# Extracting key pair Values using nested Json Paths

**URL:** <https://discuss.elastic.co/t/extracting-key-pair-values-using-nested-json-paths/295419>\
**Category:** Logstash\
**Created:** [January 26, 2022, 5:45am UTC](https://discuss.elastic.co/t/extracting-key-pair-values-using-nested-json-paths/295419 "2022-01-26T05:45:23Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![vaseemQA](https://avatars.discourse-cdn.com/v4/letter/v/4491bb/32.png) [@vaseemQA](https://discuss.elastic.co/u/vaseemQA)\
**Post date:** [January 26, 2022, 5:45am UTC](https://discuss.elastic.co/t/extracting-key-pair-values-using-nested-json-paths/295419/1 "2022-01-26T05:45:23Z")

</div>

Hi Guys,

I'm Using Json plugin in filter and trying to fetch a value which resides in below json path.

`parsedJson.query.bool.filter[0].bool.must[0].bool.must[2].term["list_attributes.orderId.long"].value`

and actually complete json looks like below.

```auto
{
  "_source": false,
  "from": 0,
  "query": {
    "bool": {
      "filter": [
        {
          "bool": {
            "must": [
              {
                "bool": {
                  "must": [
                    {
                      "bool": {
                        "must_not": [
                          {
                            "terms": {
                              "list_attributes.id.long": [
                                123456
                              ],
                              "boost": 1
                            }
                          }
                        ],
                        "adjust_pure_negative": true,
                        "boost": 1
                      }
                    },
                    {
                      "term": {
                        "list_attributes.xxxx.long": {
                          "value": 123456,
                          "boost": 1
                        }
                      }
                    },
                    {
                      "term": {
                        "list_attributes.orderId.long": {
                          "value": 12345,
                          "boost": 1
                        }
                      }
                    }
                  ],
                  "adjust_pure_negative": true,
                  "boost": 1
                }
              },
              {
                "term": {
                  "active": {
                    "value": true,
                    "boost": 1
                  }
                }
              },
              {
                "term": {
                  "deleted": {
                    "value": false,
                    "boost": 1
                  }
                }
              }
            ],
            "adjust_pure_negative": true,
            "boost": 1
          }
        }
      ],
      "adjust_pure_negative": true,
      "boost": 1
    }
  },
  "size": 24,
  "sort": [
    {
      "attributes.startdate": {
        "order": "desc",
        "missing": "_last",
        "unmapped_type": "long"
      }
    }
  ],
  "version": true
}

```

And, So In Filter plugin I've used below json path to get the value of orderId, but Its not extracting the value, can anyone help me in escaping double Quotes ? or How can we extract such values using json paths?

```auto
mutate{
 add_field => {"orderId" => "%{[parsedJson][query][bool][filter][0][bool][must][0][bool][must][2][term]["list_attributes.orderId.long"][value]}"}
}

```

```auto
mutate{
 add_field => {"orderId" => "%{[parsedJson][query][bool][filter][0][bool][must][0][bool][must][2][term][\"list_attributes.orderId.long\"][value]}"}
}

```

Thanks,  
Vaseem

---

<div class="post-metadata">

**Author:** ![Tomo\_M](https://avatars.discourse-cdn.com/v4/letter/t/848f3c/32.png) [@Tomo\_M](https://discuss.elastic.co/u/Tomo_M)\
**Post date:** [January 26, 2022, 8:55am UTC](https://discuss.elastic.co/t/extracting-key-pair-values-using-nested-json-paths/295419/2 "2022-01-26T08:55:07Z")

</div>

Have you tried path without quotes like `%{[parsedJson][query][bool][filter][0][bool][must][0][bool][must][2][term][indexed_attributes.orderId.long][value]}`?

---

<div class="post-metadata">

**Author:** ![vaseemQA](https://avatars.discourse-cdn.com/v4/letter/v/4491bb/32.png) [@vaseemQA](https://discuss.elastic.co/u/vaseemQA)\
**Post date:** [January 26, 2022, 8:59am UTC](https://discuss.elastic.co/t/extracting-key-pair-values-using-nested-json-paths/295419/3 "2022-01-26T08:59:22Z")

</div>

Yes I tried this, It doesn't worked

☹

---

<div class="post-metadata">

**Author:** ![Tomo\_M](https://avatars.discourse-cdn.com/v4/letter/t/848f3c/32.png) [@Tomo\_M](https://discuss.elastic.co/u/Tomo_M)\
**Post date:** [January 26, 2022, 12:33pm UTC](https://discuss.elastic.co/t/extracting-key-pair-values-using-nested-json-paths/295419/4 "2022-01-26T12:33:18Z")

</div>

Hmm, it's strange.  
It worked completely fine for me.

```auto
input {
 file {
   mode => "read"
   path => ["C:/test_json_path.json"]
   start_position => "beginning"
   exit_after_read => true
   file_completed_action => "log"
   file_completed_log_path => "C:/test.log"
   codec => multiline {
        pattern => "^{"
        negate => "true"
        what => "previous"
    }
 }
}
filter {
    json{
        source => "message"
        target => "doc"
        remove_field => "message"
    }
}
filter {
 mutate{
  add_field => {"orderID" => "%{[doc][query][bool][filter][0][bool][must][0][bool][must][2][term][list_attributes.orderId.long][value]}"}
  remove_field => "doc"
 }
}
output {
   stdout { codec => rubydebug }
}

```

```auto
{
    "@timestamp" => 2022-01-26T12:32:30.140Z,
          "path" => "C:/test_json_path.json",
          "tags" => [
        [0] "multiline"
    ],
       "orderID" => "12345",
      "@version" => "1",
          "host" => "DESKTOP-RGB3EPD"
}

```

---

<div class="post-metadata">

**Author:** ![vaseemQA](https://avatars.discourse-cdn.com/v4/letter/v/4491bb/32.png) [@vaseemQA](https://discuss.elastic.co/u/vaseemQA)\
**Post date:** [January 26, 2022, 1:35pm UTC](https://discuss.elastic.co/t/extracting-key-pair-values-using-nested-json-paths/295419/5 "2022-01-26T13:35:26Z")

</div>

Hey @Tomo_M ,

Sorry Yes It worked, I had some typo error.

Thanks,

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 23, 2022, 1:36pm UTC](https://discuss.elastic.co/t/extracting-key-pair-values-using-nested-json-paths/295419/6 "2022-02-23T13:36:27Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
