# Fields are not populating from logstash to elastic

**URL:** <https://discuss.elastic.co/t/fields-are-not-populating-from-logstash-to-elastic/348593>\
**Category:** Logstash\
**Created:** [December 4, 2023, 7:59pm UTC](https://discuss.elastic.co/t/fields-are-not-populating-from-logstash-to-elastic/348593 "2023-12-04T19:59:44Z")\
**Posts on this page:** 12\
**Page:** 1

<div class="post-metadata">

**Author:** ![mmercaldi](https://avatars.discourse-cdn.com/v4/letter/m/a3d4f5/32.png) [@mmercaldi](https://discuss.elastic.co/u/mmercaldi)\
**Post date:** [December 4, 2023, 7:59pm UTC](https://discuss.elastic.co/t/fields-are-not-populating-from-logstash-to-elastic/348593/1 "2023-12-04T19:59:44Z")

</div>

I am using logstash to populate elastic  
I have it set so this filter:

```auto
filter {
  json {
    source => "message"
    target => "jsoncontent"
    remove_field => ["message"]
    }
}

```

and

````auto
jsoncontent: {"switchname": "switch1", "interface": "Ethernet101/1/5", "vlan": "25", "speed": "a-1000", "duplex": "full"}```
type or paste code here

````

to populate elastic  
However the only field I get is jsoncontent. I want fields created for switchname, interface, vlan, speed, duplex

Any idea how I can create those fields?

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [December 4, 2023, 8:42pm UTC](https://discuss.elastic.co/t/fields-are-not-populating-from-logstash-to-elastic/348593/2 "2023-12-04T20:42:47Z")

</div>

> [@mmercaldi](#):
>
> `the only field I get is jsoncontent`

The [jsoncontent] field is created by the json filter. There will be fields within like [jsoncontent][switchname]. If you want those at the top level then remove the target option from the json filter.

---

<div class="post-metadata">

**Author:** ![mmercaldi](https://avatars.discourse-cdn.com/v4/letter/m/a3d4f5/32.png) [@mmercaldi](https://discuss.elastic.co/u/mmercaldi)\
**Post date:** [December 4, 2023, 9:42pm UTC](https://discuss.elastic.co/t/fields-are-not-populating-from-logstash-to-elastic/348593/3 "2023-12-04T21:42:03Z")

</div>

when I remove the top filter I get a json error in my output saying that a target is needed  
Parsed JSON object/hash requires a target configuration option {:source=\>"message",

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [December 4, 2023, 10:12pm UTC](https://discuss.elastic.co/t/fields-are-not-populating-from-logstash-to-elastic/348593/4 "2023-12-04T22:12:00Z")

</div>

OK, so check [this](https://discuss.elastic.co/t/how-to-dynamically-move-nested-key-value-to-root-level/180006/2) thread.

---

<div class="post-metadata">

**Author:** ![mmercaldi](https://avatars.discourse-cdn.com/v4/letter/m/a3d4f5/32.png) [@mmercaldi](https://discuss.elastic.co/u/mmercaldi)\
**Post date:** [December 5, 2023, 2:47pm UTC](https://discuss.elastic.co/t/fields-are-not-populating-from-logstash-to-elastic/348593/5 "2023-12-05T14:47:12Z")

</div>

sorry I am confused, how does the ruby code help?

---

<div class="post-metadata">

**Author:** ![mmercaldi](https://avatars.discourse-cdn.com/v4/letter/m/a3d4f5/32.png) [@mmercaldi](https://discuss.elastic.co/u/mmercaldi)\
**Post date:** [December 5, 2023, 3:36pm UTC](https://discuss.elastic.co/t/fields-are-not-populating-from-logstash-to-elastic/348593/6 "2023-12-05T15:36:56Z")

</div>

I see how it could help but my code is not working  
did I do something wrong on it:

```auto
filter {
  json {
    source => "message"
    target => "jsoncontent"
    remove_field => ["message"]
    }
}

ruby {
  code => '
    event.get("jsoncontent").each { |k, v|
    event.set(k,v)}
    event.remove("jsoncontent")'
}

```

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [December 5, 2023, 5:09pm UTC](https://discuss.elastic.co/t/fields-are-not-populating-from-logstash-to-elastic/348593/7 "2023-12-05T17:09:43Z")

</div>

What do you see if you use `output { stdout { codec => rubydebug } } `?

---

<div class="post-metadata">

**Author:** ![mmercaldi](https://avatars.discourse-cdn.com/v4/letter/m/a3d4f5/32.png) [@mmercaldi](https://discuss.elastic.co/u/mmercaldi)\
**Post date:** [December 5, 2023, 7:00pm UTC](https://discuss.elastic.co/t/fields-are-not-populating-from-logstash-to-elastic/348593/8 "2023-12-05T19:00:15Z")

</div>

> [@Badger](#):
>
> stdout { codec =\> rubydebug

For some reason with the ruby code the conf file will not launch, so I cannot get a stdout

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [December 5, 2023, 7:22pm UTC](https://discuss.elastic.co/t/fields-are-not-populating-from-logstash-to-elastic/348593/9 "2023-12-05T19:22:30Z")

</div>

So remove the ruby filter and post the rubydebug.

---

<div class="post-metadata">

**Author:** ![mmercaldi](https://avatars.discourse-cdn.com/v4/letter/m/a3d4f5/32.png) [@mmercaldi](https://discuss.elastic.co/u/mmercaldi)\
**Post date:** [December 5, 2023, 9:19pm UTC](https://discuss.elastic.co/t/fields-are-not-populating-from-logstash-to-elastic/348593/10 "2023-12-05T21:19:51Z")

</div>

sorry for the delay:

```auto
          "event" => {
        "original" => "\"{\\\"switchname\\\": \\\"switch1\\\", \\\"interface\\\": \\\"Ethernet101/1/2\\\", \\\"vlan\\\": \\\"254\\\", \\\"speed\\\": \\\"a-1000\\\", \\\"duplex\\\": \\\"full\\\"}\""
    },
    "jsoncontent" => "{\"switchname\": \"switch1\", \"interface\": \"Ethernet101/1/2\", \"vlan\": \"254\", \"speed\": \"a-1000\", \"duplex\": \"full\"}",
       "@version" => "1",
     "@timestamp" => 2023-12-05T21:17:44.717761918Z,
           "host" => {
        "ip" => "5.5.5.5"
    }
}

```

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [December 5, 2023, 10:44pm UTC](https://discuss.elastic.co/t/fields-are-not-populating-from-logstash-to-elastic/348593/11 "2023-12-05T22:44:34Z")

</div>

OK, you will need to use a second json filter to parse [jsoncontent].

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 2, 2024, 10:44pm UTC](https://discuss.elastic.co/t/fields-are-not-populating-from-logstash-to-elastic/348593/12 "2024-01-02T22:44:39Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
