# How to grok using json filter

**URL:** <https://discuss.elastic.co/t/how-to-grok-using-json-filter/94261>\
**Category:** Logstash\
**Created:** [July 24, 2017, 2:19am UTC](https://discuss.elastic.co/t/how-to-grok-using-json-filter/94261 "2017-07-24T02:19:01Z")\
**Posts on this page:** 1\
**Showing post:** 5

<div class="post-metadata">

**Author:** ![ssasporta](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ssasporta/32/13695_2.png) [@ssasporta](https://discuss.elastic.co/u/ssasporta)\
**Post date:** [July 27, 2017, 1:52am UTC](https://discuss.elastic.co/t/how-to-grok-using-json-filter/94261/5 "2017-07-27T01:52:12Z")

</div>

Hi,

I tried to break it for small pieces but still can't cross this rock.  
I would like that every field of the json will have a unique target line but in the same entry.  
Anyway, nothing is working to me.

`This is my input:`

Timestamp:2017-05-24 09:43:11.733 "requestUrl" : "ecommerce/user/register", "response" : "{"errorCode":"000202","errorMessage":"One or more inputs are invalid","transactionId":"af280fcb-1e5b-4731-a11e-d11b1f286e34"}"

`This is my logstash filter`

```
    if [type] == "json1" {
            mutate {
                    uppercase => ["severity"]
            }
            grok {
                  tag_on_failure => ["_grokparsefailure" , "_jsonparsefailure"]
                  break_on_match => true
                  keep_empty_captures => false
                  match => { "message" => "Timestamp:%{TIMESTAMP_ISO8601:timestamp} %{GREEDYDATA:jsonstring}"
                  }
                  patterns_dir => "/etc/logstash/patterns"
            }
            date {                      
                  match => ["timestamp" , "yyyy-MM-dd HH:mm:ss,SSS", "yyyy-MM-dd HH:mm:ss aa" , "yyyy-MM-dd HH:mm:ss.SSS" , "ISO8601"]
            }
            json {
                  source => "jsonstring"
                  target => "doc"
            }
            mutate {
               add_field => {
                  "requestUrl" => "%{[doc][requestUrl]}"
                  "response" => "%{[doc][response]}"
               }
            }
    }

```

`And this is the output:`

 ![](https://us1.discourse-cdn.com/elastic/original/3X/e/0/e0f84d55ab83a8382139e20c37bf7b808dff7db7.jpg)

**Really need help here!!!**  
Thanks  
Sharon.

---

_[View the full topic](https://discuss.elastic.co/t/how-to-grok-using-json-filter/94261)._
