# How to get part of a field of parsed json message in logstash

**URL:** <https://discuss.elastic.co/t/how-to-get-part-of-a-field-of-parsed-json-message-in-logstash/109737>\
**Category:** Logstash\
**Created:** [November 30, 2017, 11:14am UTC](https://discuss.elastic.co/t/how-to-get-part-of-a-field-of-parsed-json-message-in-logstash/109737 "2017-11-30T11:14:26Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![elk\_chaser](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/elk_chaser/32/76982_2.png) [@elk\_chaser](https://discuss.elastic.co/u/elk_chaser)\
**Post date:** [November 30, 2017, 11:14am UTC](https://discuss.elastic.co/t/how-to-get-part-of-a-field-of-parsed-json-message-in-logstash/109737/1 "2017-11-30T11:14:26Z")

</div>

I am trying to get just the date part from @report\_timestamp field of a parsed json message in logstash configuration so that I can name the output log file name based on date, say request\_2017\_08\_01.log  
my message looks like this:  
"{"udf": 1, "report\_timestamp": "2017-11-29T17:58:28.967388", "service\_engine": "test", "vcpu\_id": 1, "log\_id": 911550, "client\_ip": "93.20.1.24", "response\_code": 200}"  
my logstash conf looks like this:  
filter {  
json {  
source =\> "message"  
target =\> "parsedjson"  
}  
mutate {  
add\_field =\> {"event\_generated\_on" =\> "%{[parsedjson][report\_timestamp]}"}

}

Expecting date part of the report\_timestamp field value assigned to "event\_generated\_on".

Thanks

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [November 30, 2017, 12:16pm UTC](https://discuss.elastic.co/t/how-to-get-part-of-a-field-of-parsed-json-message-in-logstash/109737/2 "2017-11-30T12:16:04Z")

</div>

Show an example event produced by Logstash. Use a `stdout { codec => rubydebug }` to get a raw dump of it.

---

<div class="post-metadata">

**Author:** ![elk\_chaser](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/elk_chaser/32/76982_2.png) [@elk\_chaser](https://discuss.elastic.co/u/elk_chaser)\
**Post date:** [November 30, 2017, 12:34pm UTC](https://discuss.elastic.co/t/how-to-get-part-of-a-field-of-parsed-json-message-in-logstash/109737/3 "2017-11-30T12:34:17Z")

</div>

Hi Magnus,  
Output is something like this; changed message due to security reasons.  
Thanks  
{

```
        "@timestamp" => 2017-11-29T17:58:29.495Z,
"event_generated_on" => "2017-11-29T17:58:28.967388",
        "parsedjson" => {
               "server_response_code" => 200,
     "server_response_time_last_byte" => 38,
                            "vs_name" => "test_443",
                            "message" => "{\"udf\": 1, \"report_timestamp\": \"2017-11-29T17:58:28.967388\", \"service_engine\": \"test\", \"vcpu_id\": 1, \"log_id\": 911550, \"client_ip\": \"93.20.1.24\", \"response_code\": 200}",
          "server_ssl_session_reused" => 1,
                   "report_timestamp" => "2017-11-29T17:58:28.967388",
           "server_connection_reused" => 1,
                      "request_state" => "HTTP_REQUEST_STATE_SEND_TO_CLIENT",
                         "@timestamp" => "2017-11-29T17:58:29.451Z",
       "headers_received_from_server" => "Date: Wed, 29 Nov 2017 17:58:49 GMT X-Powered-By: Servlet/3.0 Set-Cookie: JSESSIONID_IC_BMIX_T=0000fwSnDd2:ICCommon01; Path=/; Domain=.ibm.com; HttpOnly Expires: Thu, 01 Dec 1994 16:00:00 GMT Cache-Control: no-cache=set-cookie, set-cookie2 Vary: User-Agent,Accept-Encoding Transfer-Encoding: chunked Content-Type: text/html;charset=ISO-8859-1 Content-Language: en-US "
},
          "@version" => "1",
              "host" => "9.207.131.217",
           "message" => "same as above, changed due to security reasons"

```

}

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [November 30, 2017, 12:50pm UTC](https://discuss.elastic.co/t/how-to-get-part-of-a-field-of-parsed-json-message-in-logstash/109737/4 "2017-11-30T12:50:46Z")

</div>

You can use a grok filter to extract the date, but if your end goal is to name your output file e.g. request\_2017\_08\_01.log just use the `%{+YYYY_MM_dd}` notation to get the timestamp from `@timestamp` formatted in yyyy\_mm\_dd format.

[https://www.elastic.co/guide/en/logstash/current/event-dependent-configuration.html#sprintf](https://www.elastic.co/guide/en/logstash/current/event-dependent-configuration.html#sprintf)

---

<div class="post-metadata">

**Author:** ![elk\_chaser](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/elk_chaser/32/76982_2.png) [@elk\_chaser](https://discuss.elastic.co/u/elk_chaser)\
**Post date:** [November 30, 2017, 1:18pm UTC](https://discuss.elastic.co/t/how-to-get-part-of-a-field-of-parsed-json-message-in-logstash/109737/5 "2017-11-30T13:18:44Z")

</div>

Not sure if @timestamp will have values same as that of report\_timestamp (What if I put a past date ) which is a part of json message field. please suggest.

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [December 1, 2017, 6:46am UTC](https://discuss.elastic.co/t/how-to-get-part-of-a-field-of-parsed-json-message-in-logstash/109737/6 "2017-12-01T06:46:08Z")

</div>

Well, I don't know your data so I can't tell if `report_timestamp` should be copied to `@timestamp` but it probably should be if `report_timestamp` is the "main" timestamp of the event.

If not you should, as I said, use a grok filter to extract the date part from `report_timestamp`.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 29, 2017, 6:46am UTC](https://discuss.elastic.co/t/how-to-get-part-of-a-field-of-parsed-json-message-in-logstash/109737/7 "2017-12-29T06:46:09Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
