# Grep on input message with json format

**URL:** <https://discuss.elastic.co/t/grep-on-input-message-with-json-format/36221>\
**Category:** Logstash\
**Created:** [December 2, 2015, 7:28pm UTC](https://discuss.elastic.co/t/grep-on-input-message-with-json-format/36221 "2015-12-02T19:28:53Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![vimalmpatel](https://avatars.discourse-cdn.com/v4/letter/v/49beb7/32.png) [@vimalmpatel](https://discuss.elastic.co/u/vimalmpatel)\
**Post date:** [December 2, 2015, 7:28pm UTC](https://discuss.elastic.co/t/grep-on-input-message-with-json-format/36221/1 "2015-12-02T19:28:54Z")

</div>

hello

my input message is in json format. if i want to use condition to create new tag within jason how would i do that . please correct me if i am wrong.

input file record

{"applicationID":"12348811","timestamp":"2015-11-12T21:15:25.092Z","approved":1,"rejected":0}

log stash configuration

input {  
file {  
path =\> "C:\xxx.log"  
}  
}

filter {  
if [approved] =1  
json {  
add\_field =\> {  
"new\_field" =\> "Application Accepted"  
}  
}  
}

output {  
elasticsearch {  
host =\> "localhost"  
protocol =\> "http"  
index =\> "xxx-%{+YYYY.MM.dd}"  
}  
}

expected output in elastic

{"applicationID":"12348811","timestamp":"2015-11-12T21:15:25.092Z","approved":1,"rejected":0,"new\_field":"Application Accepted}

---

<div class="post-metadata">

**Author:** ![vtst2412](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/vtst2412/32/6228_2.png) [@vtst2412](https://discuss.elastic.co/u/vtst2412)\
**Post date:** [December 2, 2015, 7:47pm UTC](https://discuss.elastic.co/t/grep-on-input-message-with-json-format/36221/2 "2015-12-02T19:47:48Z")

</div>

Well, did you run that config? What was the output? I tend to use the json filter in this manner as I'm not sure if you can put an if condition inside of a filter.

```
input {
  file {
    path => "C:\xxx.log"
  }
}

filter {
  json {
    source => "message"
   }
  if [approved] == 1 {
      mutate {
         add_field => {
              "new_field" => "Application Accepted"
         }
      }
   }
# this is optional if you don't want to collect events that are not approved
# else {
# drop {} 
# }
}

output {
    elasticsearch {
        host => "localhost"
        protocol => "http"
        index => "xxx-%{+YYYY.MM.dd}"
    }
}
```

---

<div class="post-metadata">

**Author:** ![vimalmpatel](https://avatars.discourse-cdn.com/v4/letter/v/49beb7/32.png) [@vimalmpatel](https://discuss.elastic.co/u/vimalmpatel)\
**Post date:** [December 2, 2015, 7:50pm UTC](https://discuss.elastic.co/t/grep-on-input-message-with-json-format/36221/3 "2015-12-02T19:50:57Z")

</div>

No it did not work in the first run. i will try it out with this one. Thanks

---

<div class="post-metadata">

**Author:** ![vimalmpatel](https://avatars.discourse-cdn.com/v4/letter/v/49beb7/32.png) [@vimalmpatel](https://discuss.elastic.co/u/vimalmpatel)\
**Post date:** [December 2, 2015, 7:56pm UTC](https://discuss.elastic.co/t/grep-on-input-message-with-json-format/36221/4 "2015-12-02T19:56:21Z")

</div>

One more thing i was referring [https://www.elastic.co/guide/en/logstash/current/plugins-filters-json.html](https://www.elastic.co/guide/en/logstash/current/plugins-filters-json.html) where you can add field. why do i need to use mutate ? i know you can do it using mutate but want to make i can use this also.

filter {  
json {  
add\_field =\> { "foo\_%{somefield}" =\> "Hello world, from %{host}" }  
}  
}

---

<div class="post-metadata">

**Author:** ![vtst2412](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/vtst2412/32/6228_2.png) [@vtst2412](https://discuss.elastic.co/u/vtst2412)\
**Post date:** [December 2, 2015, 8:16pm UTC](https://discuss.elastic.co/t/grep-on-input-message-with-json-format/36221/5 "2015-12-02T20:16:10Z")

</div>

You can use add\_field in the json filter as well. However, you only want to add\_field `if [approved] == 1`, so we have to breakout of the json filter to do that. You can use the json filter instead of mutate inside of the conditional clause if that bothers you. (add\_field is pretty standard among the filters)

---

<div class="post-metadata">

**Author:** ![vimalmpatel](https://avatars.discourse-cdn.com/v4/letter/v/49beb7/32.png) [@vimalmpatel](https://discuss.elastic.co/u/vimalmpatel)\
**Post date:** [December 2, 2015, 8:23pm UTC](https://discuss.elastic.co/t/grep-on-input-message-with-json-format/36221/6 "2015-12-02T20:23:04Z")

</div>

perfect Thanks

---

<div class="post-metadata">

**Author:** ![vimalmpatel](https://avatars.discourse-cdn.com/v4/letter/v/49beb7/32.png) [@vimalmpatel](https://discuss.elastic.co/u/vimalmpatel)\
**Post date:** [January 14, 2016, 9:01pm UTC](https://discuss.elastic.co/t/grep-on-input-message-with-json-format/36221/8 "2016-01-14T21:01:47Z")

</div>

i did exactly what you suggested but it is not adding extra field

filter {  
json {  
source =\> "message"  
}  
if [approved] == "0" {  
mutate {  
add\_field =\> {  
"ApproveIndicator" =\> "0"  
}  
}  
}  
else if [approved] == "1" {  
mutate {  
add\_field =\> {  
"ApproveIndicator" =\> "1"  
}  
}  
}  
else {  
drop {}  
}  
}

---

<div class="post-metadata">

**Author:** ![vtst2412](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/vtst2412/32/6228_2.png) [@vtst2412](https://discuss.elastic.co/u/vtst2412)\
**Post date:** [January 26, 2016, 3:24pm UTC](https://discuss.elastic.co/t/grep-on-input-message-with-json-format/36221/9 "2016-01-26T15:24:08Z")

</div>

Can you run this in debug for one document and provide the output?  
Also you didn't put the integer in double quotations originally, why changed? I'm wondering if it's treating them as string and not matching the equality.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 5:14am UTC](https://discuss.elastic.co/t/grep-on-input-message-with-json-format/36221/10 "2017-07-06T05:14:16Z")

</div>


