# Adding JSON fields Kibana

**URL:** <https://discuss.elastic.co/t/adding-json-fields-kibana/62437>\
**Category:** Logstash\
**Created:** [October 6, 2016, 8:50pm UTC](https://discuss.elastic.co/t/adding-json-fields-kibana/62437 "2016-10-06T20:50:21Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![arque](https://avatars.discourse-cdn.com/v4/letter/a/9fc348/32.png) [@arque](https://discuss.elastic.co/u/arque)\
**Post date:** [October 6, 2016, 8:50pm UTC](https://discuss.elastic.co/t/adding-json-fields-kibana/62437/1 "2016-10-06T20:50:21Z")

</div>

Hi,

I have a JSON file as input for Logstash, and it looks as follows:

```
[
  {
    "_index": "packets-2016-10-06",
    "_type": "pcap_file",
    "_score": null,
    "_source": {
      "layers": {
        "frame": {
          "frame.number": "1",
          "frame.len": "215"
        },
        "eth": {
          "eth.dst": {
            "eth.dst_resolved": "Broadcast",
            "eth.addr": "ff:ff:ff:ff:ff:ff"
          },
          "eth.src": {
            "eth.src_resolved": "value",
            "eth.addr": "ff:ff:ff:ff:ff:ff"
          }
        }
       }
     } 
   },
  {
    "_index": "packets-2016-10-06",
    "_type": "pcap_file",
    "_score": null,
    "_source": {
      "layers": {
        "frame": {
          "frame.number": "2",
          "frame.len": "214"
        },
        "eth": {
          "eth.dst": {
            "eth.dst_resolved": "Broadcast",
            "eth.addr": "ff:ff:ff:ff:ff:ff"
          },
          "eth.src": {
            "eth.src_resolved": "value",
            "eth.addr": "ff:ff:ff:ff:ff:ff"
          }
        }
       }
     } 
   }]

```

However, in kibana, in the message field, I get the content of the whole line, of each line of the JSON file. What should I do in order to have these JSON fields available in the Kibana fields?  
What I really want to have is, in this example, only two events (each beginning in the "\_index" field) with all the fields inside this event (that is, frame.number, frame.len, eth.dst\_resolved, etc). Is it possible?

If needed, here is the pipeline I am using:

```
input {
  file {
    path => "C:\Users\NOTEBOOKRIC\Desktop\esse.txt"
    type => "json"
    codec => "json"
    start_position => "beginning"
  }
}

filter {
  json{
       source => "message"
   }
}

output {
  elasticsearch {
    hosts => ["localhost:9200"]
  }
  stdout { codec => rubydebug }
}

```

Thank you.

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [October 7, 2016, 5:36am UTC](https://discuss.elastic.co/t/adding-json-fields-kibana/62437/2 "2016-10-07T05:36:41Z")

</div>

The json codec doesn't support this kind of multiline json objects. Would it be possible for you to get a file with one array element for line? Or the whole contents of the file in a single line? You might be able to use the multiline codec to do that joining.

---

<div class="post-metadata">

**Author:** ![arque](https://avatars.discourse-cdn.com/v4/letter/a/9fc348/32.png) [@arque](https://discuss.elastic.co/u/arque)\
**Post date:** [October 7, 2016, 6:01pm UTC](https://discuss.elastic.co/t/adding-json-fields-kibana/62437/3 "2016-10-07T18:01:49Z")

</div>

Thank you, magnusbaeck.

I found a logstash plugin for inputting pcap files, which I think suits me better.  
But now I am facing some problems while installing it. I created a new thread for that.  
Thanks again.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 4:35am UTC](https://discuss.elastic.co/t/adding-json-fields-kibana/62437/4 "2017-07-06T04:35:09Z")

</div>


