# How to filter single line json?

**URL:** <https://discuss.elastic.co/t/how-to-filter-single-line-json/296242>\
**Category:** Logstash\
**Created:** [February 4, 2022, 12:16am UTC](https://discuss.elastic.co/t/how-to-filter-single-line-json/296242 "2022-02-04T00:16:51Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![jeromeat](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jeromeat/32/87195_2.png) [@jeromeat](https://discuss.elastic.co/u/jeromeat)\
**Post date:** [February 4, 2022, 12:16am UTC](https://discuss.elastic.co/t/how-to-filter-single-line-json/296242/1 "2022-02-04T00:16:51Z")

</div>

I am trying to figure out how to filter this single line of json data I have been able to pull via http\_poller. I've obfuscated the data, but this is the format it's coming in as. I've never utilized a filter before, so I'm not sure how to go about this. Any help would be appreciated.

````auto
{"products":[{"test_level":"Green","title":"Testing Title one","executive_summary":"Test Executive summary","updated_at":"2018-10-15T17:50:28.000Z","threat_level":0,"serial":"Test-2020-01","test_count":0,"tags":[{"text":"Test Distribution","tag_type":"Testing"},{"text":"United States","tag_type":"GeographicLocation"},{"text":"Testing Location","tag_type":"Industry"}],"release_date":"2020-04-21T04:00:00.000Z","type":"Report Special","report_link":"https://portal.website.test/api/v1"},{"test_level":"Green","title":"Testing Title one","executive_summary":"Test Executive summary","updated_at":"2018-10-15T17:50:28.000Z","threat_level":0,"serial":"Test-2020-01","test_count":0,"tags":[{"text":"Test Distribution","tag_type":"Testing"},{"text":"United States","tag_type":"GeographicLocation"},{"text":"Testing Location","tag_type":"Industry"}],"release_date":"2020-04-21T04:00:00.000Z","type":"Report Special","report_link":"https://portal.website.test/api/v1"},{"test_level":"Green","title":"Testing Title one","executive_summary":"Test Executive summary","updated_at":"2018-10-15T17:50:28.000Z","threat_level":0,"serial":"Test-2020-01","test_count":0,"tags":[{"text":"Test Distribution","tag_type":"Testing"},{"text":"United States","tag_type":"GeographicLocation"},{"text":"Testing Location","tag_type":"Industry"}],"release_date":"2020-04-21T04:00:00.000Z","type":"Report Special","report_link":"https://portal.website.test/api/v1"},{"test_level":"Green","title":"Testing Title one","executive_summary":"Test Executive summary","updated_at":"2018-10-15T17:50:28.000Z","threat_level":0,"serial":"Test-2020-01","test_count":0,"tags":[{"text":"Test Distribution","tag_type":"Testing"},{"text":"United States","tag_type":"GeographicLocation"},{"text":"Testing Location","tag_type":"Industry"}],"release_date":"2020-04-21T04:00:00.000Z","type":"Report Special","report_link":"https://portal.website.test/api/v1"},```
````

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [February 4, 2022, 1:35am UTC](https://discuss.elastic.co/t/how-to-filter-single-line-json/296242/2 "2022-02-04T01:35:47Z")

</div>

Aren't you using a json codec on your http\_poller input?

---

<div class="post-metadata">

**Author:** ![jeromeat](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jeromeat/32/87195_2.png) [@jeromeat](https://discuss.elastic.co/u/jeromeat)\
**Post date:** [February 4, 2022, 1:57am UTC](https://discuss.elastic.co/t/how-to-filter-single-line-json/296242/3 "2022-02-04T01:57:02Z")

</div>

Yes I am. However, it’s parsing the one line as one line.

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [February 4, 2022, 2:42am UTC](https://discuss.elastic.co/t/how-to-filter-single-line-json/296242/4 "2022-02-04T02:42:11Z")

</div>

Use a [json](https://www.elastic.co/guide/en/logstash/current/plugins-filters-json.html) filter. You may need to use mutate+gsub to clean up the end of the [message] field before doing so.

---

<div class="post-metadata">

**Author:** ![jeromeat](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jeromeat/32/87195_2.png) [@jeromeat](https://discuss.elastic.co/u/jeromeat)\
**Post date:** [February 8, 2022, 5:21pm UTC](https://discuss.elastic.co/t/how-to-filter-single-line-json/296242/5 "2022-02-08T17:21:28Z")

</div>

I fixed it using the following:

````auto
filter {
  split { field => "[products]" }
  split { field => "[products][code_level]" } 
   
}```
````

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 8, 2022, 5:22pm UTC](https://discuss.elastic.co/t/how-to-filter-single-line-json/296242/6 "2022-03-08T17:22:26Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
