# Elastic Search using Message Content Parse with Logstash

**URL:** <https://discuss.elastic.co/t/elastic-search-using-message-content-parse-with-logstash/293111>\
**Category:** Logstash\
**Created:** [December 29, 2021, 12:12pm UTC](https://discuss.elastic.co/t/elastic-search-using-message-content-parse-with-logstash/293111 "2021-12-29T12:12:43Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![kiran\_tirumalasetti](https://avatars.discourse-cdn.com/v4/letter/k/b9e5f3/32.png) [@kiran\_tirumalasetti](https://discuss.elastic.co/u/kiran_tirumalasetti)\
**Post date:** [December 29, 2021, 12:12pm UTC](https://discuss.elastic.co/t/elastic-search-using-message-content-parse-with-logstash/293111/1 "2021-12-29T12:12:43Z")

</div>

Hello,

I am trying to push some data into Elasticsearch from an application via logstash and is there anyway to search/filter the json message in Elasticsearch for a particular field in the json message.

I am using below logstash configuration

```auto

# Sample Logstash configuration for creating a simple
# Beats -> Logstash -> Elasticsearch pipeline.

input {
  tcp {
    port => 4560
    codec => json
  }
}
filter {   
  date {
    match => ["timeMillis", "UNIX_MS"]
  }
}
output {
	elasticsearch {
		hosts => ["localhost:9200"]
		index => "mule-logs"	
	}	
}

```

and the sample message is Elasticsearch is attached

 ![Capture](https://us1.discourse-cdn.com/elastic/original/3X/e/a/ea54112378dfe20f49fd63321d23a03b1c711592.png)  
 ![image](https://us1.discourse-cdn.com/elastic/original/3X/4/a/4a516914645854a0f528a17fd88167582e45a381.png)

For example I want to search for messageId in the json data using message.messageId or if I want to search for the code can I search it using message.code ? In simple terms I want to search with the keys in the message section. is it possible ?

---

<div class="post-metadata">

**Author:** ![FALEN](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/falen/32/82754_2.png) [@FALEN](https://discuss.elastic.co/u/FALEN)\
**Post date:** [December 29, 2021, 12:28pm UTC](https://discuss.elastic.co/t/elastic-search-using-message-content-parse-with-logstash/293111/2 "2021-12-29T12:28:27Z")

</div>

It seems your data is raw, you need to parse those fields first.  
Im not so good at grok, can be pain in the a\*\* to learn. But you can check basics there

> **[Grok filter plugin | Logstash Reference \[7.16\] | Elastic](https://www.elastic.co/guide/en/logstash/current/plugins-filters-grok.html)**

---

<div class="post-metadata">

**Author:** ![kiran\_tirumalasetti](https://avatars.discourse-cdn.com/v4/letter/k/b9e5f3/32.png) [@kiran\_tirumalasetti](https://discuss.elastic.co/u/kiran_tirumalasetti)\
**Post date:** [December 29, 2021, 12:47pm UTC](https://discuss.elastic.co/t/elastic-search-using-message-content-parse-with-logstash/293111/3 "2021-12-29T12:47:35Z")

</div>

Thanks @FALEN for your answer, can you post some code ?

---

<div class="post-metadata">

**Author:** ![FALEN](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/falen/32/82754_2.png) [@FALEN](https://discuss.elastic.co/u/FALEN)\
**Post date:** [December 29, 2021, 1:03pm UTC](https://discuss.elastic.co/t/elastic-search-using-message-content-parse-with-logstash/293111/4 "2021-12-29T13:03:01Z")

</div>

Maybe some other community member help for grok,

Alternatively, are you developing an app? Because its easier with Kafka.  
Just configure Kafka connector in your app, with mapped fields.  
Kafka will transfer all formats, and fields to logstash -\> elastic. Also this will be more cpu friendly since grok takes lot of cpu/ram if not configured properly

---

<div class="post-metadata">

**Author:** ![kiran\_tirumalasetti](https://avatars.discourse-cdn.com/v4/letter/k/b9e5f3/32.png) [@kiran\_tirumalasetti](https://discuss.elastic.co/u/kiran_tirumalasetti)\
**Post date:** [December 29, 2021, 2:36pm UTC](https://discuss.elastic.co/t/elastic-search-using-message-content-parse-with-logstash/293111/5 "2021-12-29T14:36:51Z")

</div>

Hi @Luca_Belluccini can you help on this topic ?

---

<div class="post-metadata">

**Author:** ![Iker](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/iker/32/91708_2.png) [@Iker](https://discuss.elastic.co/u/Iker)\
**Post date:** [December 29, 2021, 4:07pm UTC](https://discuss.elastic.co/t/elastic-search-using-message-content-parse-with-logstash/293111/6 "2021-12-29T16:07:25Z")

</div>

It's a better approach to parse the messages with a json filter, check these posts:

> [@Parsing array of json objects with logstash and injesting to elastic](https://discuss.elastic.co/t/parsing-array-of-json-objects-with-logstash-and-injesting-to-elastic/203197/7):
>
> Thanks Badger. Unfortunately, it doesnt seem to do anything. I added the below, but it doesnt ingest anything. filter { json { source =\> "message" target =\> "someField" remove\_field =\> ["message"] } split { field =\> "someField" } date { match =\> ["[someField][date]", "YYYY-MM-dd'T'HH:mm:ssZZ" ] } }

> <https://stackoverflow.com/questions/25588222/parse-multiline-json-with-grok-in-logstash>

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 26, 2022, 4:07pm UTC](https://discuss.elastic.co/t/elastic-search-using-message-content-parse-with-logstash/293111/7 "2022-01-26T16:07:56Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
