2017, 3:25pm UTC](https://discuss.elastic.co/t/using-key-value-with-nested-fields-with-logstash/95340/2 "2017-08-01T15:25:20Z")

</div>

I just saw that the "dedot" filter of Logstash provides the capability to replace dots with nested fields, not just replace dots with another character. Could this solve my problem?

Will heavily nested be fields be better with Elasticsearch than lots of different fieldnames? (Maybe I should ask this in the Elasticsearch forums, too)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 29, 2017, 3:25pm UTC](https://discuss.elastic.co/t/using-key-value-with-nested-fields-with-logstash/95340/3 "2017-08-29T15:25:29Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
