# How create fields using json fileter in logstash

**URL:** <https://discuss.elastic.co/t/how-create-fields-using-json-fileter-in-logstash/236557>\
**Category:** Logstash\
**Created:** [June 10, 2020, 5:47pm UTC](https://discuss.elastic.co/t/how-create-fields-using-json-fileter-in-logstash/236557 "2020-06-10T17:47:16Z")\
**Posts on this page:** 12\
**Page:** 1

<div class="post-metadata">

**Author:** ![Ramalakshmi](https://avatars.discourse-cdn.com/v4/letter/r/f9ae1b/32.png) [@Ramalakshmi](https://discuss.elastic.co/u/Ramalakshmi)\
**Post date:** [June 10, 2020, 5:47pm UTC](https://discuss.elastic.co/t/how-create-fields-using-json-fileter-in-logstash/236557/1 "2020-06-10T17:47:17Z")

</div>

Hi  
I am getting json formated data I can able to split the data into fields using json plugin in logstash,but with in the fields i am some more fields.Please help me out to get those fields also.  
Below is the example for the field

```
  resource.instanceDetails.networkInterfaces {

```

"privateIpAddresses": [  
{  
"privateIpAddress": "xxxxxxx",  
"privateDnsName": null  
},  
{  
"privateIpAddress": "xxxxxxxxxxx",  
"privateDnsName": ""  
}  
],  
"ipv6Addresses": ,  
"privateDnsName": null,  
"privateIpAddress": "xxxxxxx",  
"networkInterfaceId": "xxxxxxxxx",  
"securityGroups": [  
{  
"groupName": "xxxxxxxx",  
"groupId": "xxxxxxxx"  
}  
],  
"subnetId": "xxxxxxx",  
"vpcId": "xxxxxxxx"  
},  
{  
"privateIpAddresses": [  
{  
"privateIpAddress": "xxxxxxxx",  
"privateDnsName": null  
}  
],  
"ipv6Addresses": ,  
"privateDnsName": null,  
"privateIpAddress": "xxxxxxxxxxx",  
"networkInterfaceId": "xxxxxxxx",  
"securityGroups": [  
{  
"groupName": "xxxxxxx",  
"groupId": "xxxxxx"  
}  
],  
"subnetId": "xxxxxxx",  
"vpcId": "xxxxxxx"  
},  
{  
"privateIpAddresses": [  
{  
"privateIpAddress": "xxxxxxx,  
"privateDnsName": null  
},  
{  
"privateIpAddress": "xxxxxxx",  
"privateDnsName": ""  
},  
{  
"privateIpAddress": "xxxxxx",  
"privateDnsName": ""  
},  
{  
"privateIpAddress": "xxxxxxxx",  
"privateDnsName": ""  
},  
{  
"privateIpAddress": "xxxxxxxx",  
"privateDnsName": ""  
},  
{  
"privateIpAddress": "xxxxxx,  
"privateDnsName": ""  
}  
],  
"publicIp": "xxxxxx,  
"privateDnsName": null,  
"ipv6Addresses": ,  
"networkInterfaceId": "xxxxxxxx",  
"securityGroups": [  
{  
"groupName": "xxxxxxxx",  
"groupId": "xxxxxxxxx"  
}  
],  
"privateIpAddress": "xxxxxxx",  
"subnetId": "xxxxxxxx",  
"vpcId": "xxxxxx",  
"publicDnsName": ""  
},  
{  
"privateIpAddresses": [  
{  
"privateIpAddress": "xxxxxxxxx",  
"privateDnsName": null  
}  
],  
"ipv6Addresses": ,  
"privateDnsName": null,  
"privateIpAddress": "xxxxxxxx",  
"networkInterfaceId": "xxxxxxx",  
"securityGroups": [  
{  
"groupName": "xxxxxxxx",  
"groupId": "xxxxxxxxx"  
}  
],  
"subnetId": "xxxxxxx",  
"vpcId": "xxxxxxxx"

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [June 10, 2020, 6:05pm UTC](https://discuss.elastic.co/t/how-create-fields-using-json-fileter-in-logstash/236557/2 "2020-06-10T18:05:22Z")

</div>

Please edit your post, select the JSON, and click on \</\> in the toolbar about the edit pane. That will improve the formatting of your text.

What is the problem with the current way the data is structured? What do you want to change?

---

<div class="post-metadata">

**Author:** ![Ramalakshmi](https://avatars.discourse-cdn.com/v4/letter/r/f9ae1b/32.png) [@Ramalakshmi](https://discuss.elastic.co/u/Ramalakshmi)\
**Post date:** [June 10, 2020, 6:11pm UTC](https://discuss.elastic.co/t/how-create-fields-using-json-fileter-in-logstash/236557/3 "2020-06-10T18:11:40Z")

</div>

Hey Badger,  
In that data having different sub fields like privateipaddresses, sunbetid and vpcid etc.so those fields need to create in logstash.

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [June 10, 2020, 6:34pm UTC](https://discuss.elastic.co/t/how-create-fields-using-json-fileter-in-logstash/236557/4 "2020-06-10T18:34:20Z")

</div>

If you are using a json filter to parse the message then all of the sub-fields will get created.

---

<div class="post-metadata">

**Author:** ![Ramalakshmi](https://avatars.discourse-cdn.com/v4/letter/r/f9ae1b/32.png) [@Ramalakshmi](https://discuss.elastic.co/u/Ramalakshmi)\
**Post date:** [June 10, 2020, 6:39pm UTC](https://discuss.elastic.co/t/how-create-fields-using-json-fileter-in-logstash/236557/5 "2020-06-10T18:39:56Z")

</div>

No, It's not creating.Please tell me how to create those subfileds.

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [June 10, 2020, 7:04pm UTC](https://discuss.elastic.co/t/how-create-fields-using-json-fileter-in-logstash/236557/6 "2020-06-10T19:04:37Z")

</div>

If you change your output to

```
output { stdout { codec => rubydebug } }

```

then what does an event look like in the output?

---

<div class="post-metadata">

**Author:** ![Ramalakshmi](https://avatars.discourse-cdn.com/v4/letter/r/f9ae1b/32.png) [@Ramalakshmi](https://discuss.elastic.co/u/Ramalakshmi)\
**Post date:** [June 10, 2020, 7:17pm UTC](https://discuss.elastic.co/t/how-create-fields-using-json-fileter-in-logstash/236557/7 "2020-06-10T19:17:58Z")

</div>

I have already given same thing in output section,but there is no change.

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [June 10, 2020, 8:53pm UTC](https://discuss.elastic.co/t/how-create-fields-using-json-fileter-in-logstash/236557/8 "2020-06-10T20:53:08Z")

</div>

If you do not supply the information required to answer you question you will not get an answer. What does a complete event look like in rubydebug?

---

<div class="post-metadata">

**Author:** ![Ramalakshmi](https://avatars.discourse-cdn.com/v4/letter/r/f9ae1b/32.png) [@Ramalakshmi](https://discuss.elastic.co/u/Ramalakshmi)\
**Post date:** [June 11, 2020, 11:32am UTC](https://discuss.elastic.co/t/how-create-fields-using-json-fileter-in-logstash/236557/9 "2020-06-11T11:32:48Z")

</div>

In output section I have given output { stdout { codec =\> rubydebug } } and I got the same result

---

<div class="post-metadata">

**Author:** ![Jenni](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jenni/32/29684_2.png) [@Jenni](https://discuss.elastic.co/u/Jenni)\
**Post date:** [June 11, 2020, 12:08pm UTC](https://discuss.elastic.co/t/how-create-fields-using-json-fileter-in-logstash/236557/10 "2020-06-11T12:08:08Z")

</div>

He's been asking you repeatedly to post the actual data output that you see. The code that he gave you was not meant to change anything about your results, but to produce the detailed information about your events that is needed to debug your pipeline.

---

<div class="post-metadata">

**Author:** ![Ramalakshmi](https://avatars.discourse-cdn.com/v4/letter/r/f9ae1b/32.png) [@Ramalakshmi](https://discuss.elastic.co/u/Ramalakshmi)\
**Post date:** [June 11, 2020, 3:06pm UTC](https://discuss.elastic.co/t/how-create-fields-using-json-fileter-in-logstash/236557/11 "2020-06-11T15:06:48Z")

</div>

Hey Jenni,  
It means logstash configuration file.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 9, 2020, 3:06pm UTC](https://discuss.elastic.co/t/how-create-fields-using-json-fileter-in-logstash/236557/12 "2020-07-09T15:06:56Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
