# Create json object in logstash & pass to the elastic search

**URL:** <https://discuss.elastic.co/t/create-json-object-in-logstash-pass-to-the-elastic-search/106665>\
**Category:** Logstash\
**Created:** [November 7, 2017, 10:07am UTC](https://discuss.elastic.co/t/create-json-object-in-logstash-pass-to-the-elastic-search/106665 "2017-11-07T10:07:19Z")\
**Posts on this page:** 11\
**Page:** 1

<div class="post-metadata">

**Author:** ![dsakpal](https://avatars.discourse-cdn.com/v4/letter/d/c2a13f/32.png) [@dsakpal](https://discuss.elastic.co/u/dsakpal)\
**Post date:** [November 7, 2017, 10:07am UTC](https://discuss.elastic.co/t/create-json-object-in-logstash-pass-to-the-elastic-search/106665/1 "2017-11-07T10:07:19Z")

</div>

**My log format is like,**  
02.11.2017,11:33:13,DDIC,6,192.168.2.110,PFCG,SAPMSYST SAPMSYST1,Logon Successful (Type=A)

**My filter is like,**

filter {  
grok{  
match=\>{  
"message"=\>"%{NOTSPACE:date},%{NOTSPACE:time},%{WORD:user},%{NUMBER:riskindex},%{IP:terminal},%{NOTSPACE:tcode},%{GREEDYDATA:program},%{GREEDYDATA:messagetext}"  
}  
add\_field=\>{  
"eventName"=\>"grok"  
}  
}  
}

**& I am getting output in elastic is as below,**

{  
"date" =\> "02.11.2017",  
"terminal" =\> "192.168.2.110",  
"program" =\> "SAPMSYST SAPMSYST1",  
"message" =\> "02.11.2017,11:33:13,DDIC,6,192.168.2.110,PFCG,SAPMSYST SAPMSYST1,Logon Successful (Type=A)\r",  
"type" =\> "logs",  
"riskindex" =\> "6",  
"tcode" =\> "PFCG",  
"path" =\> "D:\logfile\test.log",  
"@timestamp" =\> 2017-11-07T09:48:41.835Z,  
"messagetext" =\> "Logon Successful (Type=A)\r",  
"@version" =\> "1",  
"host" =\> "GLT-D103",  
"eventName" =\> "grok",  
"time" =\> "11:33:13",  
"user" =\> "DDIC"  
}

**Expected output for me is,**  
{  
"date" =\> "02.11.2017",  
"terminal" =\> "192.168.2.110",  
**"program" =\> "{"grp1":"SAPMSYST",  
"grp2":"SAPMSYST1"}",**  
"message" =\> "02.11.2017,11:33:13,DDIC,6,192.168.2.110,PFCG,SAPMSYST SAPMSYST1,Logon Successful (Type=A)\r",  
"type" =\> "logs",  
"riskindex" =\> "6",  
"tcode" =\> "PFCG",  
"path" =\> "D:\logfile\test.log",  
"@timestamp" =\> 2017-11-07T09:48:41.835Z,  
"messagetext" =\> "Logon Successful (Type=A)\r",  
"@version" =\> "1",  
"host" =\> "GLT-D103",  
"eventName" =\> "grok",  
"time" =\> "11:33:13",  
"user" =\> "DDIC"  
}

If anyone could point out my oversite or redirect my efforts, it would be greatly appreciate it.

Thanks

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [November 7, 2017, 10:12am UTC](https://discuss.elastic.co/t/create-json-object-in-logstash-pass-to-the-elastic-search/106665/2 "2017-11-07T10:12:21Z")

</div>

Replace

```
%{GREEDYDATA:program}

```

with

```
%{WORD:[program][grp1]} %{WORD:[program][grp2]}
```

---

<div class="post-metadata">

**Author:** ![dsakpal](https://avatars.discourse-cdn.com/v4/letter/d/c2a13f/32.png) [@dsakpal](https://discuss.elastic.co/u/dsakpal)\
**Post date:** [November 7, 2017, 10:38am UTC](https://discuss.elastic.co/t/create-json-object-in-logstash-pass-to-the-elastic-search/106665/3 "2017-11-07T10:38:29Z")

</div>

it's works Thanks 🙂

Just have one more question here(previous content),  
If my log contains n numbers of fields that get generated automatically {for ex. 02.11.2017,11:33:13,DDIC,6,192.168.2.110,PFCG,SAPMSYST SAPMSYST1 SAPMSYST2 SAPMSYST3 .... SAPMSYSTn,Logon Successful (Type=A)) } then how to deal with this kind of situation?

Hope you understand my question

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [November 9, 2017, 9:38pm UTC](https://discuss.elastic.co/t/create-json-object-in-logstash-pass-to-the-elastic-search/106665/4 "2017-11-09T21:38:55Z")

</div>

No, I don't quite get it. Is it the "SAPMSYST ..." column that's dynamic?

---

<div class="post-metadata">

**Author:** ![dsakpal](https://avatars.discourse-cdn.com/v4/letter/d/c2a13f/32.png) [@dsakpal](https://discuss.elastic.co/u/dsakpal)\
**Post date:** [November 13, 2017, 12:28pm UTC](https://discuss.elastic.co/t/create-json-object-in-logstash-pass-to-the-elastic-search/106665/5 "2017-11-13T12:28:40Z")

</div>

Yes ...!!!

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [November 13, 2017, 2:42pm UTC](https://discuss.elastic.co/t/create-json-object-in-logstash-pass-to-the-elastic-search/106665/6 "2017-11-13T14:42:51Z")

</div>

You'll have to write a piece of Ruby code in a ruby filter. Capture the whole column into a field, split the field, and add/update fields for each item in the list.

---

<div class="post-metadata">

**Author:** ![dsakpal](https://avatars.discourse-cdn.com/v4/letter/d/c2a13f/32.png) [@dsakpal](https://discuss.elastic.co/u/dsakpal)\
**Post date:** [November 14, 2017, 5:12am UTC](https://discuss.elastic.co/t/create-json-object-in-logstash-pass-to-the-elastic-search/106665/7 "2017-11-14T05:12:21Z")

</div>

Can you please share code snippet for this(if you have)? I am very new to logstash & ruby. Your help make it easy.... Mean while I'll also try it at my end. Thanks 🙂

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [November 14, 2017, 6:10am UTC](https://discuss.elastic.co/t/create-json-object-in-logstash-pass-to-the-elastic-search/106665/8 "2017-11-14T06:10:37Z")

</div>

Assuming you extract the "SAPMSYST SAPMSYST1 SAPMSYST2 SAPMSYST3" string into the field `programs` something like

```nohighlight
prog_list = event.get("programs").split()
prog_list.each_index { |i|
  event.set("[program][prg#{i}]", prog_list[i])
}

```

might work. But why not just let the `program` field be an array? Why do you need separate fields?

---

<div class="post-metadata">

**Author:** ![dsakpal](https://avatars.discourse-cdn.com/v4/letter/d/c2a13f/32.png) [@dsakpal](https://discuss.elastic.co/u/dsakpal)\
**Post date:** [November 14, 2017, 8:51am UTC](https://discuss.elastic.co/t/create-json-object-in-logstash-pass-to-the-elastic-search/106665/9 "2017-11-14T08:51:33Z")

</div>

ok ... Will make program field as array & try it. Thanks for your reply 🙂

One more question: For hashing/encryption I have used 'fingerprint' plugin but when i tried to find plugin for decryption then there is no plugin in logstash(Cipher is available for decrypt function but this plugin is not available for latest logstash version(5.6.3) ). Can you please provide such plugin name to decrypt my encrypted field?

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [November 14, 2017, 10:10am UTC](https://discuss.elastic.co/t/create-json-object-in-logstash-pass-to-the-elastic-search/106665/10 "2017-11-14T10:10:29Z")

</div>

I don't think there is a decryption plugin. What problem are you trying to solve?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 12, 2017, 10:10am UTC](https://discuss.elastic.co/t/create-json-object-in-logstash-pass-to-the-elastic-search/106665/11 "2017-12-12T10:10:33Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
