# Enclose log-stash output in json array \[ \]

**URL:** <https://discuss.elastic.co/t/enclose-log-stash-output-in-json-array/24553>\
**Category:** Logstash\
**Created:** [June 29, 2015, 2:09pm UTC](https://discuss.elastic.co/t/enclose-log-stash-output-in-json-array/24553 "2015-06-29T14:09:46Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![mozowski](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mozowski/32/3501_2.png) [@mozowski](https://discuss.elastic.co/u/mozowski)\
**Post date:** [June 29, 2015, 2:09pm UTC](https://discuss.elastic.co/t/enclose-log-stash-output-in-json-array/24553/1 "2015-06-29T14:09:47Z")

</div>

Hi,  
I am in need of sending json on following format (note [] at top level) :  
[{ "some\_field" : "some\_value"}]  
however what logstash file output logs following:  
{ "some\_field" : "some\_value"}

When I try to to use mutate replace filter and enclose my message in "[] "  
replace =\> { "message" =\> '[{ "some\_field" : "some\_value"}]' }  
}  
I got from json filter:

Trouble parsing json {:source=\>"message", :raw=\>"[{ "some\_field" : "some\_value"}]", :exception=\>#\<TypeError: can't convert Java::JavaUtil::ArrayList into Hash\>, :level=\>:warn}

How can I enclose output json into json array "[]" ?

---

<div class="post-metadata">

**Author:** ![jtr](https://avatars.discourse-cdn.com/v4/letter/j/ee59a6/32.png) [@jtr](https://discuss.elastic.co/u/jtr)\
**Post date:** [June 30, 2015, 8:50pm UTC](https://discuss.elastic.co/t/enclose-log-stash-output-in-json-array/24553/2 "2015-06-30T20:50:51Z")

</div>

Oddly enough, I need exactly the same thing as mozowski. I require this format

[{"message":"some informational content"}]

When sending to a RabbitMQ exchange, but I can't get it right either to RabbitMQ or even to a plain stdout or file output. I can wrap one value in [] but not the whole thing which is what I need to do.

I have tried a wide variety of mutate and etc. but I must be missing something. (I am a logstash newbie.)

---

<div class="post-metadata">

**Author:** ![jtr](https://avatars.discourse-cdn.com/v4/letter/j/ee59a6/32.png) [@jtr](https://discuss.elastic.co/u/jtr)\
**Post date:** [July 2, 2015, 2:22pm UTC](https://discuss.elastic.co/t/enclose-log-stash-output-in-json-array/24553/3 "2015-07-02T14:22:33Z")

</div>

Just in case it may help you, mozowski, depending on how desperate you get:

I made a temporary workaround by hacking the distributed march\_hare.rb to rewrite the message (adding the square brackets) immediately before it is published to RabbitMQ. (You'd have to do the same for whichever output you are using, which I don't think you specified.)

This is just a hack, and I suppose if I don't find a better answer I'll write my own output plugin that's just a modified copy of one of the distributed ones.

It does seem odd to have to go that route, however.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 5:35am UTC](https://discuss.elastic.co/t/enclose-log-stash-output-in-json-array/24553/4 "2017-07-06T05:35:44Z")

</div>


