# Flattening JSON string level with other fields

**URL:** <https://discuss.elastic.co/t/flattening-json-string-level-with-other-fields/309182>\
**Category:** Kibana\
**Created:** [July 8, 2022, 8:25am UTC](https://discuss.elastic.co/t/flattening-json-string-level-with-other-fields/309182 "2022-07-08T08:25:09Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Mostafa\_Talebi](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mostafa_talebi/32/108063_2.png) [@Mostafa\_Talebi](https://discuss.elastic.co/u/Mostafa_Talebi)\
**Post date:** [July 8, 2022, 8:25am UTC](https://discuss.elastic.co/t/flattening-json-string-level-with-other-fields/309182/1 "2022-07-08T08:25:09Z")

</div>

I have set up my kibana and Elastic.  
I am getting my logs from Fluentbit.  
My main app log, which is JSON, is sent by Fluent with other meta fields like this:

```auto
{
    "containerId": "foo",
    "clusterId" : "bar",
    "source" : "stderr",
    "log" : "{ type: error, "msg": "cannot connect to redis" }" // My JSON-FORMATTED LOG GOES HERE 
}

```

I want to be able to extract fields "type" and "msg" from JSON (which is treated as string in ES) and level those with the rest of fields. This enables me to set filters and indexing properly for them.

How should I approach this?

Things I've tried:  
In Data view I tried to add a field log.type (considering dot-notation works) but it doesn't work.  
In Index Management, I tried to update field mappings but it doesn't allow me editing the index's fields mapping (I have full privileges).

I am looking to have my list of logs to include "type" and "msg" as distinct columns: searchable and filtertable.

---

<div class="post-metadata">

**Author:** ![nickpeihl](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nickpeihl/32/112622_2.png) [@nickpeihl](https://discuss.elastic.co/u/nickpeihl)\
**Post date:** [July 8, 2022, 4:03pm UTC](https://discuss.elastic.co/t/flattening-json-string-level-with-other-fields/309182/2 "2022-07-08T16:03:43Z")

</div>

I'm not familiar with Fluentbit since it isn't an Elastic product. But you might be able to set up an [Ingest pipeline](https://www.elastic.co/guide/en/elasticsearch/reference/8.3/ingest.html) and use the [JSON processor](https://www.elastic.co/guide/en/elasticsearch/reference/8.3/json-processor.html) to convert the JSON string to an object.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 5, 2022, 4:04pm UTC](https://discuss.elastic.co/t/flattening-json-string-level-with-other-fields/309182/3 "2022-08-05T16:04:07Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
