# How to extract message from nested json

**URL:** <https://discuss.elastic.co/t/how-to-extract-message-from-nested-json/158336>\
**Category:** Logstash\
**Created:** [November 27, 2018, 12:14pm UTC](https://discuss.elastic.co/t/how-to-extract-message-from-nested-json/158336 "2018-11-27T12:14:22Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Dan](https://avatars.discourse-cdn.com/v4/letter/d/eada6e/32.png) [@Dan](https://discuss.elastic.co/u/Dan)\
**Post date:** [November 27, 2018, 12:14pm UTC](https://discuss.elastic.co/t/how-to-extract-message-from-nested-json/158336/1 "2018-11-27T12:14:22Z")

</div>

this is below json format as input  
I am getting overall message in the nested format

> {  
> "\_type": "json",  
> "\_id": "AWdVED5hASX98xJL-Xkw",  
> "\_score": 1,  
> "\_source": {  
> "value1": "rajesh",  
> "@version": "1",  
> "host": "DESKTOP-xxxx",  
> "message": "03-Jan-18,rajesh,22\r",  
> "type": "json",  
> "date1": "03-Jan-18",  
> "cumvalue": "22",  
> "abcxyz": {  
> "value1": "rajesh",  
> "@version": "1",  
> "host": "DESKTOP-xxxx",  
> "message": "03-Jan-18,rajesh,22\r",  
> "type": "json",  
> "date1": "03-Jan-18",  
> "cumvalue": "22"  
> }  
> },  
> "fields": {  
> "abcxyz.@timestamp": [  
> 1543320387251  
> ],  
> "@timestamp": [  
> 1543320387251  
> ]  
> }  
> }

column like "date1","value1","cumvalue" i am not interested in this columns

i just interested in nested node i.e abcxyz

i want to sent this(abcxyz) as a message by dropping all other columns

my final output should looks like below

```
"abcxyz": {
  "value1": "rajesh",
  "@version": "1",
  "host": "DESKTOP-xxxxx",
  "message": "03-Jan-18,rajesh,22\r",
  "type": "json",
  "date1": "03-Jan-18",
  "cumvalue": "22"
}

```

i tried with below config file here I don't want to use multiple rename filters  
I just simply wants to drop original message and replace that message with nested json message(abcxyz)

> ```
> > input{
> > 
> > } 
> > filter {
> > 
> > 
> > split {field => "[abcxyz]"}
> > 
> > mutate {	
> > rename => { "[abcxyz][date1]" => "date1" }
> > rename => { "[abcxyz][value1]" => "value1" }
> > rename => { "[abcxyz][cumvalue]" => "cumvalue" }
> > }
> > 
> > 
> > } 
> > output {  
> > elastic
> > }
> 
> ```

---

<div class="post-metadata">

**Author:** ![Eniqmatic](https://avatars.discourse-cdn.com/v4/letter/e/ea5d25/32.png) [@Eniqmatic](https://discuss.elastic.co/u/Eniqmatic)\
**Post date:** [November 27, 2018, 12:38pm UTC](https://discuss.elastic.co/t/how-to-extract-message-from-nested-json/158336/2 "2018-11-27T12:38:10Z")

</div>

Simply use a "remove\_field" configuration to remove all the fields you do not want.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 25, 2018, 12:38pm UTC](https://discuss.elastic.co/t/how-to-extract-message-from-nested-json/158336/3 "2018-12-25T12:38:22Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
