# Get value from json object

**URL:** <https://discuss.elastic.co/t/get-value-from-json-object/224347>\
**Category:** Kibana\
**Created:** [March 20, 2020, 5:10am UTC](https://discuss.elastic.co/t/get-value-from-json-object/224347 "2020-03-20T05:10:41Z")\
**Posts on this page:** 12\
**Page:** 1

<div class="post-metadata">

**Author:** ![Avend544](https://avatars.discourse-cdn.com/v4/letter/a/43a26b/32.png) [@Avend544](https://discuss.elastic.co/u/Avend544)\
**Post date:** [March 20, 2020, 5:10am UTC](https://discuss.elastic.co/t/get-value-from-json-object/224347/1 "2020-03-20T05:10:41Z")

</div>

Hi!  
I have Kibana 7.3.2. I want to use own scripted field.  
I spent 5 hours for looking for the good try to get value from json object for a my scripted field.  
I have a next field with json object:  
{ "timestamp": "2020-03-18 12:01:23.1811",  
"correlationId": "825ee105-0eab-4f56-9c96-939c621d9c18",  
"level": "INFO", "logger":  
"Contracts",  
"message": "WorkerService.Work :825ee105-0eab-4f56-9c96-939c621d9c18",  
"json": {"SysInfo": {"TimeStamp": 1582013206597,  
"InfId": 1,"Version": "v1","Method": "GetRsaId",  
"Parameters": {"cisContractId": "ab06ca8c-92df-4405-92ec-c1fd53cbfe41",  
"cisAddendumId": "cfd35e89-e342-4678-9419-13da5fdc5f36",  
"docType": "Contract",  
"docSeries": "XXX",  
"docNumber": "3456789120"},  
"TicketId": "6f9619ff-8b86-d011-b42d-00cf4cf964ff",  
"Comment": "something"}} }

I used this:

1. `doc['message.keyword.correlationId']`
2. `doc['message.keyword.correlationId'].value`
3. `doc['message.keyword']['correlationId']`
4. `doc['message.keyword']['correlationId'].value`

But all tries fell.

Can u help with the my issue?

---

<div class="post-metadata">

**Author:** ![lukeelmers](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/lukeelmers/32/35230_2.png) [@lukeelmers](https://discuss.elastic.co/u/lukeelmers)\
**Post date:** [March 20, 2020, 5:47pm UTC](https://discuss.elastic.co/t/get-value-from-json-object/224347/2 "2020-03-20T17:47:00Z")

</div>

Hi @Avend544 -- What does your error output say?

One other thing you could try is using `params._source`:

```auto
params._source.message.correlationId

```

---

<div class="post-metadata">

**Author:** ![Avend544](https://avatars.discourse-cdn.com/v4/letter/a/43a26b/32.png) [@Avend544](https://discuss.elastic.co/u/Avend544)\
**Post date:** [March 23, 2020, 2:27am UTC](https://discuss.elastic.co/t/get-value-from-json-object/224347/3 "2020-03-23T02:27:29Z")

</div>

Hi @lukeelmers ! Thanks for your quick answer!  
I get next error, when i try open the my index in the discover panel:

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/5/5/55e6e20181e20f8b565fe5a5246abf1d0f4fc01b.png)

The your example doesn't work. I attached message of kibana logs. I guess problem in another level of the kibana's message.

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/2/5/25dd36deddab647b3067d0d50cea3199c3b67683.png)

When i call field like that : `doc['message.keyword']` i get full string, but I want get field from message property. For example "correlationId".

---

<div class="post-metadata">

**Author:** ![lukeelmers](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/lukeelmers/32/35230_2.png) [@lukeelmers](https://discuss.elastic.co/u/lukeelmers)\
**Post date:** [March 25, 2020, 3:26pm UTC](https://discuss.elastic.co/t/get-value-from-json-object/224347/4 "2020-03-25T15:26:15Z")

</div>

> When i call field like that : `doc['message.keyword']` i get full string, but I want get field from message property.

What does your mapping for `message` look like? Is it a string?

If so, that's most likely your problem -- you'll need to parse that string in your scripted field first (which isn't going to be very performant).

You might instead consider ingesting this as a nested field, assuming you don't need to build visualizations on top of this data. [Visualizations support for nested fields is coming soon](https://github.com/elastic/kibana/issues/1084#issuecomment-585178079), but currently they are only supported in Discover.

---

<div class="post-metadata">

**Author:** ![Avend544](https://avatars.discourse-cdn.com/v4/letter/a/43a26b/32.png) [@Avend544](https://discuss.elastic.co/u/Avend544)\
**Post date:** [March 26, 2020, 2:56am UTC](https://discuss.elastic.co/t/get-value-from-json-object/224347/5 "2020-03-26T02:56:45Z")

</div>

Yes, it is a string field. Can do i convert this field to the JSON or only use parse?  
What script language can understand scripted field?  
I using [https://groovyconsole.appspot.com/](https://groovyconsole.appspot.com/) but not all methods works in the painless script, which work in groovy.  
Can u give a link to the all method supported in the Painless

---

<div class="post-metadata">

**Author:** ![Avend544](https://avatars.discourse-cdn.com/v4/letter/a/43a26b/32.png) [@Avend544](https://discuss.elastic.co/u/Avend544)\
**Post date:** [March 26, 2020, 7:08am UTC](https://discuss.elastic.co/t/get-value-from-json-object/224347/6 "2020-03-26T07:08:01Z")

</div>

I try parse a string:  
`String docNumberdConst = "docNumber";  
def message = doc['message.keyword'];  
String message1 = (String)message;  
if(message1.contains(docNumberdConst)){  
int indx = message1.indexOf(docNumberdConst);  
return String.valueOf(indx);  
}

return "empty";`

But when i try cast painless string to java string `(String)message;`, i get a next error:

Request to Elasticsearch failed: {"error":{"root\_cause":[{"type":"class\_cast\_exception","reason":"class\_cast\_exception: cannot explicitly cast def [org.elasticsearch.index.fielddata.ScriptDocValues.Strings] to java.lang.String"},{"type":"class\_cast\_exception","reason":"class\_cast\_exception: cannot explicitly cast def [org.elasticsearch.index.fielddata.ScriptDocValues.Strings] to java.lang.String"},{"type":"class\_cast\_exception","reason":"class\_cast\_exception: cannot explicitly cast def [org.elasticsearch.index.fielddata.ScriptDocValues.Strings] to java.lang.String"}],"type":"search\_phase\_execution\_exception","reason":"all shards failed","phase":"fetch","grouped":true,"failed\_shards":[{"shard":0,"index":"contracts-copy-svc-2020.03.18","node":"B42056aPTIm5sWSxuQamCA","reason":{"type":"script\_exception","reason":"runtime error","script\_stack":["message1 = (String)message;\r\n"," ^---- HERE"],"script":"String docNumberdConst = "docNumber";\r\ndef message = doc['message.keyword'];\r\nString message1 = (String)message;\r\nif(message1.contains(docNumberdConst)){\r\n int indx = message1.indexOf(docNumberdConst);\r\n return String.valueOf(indx);\r\n}\r\n\r\nreturn "empty";\r\n","lang":"painless","caused\_by":{"type":"class\_cast\_exception","reason":"class\_cast\_exception: cannot explicitly cast def [org.elasticsearch.index.fielddata.ScriptDocValues.Strings] to java.lang.String"}}},{"shard":0,"index":"contracts-copy-svc-2020.03.25","node":"lHWpRR4iSOeBcjGgEHeplA","reason":{"type":"script\_exception","reason":"runtime error","script\_stack":["message1 = (String)message;\r\n"," ^---- HERE"],"script":"String docNumberdConst = "docNumber";\r\ndef message = doc['message.keyword'];\r\nString message1 = (String)message;\r\nif(message1.contains(docNumberdConst)){\r\n int indx = message1.indexOf(docNumberdConst);\r\n return String.valueOf(indx);\r\n}\r\n\r\nreturn "empty";\r\n","lang":"painless","caused\_by":{"type":"class\_cast\_exception","reason":"class\_cast\_exception: cannot explicitly cast def [org.elasticsearch.index.fielddata.ScriptDocValues.Strings] to java.lang.String"}}},{"shard":0,"index":"contracts-copy-svc-2020.03.26","node":"B42056aPTIm5sWSxuQamCA","reason":{"type":"script\_exception","reason":"runtime error","script\_stack":["message1 = (String)message;\r\n"," ^---- HERE"],"script":"String docNumberdConst = "docNumber";\r\ndef message = doc['message.keyword'];\r\nString message1 = (String)message;\r\nif(message1.contains(docNumberdConst)){\r\n int indx = message1.indexOf(docNumberdConst);\r\n return String.valueOf(indx);\r\n}\r\n\r\nreturn "empty";\r\n","lang":"painless","caused\_by":{"type":"class\_cast\_exception","reason":"class\_cast\_exception: cannot explicitly cast def [org.elasticsearch.index.fielddata.ScriptDocValues.Strings] to java.lang.String"}}}],"caused\_by":{"type":"class\_cast\_exception","reason":"class\_cast\_exception: cannot explicitly cast def [org.elasticsearch.index.fielddata.ScriptDocValues.Strings] to java.lang.String"}},"status":400}

```auto
Error: Request to Elasticsearch failed: {"error":{"root_cause":[{"type":"class_cast_exception","reason":"class_cast_exception: cannot explicitly cast def [org.elasticsearch.index.fielddata.ScriptDocValues.Strings] to java.lang.String"},{"type":"class_cast_exception","reason":"class_cast_exception: cannot explicitly cast def [org.elasticsearch.index.fielddata.ScriptDocValues.Strings] to java.lang.String"},{"type":"class_cast_exception","reason":"class_cast_exception: cannot explicitly cast def [org.elasticsearch.index.fielddata.ScriptDocValues.Strings] to java.lang.String"}],"type":"search_phase_execution_exception","reason":"all shards failed","phase":"fetch","grouped":true,"failed_shards":[{"shard":0,"index":"contracts-copy-svc-2020.03.18","node":"B42056aPTIm5sWSxuQamCA","reason":{"type":"script_exception","reason":"runtime error","script_stack":["message1 = (String)message;\r\n"," ^---- HERE"],"script":"String docNumberdConst = \"docNumber\";\r\ndef message = doc['message.keyword'];\r\nString message1 = (String)message;\r\nif(message1.contains(docNumberdConst)){\r\n int indx = message1.indexOf(docNumberdConst);\r\n return String.valueOf(indx);\r\n}\r\n\r\nreturn \"empty\";\r\n","lang":"painless","caused_by":{"type":"class_cast_exception","reason":"class_cast_exception: cannot explicitly cast def [org.elasticsearch.index.fielddata.ScriptDocValues.Strings] to java.lang.String"}}},{"shard":0,"index":"contracts-copy-svc-2020.03.25","node":"lHWpRR4iSOeBcjGgEHeplA","reason":{"type":"script_exception","reason":"runtime error","script_stack":["message1 = (String)message;\r\n"," ^---- HERE"],"script":"String docNumberdConst = \"docNumber\";\r\ndef message = doc['message.keyword'];\r\nString message1 = (String)message;\r\nif(message1.contains(docNumberdConst)){\r\n int indx = message1.indexOf(docNumberdConst);\r\n return String.valueOf(indx);\r\n}\r\n\r\nreturn \"empty\";\r\n","lang":"painless","caused_by":{"type":"class_cast_exception","reason":"class_cast_exception: cannot explicitly cast def [org.elasticsearch.index.fielddata.ScriptDocValues.Strings] to java.lang.String"}}},{"shard":0,"index":"contracts-copy-svc-2020.03.26","node":"B42056aPTIm5sWSxuQamCA","reason":{"type":"script_exception","reason":"runtime error","script_stack":["message1 = (String)message;\r\n"," ^---- HERE"],"script":"String docNumberdConst = \"docNumber\";\r\ndef message = doc['message.keyword'];\r\nString message1 = (String)message;\r\nif(message1.contains(docNumberdConst)){\r\n int indx = message1.indexOf(docNumberdConst);\r\n return String.valueOf(indx);\r\n}\r\n\r\nreturn \"empty\";\r\n","lang":"painless","caused_by":{"type":"class_cast_exception","reason":"class_cast_exception: cannot explicitly cast def [org.elasticsearch.index.fielddata.ScriptDocValues.Strings] to java.lang.String"}}}],"caused_by":{"type":"class_cast_exception","reason":"class_cast_exception: cannot explicitly cast def [org.elasticsearch.index.fielddata.ScriptDocValues.Strings] to java.lang.String"}},"status":400}
```

---

<div class="post-metadata">

**Author:** ![Avend544](https://avatars.discourse-cdn.com/v4/letter/a/43a26b/32.png) [@Avend544](https://discuss.elastic.co/u/Avend544)\
**Post date:** [March 26, 2020, 9:53am UTC](https://discuss.elastic.co/t/get-value-from-json-object/224347/7 "2020-03-26T09:53:35Z")

</div>

I try use method indexOf but i cant find my pattern value "docNumber" from `doc['message.keyword'];`  
When i use indexOf with `doc['message.keyword'];` method return -1  
But when i use it on another string like that "asdasdasda docNumber asdasdas" i get index by my pattern.  
I don't understand why i don't get index of pattern...

Code:  
`String docNumberdConst = "docNumber"; def message1 = doc['message.keyword']; int i = message1.indexOf(docNumberdConst); if(i >= 0){ return "exist"; } return "EMPTY " + i;`

---

<div class="post-metadata">

**Author:** ![lukeelmers](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/lukeelmers/32/35230_2.png) [@lukeelmers](https://discuss.elastic.co/u/lukeelmers)\
**Post date:** [March 26, 2020, 7:53pm UTC](https://discuss.elastic.co/t/get-value-from-json-object/224347/8 "2020-03-26T19:53:12Z")

</div>

> [@Avend544](#):
>
> Can u give a link to the all method supported in the Painless

[The painless specification](https://www.elastic.co/guide/en/elasticsearch/painless/current/index.html) and [the painless API reference](https://www.elastic.co/guide/en/elasticsearch/painless/7.6/painless-api-reference.html) should have the information you are looking for.

> [@lukeelmers](#):
>
> If so, that's most likely your problem -- you'll need to parse that string in your scripted field first (which isn't going to be very performant).

My bad, but I just realized I was mistaken in this comment above -- I forgot that painless doesn't actually allow JSON parsing in its API. (In part because it would be really terrible from a performance perspective as I mentioned).

So your best bet is going to be parsing those `message` strings to objects at ingest time as stated in the comment above... these two threads have more on this topic:

- [How to convert a json format string to json object using painless script kibana](https://discuss.elastic.co/t/how-to-convert-a-json-format-string-to-json-object-using-painless-script-kibana/210684)
- [Painless scripting JSON functions](https://discuss.elastic.co/t/painless-scripting-json-functions/98511)

The only other alternative I can think of would be [regex matching for a substring](https://discuss.elastic.co/t/substring-in-painless/88660/3), which is also going to slow things down, and definitely isn't considered a best practice for a situation like this.

---

<div class="post-metadata">

**Author:** ![Avend544](https://avatars.discourse-cdn.com/v4/letter/a/43a26b/32.png) [@Avend544](https://discuss.elastic.co/u/Avend544)\
**Post date:** [March 27, 2020, 4:45am UTC](https://discuss.elastic.co/t/get-value-from-json-object/224347/9 "2020-03-27T04:45:57Z")

</div>

@lukeelmers, Can u help with regex example ?  
i try this, but it doesn't work....  
`def m = /\|docNumber([^\|]+)/.matcher(doc['message.keyword']);`  
`if (m.matches()) {`  
`return m.group(1);`  
`} else {`  
` return "EMPTY";`  
`}`  
I got a next exception: "Script is invalid. View script preview for details". If i can open some view with error text, then tell to me pls

And what's problem in parse `doc['message.keyword']` why i can't use it? Why Painlees string different by Java string?

---

<div class="post-metadata">

**Author:** ![Avend544](https://avatars.discourse-cdn.com/v4/letter/a/43a26b/32.png) [@Avend544](https://discuss.elastic.co/u/Avend544)\
**Post date:** [April 1, 2020, 7:09am UTC](https://discuss.elastic.co/t/get-value-from-json-object/224347/10 "2020-04-01T07:09:01Z")

</div>

I attached the screenshot with my filed and it's type.

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/a/6/a676aae7cff138172d03ac3aa1d421a762f78a98.png)  
May be it help u give a solution to me.  
If i can change type of field, then can u say how to make it. It will help me for take value like a string and will perform this with Java api.

---

<div class="post-metadata">

**Author:** ![Avend544](https://avatars.discourse-cdn.com/v4/letter/a/43a26b/32.png) [@Avend544](https://discuss.elastic.co/u/Avend544)\
**Post date:** [April 6, 2020, 4:56am UTC](https://discuss.elastic.co/t/get-value-from-json-object/224347/11 "2020-04-06T04:56:36Z")

</div>

I found a solution. I just separated my json object on filebeat layer, and after that i get value like from ordinary field.  
I add that string in filebeat.yml  
#----------------------------- Logstash output --------------------------------  
output.logstash:  
hosts: ["[elog.kibana.ru:5001](http://elog.kibana.ru:5001)"]  
and after that elastic will do automatic seporating JSON object and recognizing type of field

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 4, 2020, 4:56am UTC](https://discuss.elastic.co/t/get-value-from-json-object/224347/12 "2020-05-04T04:56:46Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
