# How do I parse inner fields from json?

**URL:** <https://discuss.elastic.co/t/how-do-i-parse-inner-fields-from-json/70988>\
**Category:** Logstash\
**Created:** [January 9, 2017, 7:35pm UTC](https://discuss.elastic.co/t/how-do-i-parse-inner-fields-from-json/70988 "2017-01-09T19:35:52Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Ben\_Davis](https://avatars.discourse-cdn.com/v4/letter/b/d2c977/32.png) [@Ben\_Davis](https://discuss.elastic.co/u/Ben_Davis)\
**Post date:** [January 9, 2017, 7:35pm UTC](https://discuss.elastic.co/t/how-do-i-parse-inner-fields-from-json/70988/1 "2017-01-09T19:35:52Z")

</div>

My log is full of nested json like so...

```
   {
         "foo": 1, 
              "result":{
                   "time":"2017-01-09T02.01:50.000+0000",
                   "product":"blahblah",
                   "quantity":"20"
              }
         }
    }

```

I only care about the innermost fields named time, product, and quantity. I want logstash to parse those into individual fields.

I've tried

```
filter{
   json{
      source => "result"
   }
}

```

And the output is one huge string containing the result field, it does not parse out the contents.

I've been all over the documentation but can't get it right. Any advice?

thank you,

- Ben

---

<div class="post-metadata">

**Author:** ![Andrew\_Cholakian1](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrew_cholakian1/32/3612_2.png) [@Andrew\_Cholakian1](https://discuss.elastic.co/u/Andrew_Cholakian1)\
**Post date:** [January 9, 2017, 8:33pm UTC](https://discuss.elastic.co/t/how-do-i-parse-inner-fields-from-json/70988/2 "2017-01-09T20:33:20Z")

</div>

@Ben_Davis you probably want to use a `json` or `json_lines` codec (not filter) with whatever input you're using. So, if you're using the stdin input you'd want `input { stdin => { codec => json_lines } }` in your input section. Then, you would use a [prune](https://discuss.elastic.co/t/how-do-i-parse-inner-fields-from-json/70988) filter to pick which fields you do/don't want.

---

<div class="post-metadata">

**Author:** ![Ben\_Davis](https://avatars.discourse-cdn.com/v4/letter/b/d2c977/32.png) [@Ben\_Davis](https://discuss.elastic.co/u/Ben_Davis)\
**Post date:** [January 9, 2017, 8:34pm UTC](https://discuss.elastic.co/t/how-do-i-parse-inner-fields-from-json/70988/3 "2017-01-09T20:34:53Z")

</div>

Thank you very much!

including

codec =\> "json"

in the input section seems to have done the trick.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 6, 2017, 8:35pm UTC](https://discuss.elastic.co/t/how-do-i-parse-inner-fields-from-json/70988/4 "2017-02-06T20:35:58Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
