# How to get variable names in nested JSON format

**URL:** <https://discuss.elastic.co/t/how-to-get-variable-names-in-nested-json-format/272768>\
**Category:** Logstash\
**Created:** [May 12, 2021, 6:55am UTC](https://discuss.elastic.co/t/how-to-get-variable-names-in-nested-json-format/272768 "2021-05-12T06:55:00Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![its-ogawa](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/its-ogawa/32/120829_2.png) [@its-ogawa](https://discuss.elastic.co/u/its-ogawa)\
**Post date:** [May 12, 2021, 6:55am UTC](https://discuss.elastic.co/t/how-to-get-variable-names-in-nested-json-format/272768/1 "2021-05-12T06:55:00Z")

</div>

I am using a JSON plugin to parse logs in JSON format.  
Eventually, the nested variable names are retrieved along with their parent names.  
How can I simply get just the variable names?

target log:  
`... snip ... {... snip ...,"results":{ ... snip ..., "api_code":"51200"}} ... snip ... `

my grok:

```auto
grok{
	"match" => { "message" => " ... snip ... (?<MY_JSON>\{.*\})( %{GREEDYDATA:message})? ... snip ..." }
}
if( [MY_JSON] ) {
  json {
    source => "MY_JSON"
  }
}

```

result:  
`results.api_code : 51200`

expect:  
`api_code : 51200`

---

<div class="post-metadata">

**Author:** ![Cad](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/cad/32/86661_2.png) [@Cad](https://discuss.elastic.co/u/Cad)\
**Post date:** [May 12, 2021, 10:42am UTC](https://discuss.elastic.co/t/how-to-get-variable-names-in-nested-json-format/272768/2 "2021-05-12T10:42:09Z")

</div>

Hi,

I think you have three possibilities.

The first one is to update your grok pattern like this :  
`(?<MY_JSON>\{.*"api_code":"(?<api_code>[0-9]+).*\})`  
With this syntax, the field `MY_JSON` don't change and you create a new field named `api_code` who contain the integer.

The second possibility is to use the rename option with the mutate filter but you have to know in advance the name of each field you need.

```auto
mutate {
    rename =>[
        "[MY_JSON][results][api_core]", "api_core"
    ]
}

```

The last one is to use the ruby filter to browse the JSON.  
`event['MY_JSON']['results'].each...`  
With this one, no necessity to know the field name in advance.

I only try the grok pattern so the others possibilities possibly need some update to work.

Cad.

---

<div class="post-metadata">

**Author:** ![its-ogawa](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/its-ogawa/32/120829_2.png) [@its-ogawa](https://discuss.elastic.co/u/its-ogawa)\
**Post date:** [May 13, 2021, 7:21am UTC](https://discuss.elastic.co/t/how-to-get-variable-names-in-nested-json-format/272768/3 "2021-05-13T07:21:50Z")

</div>

Thanks for answering my question.

Your idea is great!

I tried the grok you tried with Kibana's Grok Debugger and it worked.  
However, I actually tried it in logstash and it didn't work for some reason.

my grok:

```auto
grok{
  "match" => { "message" => " ... snip ... (?<MY_JSON>\{.*\})( %{GREEDYDATA:message})? ... snip ..."
}
if( [MY_JSON] ) {
  #grok {
  # "match" => { "MY_JSON" => ".*"api_code":"(?<api_code>[0-9a-zA-Z]+).*" } # <- not working.
  #}
  json {
    source => "MY_JSON"
  }
  mutate {
    add_field => { "api_code" => "%{[results][api_code]}" }
  }
}

```

Currently, I'm getting the expected results by writing in mutate, but I'm having trouble getting grok to work.

Any advice would be appreciated.  
The comment above is currently the best answer.

---

<div class="post-metadata">

**Author:** ![Cad](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/cad/32/86661_2.png) [@Cad](https://discuss.elastic.co/u/Cad)\
**Post date:** [May 13, 2021, 1:18pm UTC](https://discuss.elastic.co/t/how-to-get-variable-names-in-nested-json-format/272768/4 "2021-05-13T13:18:49Z")

</div>

Hi,

The second pattern not working in the logsatsh file because you need to escape quotes with backslash, my bad.

```auto
"match" => { "MY_JSON" => ".*\"api_code\":\"(?<api_code>[0-9a-zA-Z]+)\".*" }

```

Cad

---

<div class="post-metadata">

**Author:** ![its-ogawa](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/its-ogawa/32/120829_2.png) [@its-ogawa](https://discuss.elastic.co/u/its-ogawa)\
**Post date:** [May 14, 2021, 1:31am UTC](https://discuss.elastic.co/t/how-to-get-variable-names-in-nested-json-format/272768/5 "2021-05-14T01:31:48Z")

</div>

You're right!

I never realized how simple this is.  
Thanks for your sound advice.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 11, 2021, 1:32am UTC](https://discuss.elastic.co/t/how-to-get-variable-names-in-nested-json-format/272768/6 "2021-06-11T01:32:06Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
