# Decode\_json\_fields and array

**URL:** <https://discuss.elastic.co/t/decode-json-fields-and-array/281530>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [August 16, 2021, 10:49am UTC](https://discuss.elastic.co/t/decode-json-fields-and-array/281530 "2021-08-16T10:49:00Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![s17n](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/s17n/32/93211_2.png) [@s17n](https://discuss.elastic.co/u/s17n)\
**Post date:** [August 16, 2021, 10:49am UTC](https://discuss.elastic.co/t/decode-json-fields-and-array/281530/1 "2021-08-16T10:49:00Z")

</div>

Hello,

It seems decode\_json\_fields can't decode array.  
This is my log :

```auto
{"level":"panic","application":"command","stack":[{"func":"main.func1","line":"51","source":"main.go"},{"func":"gopanic","line":"965","source":"panic.go"},{"func":"panicmem","line":"212","source":"panic.go"},{"func":"sigpanic","line":"734","source":"signal_unix.go"},{"func":"main","line":"92","source":"main.go"},{"func":"main","line":"225","source":"proc.go"},{"func":"goexit","line":"1371","source":"asm_amd64.s"}],"error":"runtime error: invalid memory address or nil pointer dereference","caller":"/app/command/main.go:51","time":"2021-08-16T09:49:58Z","message":"Unexpected error"}

```

(This log is one line)

My config :

```auto
      - decode_json_fields:
          fields: ["message"]
          target: ""
          overwrite_keys: true
          add_error_key: true
          process_array: true

```

All fields have been decoded properly, except the field "stack" :

```auto
stack.func: main.func1, gopanic, panicmem, sigpanic, main, main, goexit
stack.line: 51, 965, 212, 734, 92, 225, 1371
stack.source: main.go, panic.go, panic.go, signal_unix.go, main.go, proc.go, asm_amd64.s

```

stack should be decoded like that :

```auto
"stack":[
{
"func":"main.func1",
"line":"51",
"source":"main.go"
},
{
"func":"gopanic",
"line":"965",
"source":"panic.go"
},
{
"func":"panicmem",
"line":"212",
"source":"panic.go"
},
{
"func":"sigpanic",
"line":"734",
"source":"signal_unix.go"
},
{
"func":"main",
"line":"92",
"source":"main.go"
},
{
"func":"main",
"line":"225",
"source":"proc.go"
},
{
"func":"goexit",
"line":"1371",
"source":"asm_amd64.s"
}
],

```

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [August 17, 2021, 11:32am UTC](https://discuss.elastic.co/t/decode-json-fields-and-array/281530/2 "2021-08-17T11:32:42Z")

</div>

Filebeat will output the data similar to how you posted that it should.

I assume you are looking at the data in Elasticsearch. If you look at the [`_source`](https://www.elastic.co/guide/en/elasticsearch/reference/current/mapping-source-field.html) field for the document you will see what Filebeat sent.

The reason arrays are flattened like that in the data returned by Elasticsearch is due to the data type used by default. You can change how the data is stored by changing the data type used for this field. See [Nested field type | Elasticsearch Guide [7.14] | Elastic](https://www.elastic.co/guide/en/elasticsearch/reference/current/nested.html) for details.

One way to add your own mapping for this field is to use Filebeats ` setup.template.append_fields` option ([docs](https://www.elastic.co/guide/en/beats/filebeat/7.8/configuration-template.html)). You have to delete your current index and run `filebeat setup` for the change to take effect.

---

<div class="post-metadata">

**Author:** ![s17n](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/s17n/32/93211_2.png) [@s17n](https://discuss.elastic.co/u/s17n)\
**Post date:** [August 17, 2021, 12:11pm UTC](https://discuss.elastic.co/t/decode-json-fields-and-array/281530/3 "2021-08-17T12:11:49Z")

</div>

Good catch thank you

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 14, 2021, 2:12pm UTC](https://discuss.elastic.co/t/decode-json-fields-and-array/281530/4 "2021-09-14T14:12:38Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
