# Avoid overridding of default message field in logstash

**URL:** <https://discuss.elastic.co/t/avoid-overridding-of-default-message-field-in-logstash/63127>\
**Category:** Logstash\
**Created:** [October 16, 2016, 12:10pm UTC](https://discuss.elastic.co/t/avoid-overridding-of-default-message-field-in-logstash/63127 "2016-10-16T12:10:13Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![javatechy](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/javatechy/32/8763_2.png) [@javatechy](https://discuss.elastic.co/u/javatechy)\
**Post date:** [October 16, 2016, 12:10pm UTC](https://discuss.elastic.co/t/avoid-overridding-of-default-message-field-in-logstash/63127/1 "2016-10-16T12:10:13Z")

</div>

I am using logstash to parse my logs. when i am parsing the json (which contains a "message" field) overrides the default message field. I tried using remove\_field option of json{ } filter but that didn't work work for me.

Here is my filter code:  
filter {  
mutate { gsub =\> ["message",""","'"] }  
mutate { gsub =\> ["message",".","\_"] }  
csv {  
columns =\> ["TIMESTAMP","HEADERS","FIELD1","FIELD2","FIELD2\_TIME","INTER\_FIELD2"]  
separator =\> "|"  
}  
mutate { gsub =\> ["FIELD1", "'", '"']}  
json { source =\> "FIELD1" remove\_field =\> ["message"] }  
mutate { gsub =\> ["FIELD2", "'", '"']}  
json { source =\> "FIELD2" remove\_field =\> ["message"] }  
}

How to avoid overriding of the message field ?

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [October 16, 2016, 3:40pm UTC](https://discuss.elastic.co/t/avoid-overridding-of-default-message-field-in-logstash/63127/2 "2016-10-16T15:40:22Z")

</div>

You can't. As a workaround you can use the json filter's `target` option to choose where to store the results of the parsed JSON, then selectively move the fields you want to keep into the top level (if that's where you want to store them).

---

<div class="post-metadata">

**Author:** ![javatechy](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/javatechy/32/8763_2.png) [@javatechy](https://discuss.elastic.co/u/javatechy)\
**Post date:** [October 17, 2016, 2:09pm UTC](https://discuss.elastic.co/t/avoid-overridding-of-default-message-field-in-logstash/63127/3 "2016-10-17T14:09:33Z")

</div>

thanks @magnusbaeck I used this

> json { source =\> "REQUEST" target =\> "request" }

and it worked for me.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 4:33am UTC](https://discuss.elastic.co/t/avoid-overridding-of-default-message-field-in-logstash/63127/4 "2017-07-06T04:33:56Z")

</div>


