# Follow-up from "Unable to avoid JSON parsing errors in logstash log-file"

**URL:** <https://discuss.elastic.co/t/follow-up-from-unable-to-avoid-json-parsing-errors-in-logstash-log-file/276641>\
**Category:** Logstash\
**Created:** [June 22, 2021, 11:02am UTC](https://discuss.elastic.co/t/follow-up-from-unable-to-avoid-json-parsing-errors-in-logstash-log-file/276641 "2021-06-22T11:02:13Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![es-gabriele](https://avatars.discourse-cdn.com/v4/letter/e/eb9ed0/32.png) [@es-gabriele](https://discuss.elastic.co/u/es-gabriele)\
**Post date:** [June 22, 2021, 11:02am UTC](https://discuss.elastic.co/t/follow-up-from-unable-to-avoid-json-parsing-errors-in-logstash-log-file/276641/1 "2021-06-22T11:02:13Z")

</div>

Hi everyone,  
I am using ELK 7.2.

I did read from a past answer [here](https://discuss.elastic.co/t/unable-to-avoid-json-parsing-errors-in-logstash-log-file/84673/2) and I found it useful, as what I need to do is to make logstash correctly parse json data, and also an array of nested json objects.

However, if I need to parse both json and also json in form of an array of json objects, what would it be the configuration? For now, I did read this` [{},{}]`

Is there a way to correctly embed that part of regex to the one I am already using (wrote as an answer on the forum, here below)?

```auto
if [message] =~ "\A\{.+\}\z" {
  json { .. }
}

```

To make the setup clearer, because of this problem I tried to temporarily cast every type that passes through logstash as string, so the objects will not be aggregatable by ELK but at least they can be read. I tried this ruby filter

```auto

filter {
 ruby {
        code => '
            def stringify(object, name, event)
                if object == nil
                    event.set(name, "nil" )
                elsif object.kind_of?(Hash) and object != {}
                    object.each { |k, v| stringify(v, "#{name}[#{k}]", event) }
                elsif object.kind_of?(Array) and object != []
                    object.each_index { |i|
                        stringify(object[i], "#{name}[#{i}]", event)
                    }
                else
                    event.set(name, object.to_s)
                end
            end
            stringify(event.get("extraData"), "[extraData]", event)
        '
    }
}

```

and it seem to work, at least on my local configuration. However, in the actual environment (which is also created by Terraform) that does not work.

If I could correctly ingest and parse the source [message] as it should perhaps this ruby filter to cast everything to string is not even needed.

Can you please confirm me the regex above? How can I make such json and json array of objects correctly parsed by logstash?

Many thanks

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 20, 2021, 11:03am UTC](https://discuss.elastic.co/t/follow-up-from-unable-to-avoid-json-parsing-errors-in-logstash-log-file/276641/2 "2021-07-20T11:03:05Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
