# \[filebeat\] - Json processor

**URL:** <https://discuss.elastic.co/t/filebeat-json-processor/303789>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [May 2, 2022, 11:34pm UTC](https://discuss.elastic.co/t/filebeat-json-processor/303789 "2022-05-02T23:34:49Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![JH82](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jh82/32/45952_2.png) [@JH82](https://discuss.elastic.co/u/JH82)\
**Post date:** [May 2, 2022, 11:34pm UTC](https://discuss.elastic.co/t/filebeat-json-processor/303789/1 "2022-05-02T23:34:49Z")

</div>

Hello, I try to make a JSON transform with processor in filebeat (with http\_endpoint as input).  
2 questions :

- when I send a simple json message like  
`{"message":"OK"}`  
I receive :  
`{"message": "success"}` but I get many extra unwanted data in addition of my Original JSON.  
why not have just `"{"document":{"message":"OK"}}"` into \_source ?

but in elastic db i've

```auto
{
  "_index": "cri-2022",
  "_type": "_doc",
  "_id": "aWcWh4ABcwp0swy5bbh_",
  "_version": 1,
  "_score": 1,
  "_source": {
    "@timestamp": "2022-05-02T23:23:54.543Z",
    "host": {
      "name": "lenovox1g2"
    },
    "agent": {
      "name": "lenovox1g2"
    },
    "ecs": {},
    "json": {
      "message": "OK"
    },
    "input": {}
  },
  "fields": {
    "json.message": [
      "OK"
    ],
    "agent.name": [
      "lenovox1g2"
    ],
    "@timestamp": [
      "2022-05-02T23:23:54.543Z"
    ],
    "host.name": [
      "lenovox1g2"
    ]
  }
}

```

Question 2 :

if I have a message like this  
`{"content":["1"],"default_value":"\"Module 1\"","field":2}` and I want to transforme into  
`{"Module 1":{"content":["1"],"field":2}`

is it possible to do this with processor or other anyway with filebeat ?

Thank you !

Regards.

---

<div class="post-metadata">

**Author:** ![Tetiana\_Kravchenko](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tetiana_kravchenko/32/102683_2.png) [@Tetiana\_Kravchenko](https://discuss.elastic.co/u/Tetiana_Kravchenko)\
**Post date:** [May 5, 2022, 1:20pm UTC](https://discuss.elastic.co/t/filebeat-json-processor/303789/2 "2022-05-05T13:20:15Z")

</div>

Hi @JH82

regarding question 2 - it should be possible to achieve with [script](https://www.elastic.co/guide/en/beats/filebeat/current/processor-script.html) processor.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 2, 2022, 3:20pm UTC](https://discuss.elastic.co/t/filebeat-json-processor/303789/3 "2022-06-02T15:20:33Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
