# Filebeat json decode dynamic target uses kubernetes pod name

**URL:** <https://discuss.elastic.co/t/filebeat-json-decode-dynamic-target-uses-kubernetes-pod-name/202996>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [October 10, 2019, 10:00am UTC](https://discuss.elastic.co/t/filebeat-json-decode-dynamic-target-uses-kubernetes-pod-name/202996 "2019-10-10T10:00:58Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![juka](https://avatars.discourse-cdn.com/v4/letter/j/8491ac/32.png) [@juka](https://discuss.elastic.co/u/juka)\
**Post date:** [October 10, 2019, 10:00am UTC](https://discuss.elastic.co/t/filebeat-json-decode-dynamic-target-uses-kubernetes-pod-name/202996/1 "2019-10-10T10:00:58Z")

</div>

Hello,

is it possible to use a dynamic target in the decode\_json\_fields processor?  
[https://www.elastic.co/guide/en/beats/filebeat/current/decode-json-fields.html](https://www.elastic.co/guide/en/beats/filebeat/current/decode-json-fields.html)

I would like to have a target as follows:  
processors:

- decode\_json\_fields:  
fields: ["message"]  
process\_array: false  
max\_depth: 1  
target: "pmsg.kubernetes.pod.name"

pmsg.kubernetes.pod.name -\> message holds a json string which is decoded an put behind the target.

pmsg -\> is a fixed string.  
kubernetes.pod.name -\> has the kubernetes pod name where the message is coming from -\> that name changes depending on the pod name.

Thanks for your help

---

<div class="post-metadata">

**Author:** ![exekias](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/exekias/32/28718_2.png) [@exekias](https://discuss.elastic.co/u/exekias)\
**Post date:** [October 18, 2019, 1:07pm UTC](https://discuss.elastic.co/t/filebeat-json-decode-dynamic-target-uses-kubernetes-pod-name/202996/2 "2019-10-18T13:07:23Z")

</div>

Hi @juka,

I think there is no way to do that with the `decode_json_fields`. But something you could do is using the [rename processor](https://www.elastic.co/guide/en/beats/filebeat/current/rename-fields.html) to rename after decoding.

Would that help in this case?

Best regards

---

<div class="post-metadata">

**Author:** ![juka](https://avatars.discourse-cdn.com/v4/letter/j/8491ac/32.png) [@juka](https://discuss.elastic.co/u/juka)\
**Post date:** [October 21, 2019, 8:53am UTC](https://discuss.elastic.co/t/filebeat-json-decode-dynamic-target-uses-kubernetes-pod-name/202996/3 "2019-10-21T08:53:55Z")

</div>

Thank you for your reply.  
I can imagine using the rename processor if it gives me the option of accessing the kubernetes.pod.name for renaming

Currently we have a kubernetes cluster with several pods who log in json format. That json string is getting decoded and receives the prefix "pmsg" via the target option. My problem is that the pods have the same key names in the logging output but the values are sometimes strings, integers, etc. which leads to mapping conflicts.

I would like to parse the json string, decode it and write into different key names which include kubernetes pod information.

Is it possible to access the kubernetes.pod.name in the rename processor? By that I mean:

> ```
> processors:
> - rename:
> fields:
> - from: "pmsg.error_message"
> to: "nameofthekubernetespod.error_message"
> 
> ```

nameofthekubernetespod.error\_message -\> this would be a dynamic field because the name of the kubernets pod changes.

Thank you for your help!

---

<div class="post-metadata">

**Author:** ![exekias](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/exekias/32/28718_2.png) [@exekias](https://discuss.elastic.co/u/exekias)\
**Post date:** [October 22, 2019, 12:59pm UTC](https://discuss.elastic.co/t/filebeat-json-decode-dynamic-target-uses-kubernetes-pod-name/202996/4 "2019-10-22T12:59:49Z")

</div>

Yes, as far as I know that should be possible

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 19, 2019, 12:59pm UTC](https://discuss.elastic.co/t/filebeat-json-decode-dynamic-target-uses-kubernetes-pod-name/202996/5 "2019-11-19T12:59:50Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
