# How to convert string to JSON?

**URL:** <https://discuss.elastic.co/t/how-to-convert-string-to-json/102845>\
**Category:** Logstash\
**Created:** [October 5, 2017, 1:23pm UTC](https://discuss.elastic.co/t/how-to-convert-string-to-json/102845 "2017-10-05T13:23:48Z")\
**Posts on this page:** 11\
**Page:** 1

<div class="post-metadata">

**Author:** ![iStepich](https://avatars.discourse-cdn.com/v4/letter/i/dbc845/32.png) [@iStepich](https://discuss.elastic.co/u/iStepich)\
**Post date:** [October 5, 2017, 1:23pm UTC](https://discuss.elastic.co/t/how-to-convert-string-to-json/102845/1 "2017-10-05T13:23:48Z")

</div>

My logstash configuration is:  
input {  
tcp{  
codec =\> json\_lines {charset =\> "CP1251"}  
...  
}  
}  
output {  
elasticsearch{...}}

But there is a problem that I can recieve string to already mapped as object field.  
In that case in elasticsearch occures an error and I lose this line in the results:

`org.elasticsearch.index.mapper.MapperParsingException: object mapping for [detail.data.response.body] tried to parse field [body] as object, but found a concrete value`

I tried mutate/replace or  
filter  
{  
if [detail][data][response][body]  
{  
if [detail][data][response][body] == "Unauthorized"  
{  
json\_encode  
{  
source =\> "[detail][data][response][body]"  
}  
}  
}  
}

but had no success. Can you help me, please?

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [October 5, 2017, 1:37pm UTC](https://discuss.elastic.co/t/how-to-convert-string-to-json/102845/2 "2017-10-05T13:37:52Z")

</div>

The mapping of `detail.data.response.body` is inconsistent with the data you're attempting to index. What kind of value(s) _should_ `detail.data.response.body` contain? An object or a value? What are you trying to index? Comment out the elasticsearch output and add a `stdout { codec => rubydebug }` output.

---

<div class="post-metadata">

**Author:** ![iStepich](https://avatars.discourse-cdn.com/v4/letter/i/dbc845/32.png) [@iStepich](https://discuss.elastic.co/u/iStepich)\
**Post date:** [October 5, 2017, 1:56pm UTC](https://discuss.elastic.co/t/how-to-convert-string-to-json/102845/3 "2017-10-05T13:56:01Z")

</div>

As usual it comes as json:  
"body":{"values":[], etc}  
But sometimes I recieve  
"body":"Unauthorized"  
or  
"body":"Not Found"

I would like to replace this kinds of strings with  
"body":{"thesebeautifulpeoplegavemeastring":"Unauthorized"}  
or  
"body":{"thesebeautifulpeoplegavemeastring":"Not Found"}

[2017-10-05T17:16:21,702][DEBUG][o.e.a.b.TransportShardBulkAction] [test\_node\_name] [logstash-2017.10.05][1] failed to execute bulk item (index) BulkShardRequest [[logstash-2017.10.05][1]] containing [10] requests  
org.elasticsearch.index.mapper.MapperParsingException: object mapping for [detail.data.response.body] tried to parse field [body] as object, but found a concrete value

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [October 5, 2017, 2:28pm UTC](https://discuss.elastic.co/t/how-to-convert-string-to-json/102845/4 "2017-10-05T14:28:44Z")

</div>

I think you'll have to use a ruby filter to check whether the value is a string and, if so, convert it to a hash. Something like

```nohighlight
if event.get('body').is_a? String
  event.set('body', {"thesebeautifulpeoplegavemeastring" => "Unauthorized"})
end

```

might work.

---

<div class="post-metadata">

**Author:** ![iStepich](https://avatars.discourse-cdn.com/v4/letter/i/dbc845/32.png) [@iStepich](https://discuss.elastic.co/u/iStepich)\
**Post date:** [October 5, 2017, 3:09pm UTC](https://discuss.elastic.co/t/how-to-convert-string-to-json/102845/5 "2017-10-05T15:09:37Z")

</div>

looks like what I wanted, but when i added filter

> ```
> filter 
> {
> if [detail][data][response][body]
> {
> ruby
> {
> code => "
> if event.get('detail.data.response.body').is_a? String
> event.set('detail.data.response.body', {'givenstring' => event.get('detail.data.response.body')})
> end"
> }
> }
> }
> 
> ```

the logstash began to restart all the time and became unresponsive

---

<div class="post-metadata">

**Author:** ![guyboertje](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/guyboertje/32/31592_2.png) [@guyboertje](https://discuss.elastic.co/u/guyboertje)\
**Post date:** [October 5, 2017, 5:10pm UTC](https://discuss.elastic.co/t/how-to-convert-string-to-json/102845/6 "2017-10-05T17:10:14Z")

</div>

try `event.get('[detail][data][response][body]')`

---

<div class="post-metadata">

**Author:** ![iStepich](https://avatars.discourse-cdn.com/v4/letter/i/dbc845/32.png) [@iStepich](https://discuss.elastic.co/u/iStepich)\
**Post date:** [October 6, 2017, 8:15am UTC](https://discuss.elastic.co/t/how-to-convert-string-to-json/102845/7 "2017-10-06T08:15:46Z")

</div>

made

> ```
> filter 
> {
> if [detail][data][response][body]
> {
> ruby
> {
> code => "
> if event.get('[detail][data][response][body]').is_a? String
> event.set('[detail][data][response][body]', {'[detail][data][response][body][givenstring]' => event.get('[detail][data][response][body]')})
> end"
> }
> }
> }
> 
> ```

didnt work, again infinite restart

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [October 6, 2017, 8:59am UTC](https://discuss.elastic.co/t/how-to-convert-string-to-json/102845/8 "2017-10-06T08:59:46Z")

</div>

What's the error message?

Also,

```
{'[detail][data][response][body][givenstring]' => event.get('[detail][data][response][body]')}

```

should be:

```
{'givenstring' => event.get('[detail][data][response][body]')}
```

---

<div class="post-metadata">

**Author:** ![guyboertje](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/guyboertje/32/31592_2.png) [@guyboertje](https://discuss.elastic.co/u/guyboertje)\
**Post date:** [October 6, 2017, 9:00am UTC](https://discuss.elastic.co/t/how-to-convert-string-to-json/102845/9 "2017-10-06T09:00:18Z")

</div>

A) **Post some lines from the console output to show the infinite restart - usually, there is some details that we can use to troubleshoot**.

B) **Which version of Logstash are you using?**

C) try:

```auto
filter 
{
  if [detail][data][response][body]
  {
    ruby
    { init => '
        BODY_PATH = "[detail][data][response][body]".freeze
        BODY_STRING = "[givenstring]".freeze
      '
      code => '
        body_val = event.get(BODY_PATH)
        if body_val.is_a?(String)
          event.set(BODY_PATH, {BODY_STRING => body_val})
        end
      '
    }
  }
}

```

About the Ruby code.

1. Create strings once as Ruby Constants in the plugin initialization. This prevents unnecessary string creation for every filter invocation - the event.set will deconstruct the path reference into new string parts internally anyway so a new string each time is a waste.
2. Freeze the Constants, this will prevent other code from changing them.
3. Extract the value to a local variable once and reuse.

---

<div class="post-metadata">

**Author:** ![iStepich](https://avatars.discourse-cdn.com/v4/letter/i/dbc845/32.png) [@iStepich](https://discuss.elastic.co/u/iStepich)\
**Post date:** [October 6, 2017, 9:31am UTC](https://discuss.elastic.co/t/how-to-convert-string-to-json/102845/10 "2017-10-06T09:31:36Z")

</div>

That works perfectly! Thank you very much! Especially for explanation!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 3, 2017, 9:32am UTC](https://discuss.elastic.co/t/how-to-convert-string-to-json/102845/11 "2017-11-03T09:32:03Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
