I need help regarding elastic search mapping of nested json response. I am using the meatricbeat's http module to query data from our asset management system and I am getting the following response in return
"fields": [
{
"displayName": "IT Vertical",
"value": "Data Analytics"
},
{
"displayName": "Serial Number",
"value": "VMware-XXXXXXXXXXXX"
},
{
"displayName": "System Name",
"value": "Test-Virtual-Machine"
}
]
Based on what I have found on google, the above looks like a nested json response where the "key" is the value for "displayName" and the "value" is the value of the value field. for example:
----Key---------------value----------
IT Vertical-------Data Analytics
Serial Number-----VMware-XXXXXXXXXXXX
System Name-------Test-Virtual-Machine
I am able to use processors inside the http module and ideally I would like to shape the data before it gets to logstash/elasticsearch. But if that is not possible, then is it possible to modify this data accordingly by using ingest pipeline node? if so, any ideas how?