# Elastic Search using Message Content Parse with Logstash

**URL:** <https://discuss.elastic.co/t/elastic-search-using-message-content-parse-with-logstash/293111>\
**Category:** Logstash\
**Created:** [December 29, 2021, 12:12pm UTC](https://discuss.elastic.co/t/elastic-search-using-message-content-parse-with-logstash/293111 "2021-12-29T12:12:43Z")\
**Posts on this page:** 1\
**Showing post:** 6

<div class="post-metadata">

**Author:** ![Iker](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/iker/32/91708_2.png) [@Iker](https://discuss.elastic.co/u/Iker)\
**Post date:** [December 29, 2021, 4:07pm UTC](https://discuss.elastic.co/t/elastic-search-using-message-content-parse-with-logstash/293111/6 "2021-12-29T16:07:25Z")

</div>

It's a better approach to parse the messages with a json filter, check these posts:

> [@Parsing array of json objects with logstash and injesting to elastic](https://discuss.elastic.co/t/parsing-array-of-json-objects-with-logstash-and-injesting-to-elastic/203197/7):
>
> Thanks Badger. Unfortunately, it doesnt seem to do anything. I added the below, but it doesnt ingest anything. filter { json { source =\> "message" target =\> "someField" remove\_field =\> ["message"] } split { field =\> "someField" } date { match =\> ["[someField][date]", "YYYY-MM-dd'T'HH:mm:ssZZ" ] } }

> <https://stackoverflow.com/questions/25588222/parse-multiline-json-with-grok-in-logstash>

---

_[View the full topic](https://discuss.elastic.co/t/elastic-search-using-message-content-parse-with-logstash/293111)._
