# Avro to Json

**URL:** <https://discuss.elastic.co/t/avro-to-json/273820>\
**Category:** Logstash\
**Created:** [May 24, 2021, 12:40pm UTC](https://discuss.elastic.co/t/avro-to-json/273820 "2021-05-24T12:40:18Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![thirty2](https://avatars.discourse-cdn.com/v4/letter/t/a9a28c/32.png) [@thirty2](https://discuss.elastic.co/u/thirty2)\
**Post date:** [May 24, 2021, 12:40pm UTC](https://discuss.elastic.co/t/avro-to-json/273820/1 "2021-05-24T12:40:18Z")

</div>

Hi,  
I am consuming data from Kafka with INPUT configuration:

```
    input {
      kafka {
        codec => avro {
            schema_uri => "/etc/logstash/avro.avsc"
        }

        key_deserializer_class => "org.apache.kafka.common.serialization.ByteArrayDeserializer"
        value_deserializer_class => "org.apache.kafka.common.serialization.ByteArrayDeserializer"

```

Schema is:

```
 {
   "namespace": "avro_data",
   "type": "record",
   "name": "event",
   "fields":
   [
     {"name": "timestamp", "type": "long"},
     {"name": "src", "type": "string"},
     {"name": "host_ip", "type": "string"},
     {"name": "rawdata", "type": "bytes"}
   ]
}

```

My problem is that data in "rawdata" are nested, there is a lot of fields. And in Kibana i do see all these data in that one "rawdata" field.  
Example in "rawdata" fieled:

`{"timestamp":"Mon May 24 12:34:23 UTC 2021","src":"avro_syslog","hostT01":"device1","host_ip":"device1","tag":"hello","type":"syslog","source":"syslog","msg":"%Viptela-device1-ftmd-6-INFO-1400002: bfd-state-change severity-level:major host-name:device1 system-ip:10.2.0.14 src-ip:10.24.11.221 dst-ip:63.142.13.44 proto:ipsec src-port:12346 dst-port:12386 local-system-ip:10.2.0.14 local-color:custom1 remote-system-ip:10.0.0.6 remote-color:custom1 new-state:up deleted:false flap-reason:na","raw":"<190>FTMD[1285]: %Viptela-device1-ftmd-6-INFO-1400002: 2021-05-24 12:34:21 Notification: bfd-state-change severity-level:major host-name:device1 system-ip:10.2.0.14 src-ip:10.24.11.221 dst-ip:63.142.13.44 proto:ipsec src-port:12346 dst-port:12386 local-system-ip:10.2.0.14 local-color:custom1 remote-system-ip:10.0.0.6 remote-color:custom1 new-state:up deleted:false flap-reason:na"}`

I want to see for examle in Kibana a value "tag" which is in "rawdata" as separated field, not nested in "rawdata".  
Is there a way hot to pars it or split it?

Thanks

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [May 24, 2021, 3:02pm UTC](https://discuss.elastic.co/t/avro-to-json/273820/2 "2021-05-24T15:02:23Z")

</div>

Use a json filter to parse the [rawdata] field.

---

<div class="post-metadata">

**Author:** ![thirty2](https://avatars.discourse-cdn.com/v4/letter/t/a9a28c/32.png) [@thirty2](https://discuss.elastic.co/u/thirty2)\
**Post date:** [May 25, 2021, 6:45am UTC](https://discuss.elastic.co/t/avro-to-json/273820/3 "2021-05-25T06:45:48Z")

</div>

i tried, but for some reason it parsing some messages and some not. Did not find a reason why.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 22, 2021, 6:46am UTC](https://discuss.elastic.co/t/avro-to-json/273820/4 "2021-06-22T06:46:06Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
