# How to add a specific key to a field from a JSON format part

**URL:** <https://discuss.elastic.co/t/how-to-add-a-specific-key-to-a-field-from-a-json-format-part/272384>\
**Category:** Logstash\
**Created:** [May 7, 2021, 8:13am UTC](https://discuss.elastic.co/t/how-to-add-a-specific-key-to-a-field-from-a-json-format-part/272384 "2021-05-07T08:13:20Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![its-ogawa](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/its-ogawa/32/120829_2.png) [@its-ogawa](https://discuss.elastic.co/u/its-ogawa)\
**Post date:** [May 7, 2021, 8:13am UTC](https://discuss.elastic.co/t/how-to-add-a-specific-key-to-a-field-from-a-json-format-part/272384/1 "2021-05-07T08:13:20Z")

</div>

I was able to get a JSON part from a message in grok.  
I want to keep a specific key from the JSON part in a field, how can I do that?

target log:  
`... snip ... { ... snip ..., "api_code":"40216", ... snip ... } ... snip ...`

my grok:

```auto
grok{
	"match" => { "message" => " ... snip ... (?<MY_JSON>\{.*\})( %{GREEDYDATA:message})? ... snip ..." }
}

```

result:  
`MY_JSON : { ... snip ..., "api_code":"40216", ... snip ... }`

expect:

```auto
MY_JSON : { ... snip ..., "api_code":"40216", ... snip ... }
api_code : 40216

```

---

<div class="post-metadata">

**Author:** ![its-ogawa](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/its-ogawa/32/120829_2.png) [@its-ogawa](https://discuss.elastic.co/u/its-ogawa)\
**Post date:** [May 12, 2021, 1:56am UTC](https://discuss.elastic.co/t/how-to-add-a-specific-key-to-a-field-from-a-json-format-part/272384/2 "2021-05-12T01:56:36Z")

</div>

Can anyone give me some good ideas?

---

<div class="post-metadata">

**Author:** ![its-ogawa](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/its-ogawa/32/120829_2.png) [@its-ogawa](https://discuss.elastic.co/u/its-ogawa)\
**Post date:** [May 12, 2021, 2:56am UTC](https://discuss.elastic.co/t/how-to-add-a-specific-key-to-a-field-from-a-json-format-part/272384/3 "2021-05-12T02:56:58Z")

</div>

Yeah. I see what you mean.

It looks like it uses the json plugin.

> **[JSON filter plugin | Logstash Reference \[7.12\] | Elastic](https://www.elastic.co/guide/en/logstash/current/plugins-filters-json.html)**

I thought I'd have to use regular expressions, but Logstash has a nice feature.

Here is the code I wrote.

```auto
if( [MY_JSON] ) {
  json {
    source => "MY_JSON"
  }
}

```

---

<div class="post-metadata">

**Author:** ![its-ogawa](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/its-ogawa/32/120829_2.png) [@its-ogawa](https://discuss.elastic.co/u/its-ogawa)\
**Post date:** [May 12, 2021, 3:05am UTC](https://discuss.elastic.co/t/how-to-add-a-specific-key-to-a-field-from-a-json-format-part/272384/4 "2021-05-12T03:05:04Z")

</div>

Note that this method adds all the values in json format to the field.

If you don't want to include them in the field, use `remove_field`.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 9, 2021, 3:05am UTC](https://discuss.elastic.co/t/how-to-add-a-specific-key-to-a-field-from-a-json-format-part/272384/5 "2021-06-09T03:05:23Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
