# Create split series / aggregation based on json message

**URL:** <https://discuss.elastic.co/t/create-split-series-aggregation-based-on-json-message/277401>\
**Category:** Kibana\
**Created:** [June 30, 2021, 3:33am UTC](https://discuss.elastic.co/t/create-split-series-aggregation-based-on-json-message/277401 "2021-06-30T03:33:05Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![gandhz](https://avatars.discourse-cdn.com/v4/letter/g/13edae/32.png) [@gandhz](https://discuss.elastic.co/u/gandhz)\
**Post date:** [June 30, 2021, 3:33am UTC](https://discuss.elastic.co/t/create-split-series-aggregation-based-on-json-message/277401/1 "2021-06-30T03:33:05Z")

</div>

Hi,

I have service logs which contains json message like example below:

```auto
{
    "caller_method_name": "transferConfirmation",
    "caller_line_number": 328,
    "message": "Transfer via virtual : {"transferRef":"22151","amountTransfer":"10000","transferFee":"0","totalTransfer":"10000","responseCode":"31"}"
    "user_agent": "HttpComponents"
}

```

I wanted to do count aggregation based on response code. Is it possible to do it? We cannot list down the response code and filter one by one since we have so many response code start from 00 till xxx number of response code.

Thanks

---

<div class="post-metadata">

**Author:** ![Iker](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/iker/32/91708_2.png) [@Iker](https://discuss.elastic.co/u/Iker)\
**Post date:** [June 30, 2021, 4:25am UTC](https://discuss.elastic.co/t/create-split-series-aggregation-based-on-json-message/277401/2 "2021-06-30T04:25:18Z")

</div>

Hi Gandhi, as I see, is completly doable, you have to use a JSON Processor, probably twice with the option "add to root" if you like; once you have the data in a nice looking format you should be able to make all the aggregations:

```auto
{
	"caller_method_name": "transferConfirmation",
	"caller_line_number": 328,
	"message": {
		"type": "Transfer via virtual",
		"transferRef": "22151",
		"amountTransfer": "10000",
		"transferFee": "0",
		"totalTransfer": "10000",
		"responseCode": "31"
	},
	"user_agent": "HttpComponents"
}

```

> **[JSON processor | Elasticsearch Guide \[7.13\] | Elastic](https://www.elastic.co/guide/en/elasticsearch/reference/current/json-processor.html)**

---

<div class="post-metadata">

**Author:** ![gandhz](https://avatars.discourse-cdn.com/v4/letter/g/13edae/32.png) [@gandhz](https://discuss.elastic.co/u/gandhz)\
**Post date:** [June 30, 2021, 9:39am UTC](https://discuss.elastic.co/t/create-split-series-aggregation-based-on-json-message/277401/3 "2021-06-30T09:39:31Z")

</div>

Hi Iker,

Thanks for info. Actually I'm still new in ELK stack, do you have any sample to use or implement JSON Processor?

Thanks

---

<div class="post-metadata">

**Author:** ![Iker](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/iker/32/91708_2.png) [@Iker](https://discuss.elastic.co/u/Iker)\
**Post date:** [June 30, 2021, 4:40pm UTC](https://discuss.elastic.co/t/create-split-series-aggregation-based-on-json-message/277401/4 "2021-06-30T16:40:18Z")

</div>

It is not that hard, you could create a new Ingest Pipeline even from the Kibana UI, then, when you are indexing the documents, specify the pipeline id to use. Take a look at the documentation and you will be up and running in no time:

> **[Ingest pipelines | Elasticsearch Guide \[7.13\] | Elastic](https://www.elastic.co/guide/en/elasticsearch/reference/current/ingest.html)**

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 28, 2021, 4:40pm UTC](https://discuss.elastic.co/t/create-split-series-aggregation-based-on-json-message/277401/5 "2021-07-28T16:40:53Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
