# Decide if nested JSON is JSON or text

**URL:** <https://discuss.elastic.co/t/decide-if-nested-json-is-json-or-text/197338>\
**Category:** Logstash\
**Created:** [August 29, 2019, 12:38pm UTC](https://discuss.elastic.co/t/decide-if-nested-json-is-json-or-text/197338 "2019-08-29T12:38:57Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![hunsw](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/hunsw/32/93637_2.png) [@hunsw](https://discuss.elastic.co/u/hunsw)\
**Post date:** [August 29, 2019, 12:38pm UTC](https://discuss.elastic.co/t/decide-if-nested-json-is-json-or-text/197338/1 "2019-08-29T12:38:58Z")

</div>

I'm receiving JSON formatted events from Filebeat, parsed as JSON. I.e.  
**Original log:**

> {"date" : "2019...", "data" : { "subdata" : "sometext" }} (CASE1)  
> {"date" : "2019...", "data" : { "subdata" : { "field1" : "blah" } }} (CASE2)

**Filebeat conf:**

```auto
    - type: log
    ...
       json.keys_under_root:true
    ..

```

**Generated log by FB:**

```auto
{"@timestamp":"2019....", "@metadata" ...blahblah, "data":{"subdata":{"field1":"blah"}}...}

```

I need Logstash to be able to decide if "subdata" contains a text or a JSON object, e.g. ..."subdata" : { "field1" : "blah }

This is because Elasticsearch won't map JSON objects and texts into the same field (subdata is either text or object in ES).

I tried matching subdata to curly braces, but it didn't help:  
E.g.  
if [data][subdata] =~ /^{.\*/ ----\> this won't match { "data" : { "subdata" : { "field1....

I think part of the problem is that Filebeat sorts the original log message to separate fields, but I really don't feel like putting the burden on the few Logstash instances I have to JSON-ize every incoming message.

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [August 29, 2019, 1:10pm UTC](https://discuss.elastic.co/t/decide-if-nested-json-is-json-or-text/197338/2 "2019-08-29T13:10:07Z")

</div>

> [@hunsw](#):
>
> if [data][subdata] =~ /^{.\*/

That would work if [data][subdata] is a string that starts with {

You could do it in ruby

```
    ruby {
        code => '
            s = event.get("[data][subdata]")
            if s
                if s.kind_of?(String)
                    isObject = false
                else
                    isObject = true
                end
                event.set("isObject", isObject)
            end
        '
    }

```

---

<div class="post-metadata">

**Author:** ![hunsw](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/hunsw/32/93637_2.png) [@hunsw](https://discuss.elastic.co/u/hunsw)\
**Post date:** [August 29, 2019, 1:36pm UTC](https://discuss.elastic.co/t/decide-if-nested-json-is-json-or-text/197338/3 "2019-08-29T13:36:01Z")

</div>

Thank you, that works like a charm! I hope it scales well too, but nevertheless, this is a solution that hasn't just offered a quick help, but opened new ways I can fiddle with my LS configs! 🙂

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 26, 2019, 1:36pm UTC](https://discuss.elastic.co/t/decide-if-nested-json-is-json-or-text/197338/4 "2019-09-26T13:36:12Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
