# Base64 decoding & decompression of json

**URL:** <https://discuss.elastic.co/t/base64-decoding-decompression-of-json/280442>\
**Category:** Logstash\
**Created:** [August 4, 2021, 2:00pm UTC](https://discuss.elastic.co/t/base64-decoding-decompression-of-json/280442 "2021-08-04T14:00:57Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![GitSpree23](https://avatars.discourse-cdn.com/v4/letter/g/65b543/32.png) [@GitSpree23](https://discuss.elastic.co/u/GitSpree23)\
**Post date:** [August 4, 2021, 2:00pm UTC](https://discuss.elastic.co/t/base64-decoding-decompression-of-json/280442/1 "2021-08-04T14:00:57Z")

</div>

I have a JSON input containing a [message][message\_json] field which is compressed & base64 encoded at the source.  
This is the python code used to decode, decompress, and deserialize the field:

```auto
message['message_json'] = json.loads(zlib.decompress(base64.b64decode(message['message_json']), 15 + 32))

```

How can I replicate the same using logstash filter?

I tried to use logstash-filter-base64 to decode:

```auto
filter {
  json {
    source => "message"
    target => "message_deserialized"
  }

  base64 {
    field => "[message_deserialized][message_json]"
    action => "decode"
  }

```

But I'm getting `"tags" => [[0] "_base64failure"]` error.

---

<div class="post-metadata">

**Author:** ![GitSpree23](https://avatars.discourse-cdn.com/v4/letter/g/65b543/32.png) [@GitSpree23](https://discuss.elastic.co/u/GitSpree23)\
**Post date:** [August 4, 2021, 2:10pm UTC](https://discuss.elastic.co/t/base64-decoding-decompression-of-json/280442/2 "2021-08-04T14:10:32Z")

</div>

Update:

I tried

```auto
ruby { 
    init => "require 'base64'"
    code => 'event.set("[message_deserialized][message_json_decoded]", Base64.decode64(event.get("[message_deserialized][message_json]")))' 
}

```

It works. Now I need help in just decompressing the `[message_deserialized][message_json_decoded]` field.

---

<div class="post-metadata">

**Author:** ![GitSpree23](https://avatars.discourse-cdn.com/v4/letter/g/65b543/32.png) [@GitSpree23](https://discuss.elastic.co/u/GitSpree23)\
**Post date:** [August 4, 2021, 3:54pm UTC](https://discuss.elastic.co/t/base64-decoding-decompression-of-json/280442/3 "2021-08-04T15:54:02Z")

</div>

Update:

Successfully decompressed as well.

Final filter:

```auto
filter {
  json {
    source => "message"
    target => "message_deserialized"
  }

  ruby {
    init => "require 'base64'
             require 'zlib'
             require 'stringio'"
    code => 'event.set("[message_deserialized][message_json_decoded]", Zlib::GzipReader.new(StringIO.new(Base64.decode64(event.get("[message_deserialized][message_json]")))).read)' }

  json {
    source => "[message_deserialized][message_json_decoded]"
    target => "[message_deserialized][message_json_decoded_deserialized]"
  }
}

```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 1, 2021, 3:54pm UTC](https://discuss.elastic.co/t/base64-decoding-decompression-of-json/280442/4 "2021-09-01T15:54:14Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
