# Extracting JSON key and values to separated fields

**URL:** <https://discuss.elastic.co/t/extracting-json-key-and-values-to-separated-fields/236289>\
**Category:** Logstash\
**Created:** [June 9, 2020, 8:58am UTC](https://discuss.elastic.co/t/extracting-json-key-and-values-to-separated-fields/236289 "2020-06-09T08:58:12Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![mihailo](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mihailo/32/45680_2.png) [@mihailo](https://discuss.elastic.co/u/mihailo)\
**Post date:** [June 9, 2020, 8:58am UTC](https://discuss.elastic.co/t/extracting-json-key-and-values-to-separated-fields/236289/1 "2020-06-09T08:58:12Z")

</div>

Hi, I need help with processing JSON file. My input looks like this (I need to keep it intact):

```
input {     
    s3 {
    bucket => "${S3_BUCKET}"
    access_key_id => "${S3_ACCESS_KEY}"
    secret_access_key => "${S3_SECRET_KEY}"
    exclude_pattern => "^.*(?<!txt|json)$"
    }
}

```

JSON I'm trying to parse looks like this:

```
{
   "unknown_url":[
      "ad",
      "rsl",
      "vbf"
   ]
}

```

I've tried JSON filter, custom ruby code, but the main problem is that key is unknown. Only certain thing is structure. So, I need to extract first (only) key of this JSON to a new field, and its value (array) to another field:

**url** : "unknown\_url"  
**parameters** : ["ad", "rsl", "vbf"]

---

<div class="post-metadata">

**Author:** ![mihailo](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mihailo/32/45680_2.png) [@mihailo](https://discuss.elastic.co/u/mihailo)\
**Post date:** [June 9, 2020, 12:13pm UTC](https://discuss.elastic.co/t/extracting-json-key-and-values-to-separated-fields/236289/2 "2020-06-09T12:13:51Z")

</div>

Solved.

```
filter {
    json {
        source => "message"
        target => "json"
    }
    if "_jsonparsefailure" not in [tags] {
        ruby {
            code => "
                json_data = event.get('[json]')
                event.set('url', json_data.keys[0])
                event.set('parameters', json_data[json_data.keys[0]])
            "
        }
        mutate { 
            remove_field => ["message"] 
            remove_field => ["json"] 
        }
    }
}

```

[This](https://discuss.elastic.co/t/getting-key-value-from-nested-event-element/107852) can help.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 7, 2020, 12:13pm UTC](https://discuss.elastic.co/t/extracting-json-key-and-values-to-separated-fields/236289/3 "2020-07-07T12:13:54Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
