# Can Logstash output a read JSON-line as an event with multiple fields?

**URL:** <https://discuss.elastic.co/t/can-logstash-output-a-read-json-line-as-an-event-with-multiple-fields/225803>\
**Category:** Logstash\
**Created:** [March 31, 2020, 7:16am UTC](https://discuss.elastic.co/t/can-logstash-output-a-read-json-line-as-an-event-with-multiple-fields/225803 "2020-03-31T07:16:08Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Mattness](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mattness/32/52975_2.png) [@Mattness](https://discuss.elastic.co/u/Mattness)\
**Post date:** [March 31, 2020, 7:16am UTC](https://discuss.elastic.co/t/can-logstash-output-a-read-json-line-as-an-event-with-multiple-fields/225803/1 "2020-03-31T07:16:09Z")

</div>

Hello,

so I am trying to feed logdata to Elasticsearch. At first I tried Filebeat but that method did just read 1 line of JSON and converted it into one field called "message".

For that reason I switched to Logstash only to find that it behaves exactly the same. It reads one line of the JSON in the log file and puts it into a field called "message".

My problem is that I want to actually work with the data, e.g. create Kibana visualizations. But in order for that to work I need the data in this format:

1 line of JSON = 1 event with as many fields as there are properties. I guess I almost want something like deserialization. I logstash or any part of the ELK capable of this?

---

<div class="post-metadata">

**Author:** ![Robo](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/robo/32/38295_2.png) [@Robo](https://discuss.elastic.co/u/Robo)\
**Post date:** [March 31, 2020, 8:19am UTC](https://discuss.elastic.co/t/can-logstash-output-a-read-json-line-as-an-event-with-multiple-fields/225803/2 "2020-03-31T08:19:52Z")

</div>

In case your logs are already in json, use json filter in the pipeline  
[https://www.elastic.co/guide/en/logstash/current/plugins-filters-json.html](https://www.elastic.co/guide/en/logstash/current/plugins-filters-json.html)

```auto
    filter {
      json {
        source => "message"
      }
    }

```

Of course it also works with filebeat:  
[https://www.elastic.co/guide/en/beats/filebeat/current/decode-json-fields.html](https://www.elastic.co/guide/en/beats/filebeat/current/decode-json-fields.html)

```auto
processors:
 - decode_json_fields:
     fields: ['message']
     target: json

```

If you have regular single/multiline messages, use grok or dissect filter to extract the values.

---

<div class="post-metadata">

**Author:** ![Mattness](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mattness/32/52975_2.png) [@Mattness](https://discuss.elastic.co/u/Mattness)\
**Post date:** [March 31, 2020, 9:10am UTC](https://discuss.elastic.co/t/can-logstash-output-a-read-json-line-as-an-event-with-multiple-fields/225803/3 "2020-03-31T09:10:27Z")

</div>

Thank you so much. I did not even think about filters ... 🙄

You really helped me out! 🙂

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 28, 2020, 9:10am UTC](https://discuss.elastic.co/t/can-logstash-output-a-read-json-line-as-an-event-with-multiple-fields/225803/4 "2020-04-28T09:10:29Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
