# How to fetch all the fields in decode\_json\_fields instead of specifying all the fields inside

**URL:** <https://discuss.elastic.co/t/how-to-fetch-all-the-fields-in-decode-json-fields-instead-of-specifying-all-the-fields-inside/213447>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [December 31, 2019, 12:12pm UTC](https://discuss.elastic.co/t/how-to-fetch-all-the-fields-in-decode-json-fields-instead-of-specifying-all-the-fields-inside/213447 "2019-12-31T12:12:52Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Viswanath\_Lekshman](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/viswanath_lekshman/32/60139_2.png) [@Viswanath\_Lekshman](https://discuss.elastic.co/u/Viswanath_Lekshman)\
**Post date:** [December 31, 2019, 12:12pm UTC](https://discuss.elastic.co/t/how-to-fetch-all-the-fields-in-decode-json-fields-instead-of-specifying-all-the-fields-inside/213447/1 "2019-12-31T12:12:52Z")

</div>

When i'm using decode\_json\_fields in Filebeat. I'm unable to specify all fields in a json

Below is my sample json

{"message":{"name": "Viswanath","cancel":1,"description":"Hey"},"level":"info"}

When i use the below configuration

processors:

- decode\_json\_fields:  
fields: [message]  
process\_array: false  
max\_depth: 1  
target: ""  
overwrite\_keys: false  
add\_error\_key: true

json value of "message" appears as string in elasticsearch index. (Logstash is not filtering any data, bypassing for now)

Is there any way to pass the data inside "message" key as json without name of the fields individually

---

<div class="post-metadata">

**Author:** ![kvch](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kvch/32/72058_2.png) [@kvch](https://discuss.elastic.co/u/kvch)\
**Post date:** [January 3, 2020, 7:06pm UTC](https://discuss.elastic.co/t/how-to-fetch-all-the-fields-in-decode-json-fields-instead-of-specifying-all-the-fields-inside/213447/2 "2020-01-03T19:06:30Z")

</div>

Could you please share you full configuration formatted using `</>`?

---

<div class="post-metadata">

**Author:** ![kumarabhi](https://avatars.discourse-cdn.com/v4/letter/k/6a8cbe/32.png) [@kumarabhi](https://discuss.elastic.co/u/kumarabhi)\
**Post date:** [January 10, 2020, 11:14pm UTC](https://discuss.elastic.co/t/how-to-fetch-all-the-fields-in-decode-json-fields-instead-of-specifying-all-the-fields-inside/213447/3 "2020-01-10T23:14:09Z")

</div>

Please remove max\_depth: 1 and try

---

<div class="post-metadata">

**Author:** ![Viswanath\_Lekshman](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/viswanath_lekshman/32/60139_2.png) [@Viswanath\_Lekshman](https://discuss.elastic.co/u/Viswanath_Lekshman)\
**Post date:** [January 14, 2020, 8:05am UTC](https://discuss.elastic.co/t/how-to-fetch-all-the-fields-in-decode-json-fields-instead-of-specifying-all-the-fields-inside/213447/4 "2020-01-14T08:05:28Z")

</div>

Found the issue. It is a bug associated with reserved word "message". If you use any other word the above config will work. Thanks for the help all...

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 11, 2020, 8:05am UTC](https://discuss.elastic.co/t/how-to-fetch-all-the-fields-in-decode-json-fields-instead-of-specifying-all-the-fields-inside/213447/5 "2020-02-11T08:05:32Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
