# Extract some fields from json and assing to a root

**URL:** <https://discuss.elastic.co/t/extract-some-fields-from-json-and-assing-to-a-root/228289>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [April 16, 2020, 9:39am UTC](https://discuss.elastic.co/t/extract-some-fields-from-json-and-assing-to-a-root/228289 "2020-04-16T09:39:51Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![esseti](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/esseti/32/8383_2.png) [@esseti](https://discuss.elastic.co/u/esseti)\
**Post date:** [April 16, 2020, 9:39am UTC](https://discuss.elastic.co/t/extract-some-fields-from-json-and-assing-to-a-root/228289/1 "2020-04-16T09:39:51Z")

</div>

Hi all,  
i've in a log file a series of JSON that i want to parse not to extarct all the fields but only some.

This is my log

```auto
    {
        "call_type": "Example", 
        "begin_time": "2020-04-15T15:05:32.982520+00:00",
        "call_size": 30,  
        "caller_id": "123",
        "end_time": "2020-04-15T15:05:32.982744+00:00", 
        "http_method": "POST",  
        "request_id": "444"
     }

```

and what i want to have is inside a field of mine `my_obj` i want to keep the whole json inside `message` and extract some fields to go under `my_obj.<field>` such as `caller_id`

```auto
    {
        "my_obj" : 
         { 
            "message" : 
             {
              "call_type": "Example", 
              "begin_time": "2020-04-15T15:05:32.982520+00:00",
              "call_size": 30,  
              "caller_id": "123",
              "end_time": "2020-04-15T15:05:32.982744+00:00", 
              "http_method": "POST",  
              "request_id": "444" 
             },
           "request_id": "444",
           "caller_id": "123"
         }
    }

```

how can I do this? Is it feasible?

---

<div class="post-metadata">

**Author:** ![shaunak](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/shaunak/32/6643_2.png) [@shaunak](https://discuss.elastic.co/u/shaunak)\
**Post date:** [April 17, 2020, 5:56pm UTC](https://discuss.elastic.co/t/extract-some-fields-from-json-and-assing-to-a-root/228289/2 "2020-04-17T17:56:13Z")

</div>

Yes, this should be possible.

Initially, your entire JSON log entry will start out as a string in the `message` field. Use the [`decode_json_fields` processor](https://www.elastic.co/guide/en/beats/filebeat/current/decode-json-fields.html) to decode this as JSON into `my_obj.message`.

Then, you can extract specific fields from `my_obj.message.*` to `my_obj.*` using the [`rename` processor](https://www.elastic.co/guide/en/beats/filebeat/current/rename-fields.html).

Hope that helps,

Shaunak

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 15, 2020, 5:56pm UTC](https://discuss.elastic.co/t/extract-some-fields-from-json-and-assing-to-a-root/228289/3 "2020-05-15T17:56:14Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
