# Bad parsing json with logstash

**URL:** <https://discuss.elastic.co/t/bad-parsing-json-with-logstash/309121>\
**Category:** Logstash\
**Created:** [July 7, 2022, 1:38pm UTC](https://discuss.elastic.co/t/bad-parsing-json-with-logstash/309121 "2022-07-07T13:38:02Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![Lynow](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/lynow/32/98866_2.png) [@Lynow](https://discuss.elastic.co/u/Lynow)\
**Post date:** [July 7, 2022, 1:38pm UTC](https://discuss.elastic.co/t/bad-parsing-json-with-logstash/309121/1 "2022-07-07T13:38:02Z")

</div>

Hello,

I'm having trouble with logstash json parsing. I receive several events of this type:

```auto
{
    "ignoreSimilarity" => false,
             "message" => "19/04/22 19h47\n\nLogin:***",
          "@timestamp" => 2022-04-20T09:48:17.782Z,
            "dataType" => "ip",
                "data" => "xx.xx.xx.xx",
            "takedown" => "no",
           "createdAt" => 1650448097782,
               "stats" => {},
            "@version" => "1",
                 "tlp" => 2,
           "createdBy" => "mail@mail.com",
             "reports" => {
                        "MISP_2_1" => {
            "taxonomies" => [
                [0] {
                        "level" => "info",
                    "predicate" => "Search",
                        "value" => "0 events",
                    "namespace" => "MISP"
                }
            ]
        },
                   "AbuseIPDB_1_0" => {
            "taxonomies" => [
                [0] {
                        "level" => "malicious",
                    "predicate" => "Records",
                        "value" => 4,
                    "namespace" => "AbuseIPDB"
                }
            ]
        },
              "Onyphe_Summary_1_0" => {
            "taxonomies" => [
                [0] {
                        "level" => "malicious",
                    "predicate" => "Threat",
                        "value" => "2 threat found",
                    "namespace" => "Onyphe"
                }
            ]
        },
        "VirusTotal_GetReport_3_0" => {
            "taxonomies" => [
                [0] {
                        "level" => "malicious",
                    "predicate" => "GetReport",
                        "value" => "61 detected_url(s)",
                    "namespace" => "VT"
                }
            ]
        },
                      "IPVoid_1_0" => {
            "taxonomies" => [
                [0] {
                        "level" => "suspicious",
                    "predicate" => "Blacklists",
                        "value" => "3/89",
                    "namespace" => "IPVoid"
                },
                [1] {
                        "level" => "info",
                    "predicate" => "Location",
                        "value" => "Atlanta/United States of America",
                    "namespace" => "IPVoid"
                }
            ]
        }
    },
                  "id" => "~278388984",
             "sighted" => false,
                 "ioc" => false,
              "ascent" => "no",
           "startDate" => 1650448097782,
                "tags" => [
        [0] "ip",
        [1] "thehive"
    ]
}

```

And I can't figure out why, but all the fields are parsed fine, except these: (in Opensearch)

![image](https://us1.discourse-cdn.com/elastic/original/3X/9/6/96a703d481b9b6eab771a5b63d0c0bdc86d06b22.png)

For the other fields, everything is done as it should. Here is my input, filter and output configuration :

```auto
input {
  pipeline {
    address => thehive
  }
}
filter {
  date {
     match => ["startDate","UNIX_MS"]
     target => "@timestamp"
     timezone => "UTC"
  }
}

```

output :

```auto
  GNU nano 3.2 thehive-02-output.conf                                                                         

output {
          opensearch {
                  hosts => ["https://192.168.1.19:9200"]
                  index => "thehive"
                  user => "xxxx"
                  password => "xxxxx"
                  ssl => true
                  ssl_certificate_verification => true
                  cacert => "xx"
        }

  pipeline {
    send_to => logs # pipes/logs_output.conf
  }

}

```

input of pipeline :

```auto
input {
        http_poller {
              urls => {
                      thehive => {
                                 url => "http://192.168.1.8:9000/api/case/artifact/_search?range=all"
                                 method => post
                                 user => "xxx"
                                 password => "xxxxx"
                                 headers => { Accept => "application/json" }
                      }
              }
              codec => "json_lines"
              tags => ["thehive"]
        }
}

output {
  if "thehive" in [tags] {
    pipeline {
      send_to => thehive # pipes/thehive
    }
  }
}

```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 7, 2022, 1:38pm UTC](https://discuss.elastic.co/t/bad-parsing-json-with-logstash/309121/2 "2022-07-07T13:38:02Z")

</div>

OpenSearch/OpenDistro are AWS run products and differ from the original Elasticsearch and Kibana products that Elastic builds and maintains. You may need to contact them directly for further assistance.

(This is an automated response from your friendly Elastic bot. Please report this post if you have any suggestions or concerns :elasticheart: )

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [July 7, 2022, 2:49pm UTC](https://discuss.elastic.co/t/bad-parsing-json-with-logstash/309121/3 "2022-07-07T14:49:23Z")

</div>

> [@Lynow](#):
>
> all the fields are parsed fine, except these

What don't you like about the way they are parsed?

---

<div class="post-metadata">

**Author:** ![Lynow](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/lynow/32/98866_2.png) [@Lynow](https://discuss.elastic.co/u/Lynow)\
**Post date:** [July 7, 2022, 2:55pm UTC](https://discuss.elastic.co/t/bad-parsing-json-with-logstash/309121/4 "2022-07-07T14:55:39Z")

</div>

Because I want this to create the fields "level","value", etc. in Opensearch, like this:

![image](https://us1.discourse-cdn.com/elastic/original/3X/0/a/0ad16318aafc116c3ea0fb976f3420426941e3e7.png)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 7, 2022, 2:55pm UTC](https://discuss.elastic.co/t/bad-parsing-json-with-logstash/309121/5 "2022-07-07T14:55:39Z")

</div>

OpenSearch/OpenDistro are AWS run products and differ from the original Elasticsearch and Kibana products that Elastic builds and maintains. You may need to contact them directly for further assistance.

(This is an automated response from your friendly Elastic bot. Please report this post if you have any suggestions or concerns :elasticheart: )

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 5, 2022, 10:15am UTC](https://discuss.elastic.co/t/bad-parsing-json-with-logstash/309121/7 "2022-08-05T10:15:22Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
