# Extracting some JSON fields from the message

**URL:** <https://discuss.elastic.co/t/extracting-some-json-fields-from-the-message/296479>\
**Category:** Logstash\
**Created:** [February 7, 2022, 1:49pm UTC](https://discuss.elastic.co/t/extracting-some-json-fields-from-the-message/296479 "2022-02-07T13:49:30Z")\
**Posts on this page:** 1\
**Showing post:** 7

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [February 8, 2022, 5:37pm UTC](https://discuss.elastic.co/t/extracting-some-json-fields-from-the-message/296479/7 "2022-02-08T17:37:21Z")

</div>

You could try

```
    grok { match => { "message" => "{(?<[@metadata][kvData]>[^}]+)}$" } }
    kv { source => "[@metadata][kvData]" field_split => "," trim_key => " " }

```

which will produce

```
          "apiType" => "HTTP",
"proxyResponseCode" => "500",
        "errorType" => "null",
 "applicationOwner" => "admin"
```

---

_[View the full topic](https://discuss.elastic.co/t/extracting-some-json-fields-from-the-message/296479)._
