# How can I parse array of objects using Logstash?

**URL:** <https://discuss.elastic.co/t/how-can-i-parse-array-of-objects-using-logstash/228640>\
**Category:** Logstash\
**Created:** [April 18, 2020, 12:22pm UTC](https://discuss.elastic.co/t/how-can-i-parse-array-of-objects-using-logstash/228640 "2020-04-18T12:22:01Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![cezar996](https://avatars.discourse-cdn.com/v4/letter/c/e95f7d/32.png) [@cezar996](https://discuss.elastic.co/u/cezar996)\
**Post date:** [April 18, 2020, 12:22pm UTC](https://discuss.elastic.co/t/how-can-i-parse-array-of-objects-using-logstash/228640/1 "2020-04-18T12:22:01Z")

</div>

Hello everybody!

Does anybody knows how can I parse an array of objects of this type:` [{name:Cezar, age:23}, {name:Leon, age:22}, {name:Steven, age:33}]`. Every object should be an event in `Discovery` Section. Please take into consideration that this array is written in a single line (it comes from some logs extracted in Elasticsearch). I have tried and read a lot of configurations and I did't solve the problem.

Thanks in advance!

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [April 18, 2020, 5:11pm UTC](https://discuss.elastic.co/t/how-can-i-parse-array-of-objects-using-logstash/228640/2 "2020-04-18T17:11:12Z")

</div>

Use a json filter with the target option set, then use a split filter.

---

<div class="post-metadata">

**Author:** ![stcdarrell](https://avatars.discourse-cdn.com/v4/letter/s/a183cd/32.png) [@stcdarrell](https://discuss.elastic.co/u/stcdarrell)\
**Post date:** [April 19, 2020, 2:57am UTC](https://discuss.elastic.co/t/how-can-i-parse-array-of-objects-using-logstash/228640/3 "2020-04-19T02:57:30Z")

</div>

seems to be an array of jsons..

without more of the schema its kinda hard.. but it'll be either

```
filter {
     json{
             source => "[name_of_field]"
     }
}

```

or

```
filter {
 split {
   field => "[name_of_field]"
 }
}
```

---

<div class="post-metadata">

**Author:** ![cezar996](https://avatars.discourse-cdn.com/v4/letter/c/e95f7d/32.png) [@cezar996](https://discuss.elastic.co/u/cezar996)\
**Post date:** [April 20, 2020, 8:53am UTC](https://discuss.elastic.co/t/how-can-i-parse-array-of-objects-using-logstash/228640/4 "2020-04-20T08:53:21Z")

</div>

Thank you guys for your responses! I don't understand what `"[name_of_field]"` refers to. I don't have anything before `[`. My file contains a large JSON array of 30 MB which begins with `[` and ends with `]`, having nothing before or after. If I want to edit this big file, I use Notepad, but it works very very slow. So it won't be a very good solution to append a field in front of the array. Therefore, taking into consideration my above example, `[{name:Cezar, age:23}, {name:Leon, age:22}, {name:Steven, age:33}]` , by using Logstash, I want to get in Elasticsearch an index with 3 docs. Every doc should have these 2 columns: name and age. The first one with (Cezar,23), the second one with (Leon, 22), etc.  
Do you know how could I do this more exactly? Thanks in advance!

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [April 20, 2020, 3:22pm UTC](https://discuss.elastic.co/t/how-can-i-parse-array-of-objects-using-logstash/228640/5 "2020-04-20T15:22:38Z")

</div>

[name\_of\_field] is a reference to a field called name\_of\_field. You did not tell us what your field name is, and we have no way of knowing. If your field is called message then you would use [message] in those filters.

---

<div class="post-metadata">

**Author:** ![cezar996](https://avatars.discourse-cdn.com/v4/letter/c/e95f7d/32.png) [@cezar996](https://discuss.elastic.co/u/cezar996)\
**Post date:** [April 21, 2020, 8:29am UTC](https://discuss.elastic.co/t/how-can-i-parse-array-of-objects-using-logstash/228640/6 "2020-04-21T08:29:15Z")

</div>

Hi @Badger!

Thank you for your precious replies! I have read numerous topics on `discuss.elastic.co` and I saw you gave very important pieces of advice. I have succeeded in sending data to Elasticsearch for the example above where I had an array with 3 objects. In order to do that, I have used the following configuration in Logstash:

```
input {
  file {
    path => ["/home/..../json-file-name"]
    start_position => "beginning"
    sincedb_path => ["/home/..../sincedb"]
    codec => "json"
  }
}

filter {
if [message] {
    drop { }
  }
}

output {
  elasticsearch {
    hosts => ["http://localhost:9200"]
    index => "setlogs-%{+YYYY.MM.dd}"
  }
  
  stdout {
	codec => rubydebug
  }
}

```

It works for my example with 3 objects. But when try to do this for my JSON array which has 30 MB and almost 4300 objects, Logstash doesn't print anything. It is like it waits for some input. I let Logstash running for 50 min. but when I saw there is no output I closed it. Do you have any idea what happened?

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [April 21, 2020, 3:31pm UTC](https://discuss.elastic.co/t/how-can-i-parse-array-of-objects-using-logstash/228640/7 "2020-04-21T15:31:53Z")

</div>

> [@cezar996](#):
>
> if [message] { drop { } }

Interesting. If you have a json codec then if it successfully parses the event it does not set the [message] field. So this is dropping any events that were not successfully parsed. It is a really, really obscure way to achieve that, and will confuse a lot of people. I suggest you remove that and see what you get on stdout.

I suggest you remove

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 19, 2020, 3:31pm UTC](https://discuss.elastic.co/t/how-can-i-parse-array-of-objects-using-logstash/228640/8 "2020-05-19T15:31:54Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
