# How to make filter when using json format file

**URL:** <https://discuss.elastic.co/t/how-to-make-filter-when-using-json-format-file/35680>\
**Category:** Logstash\
**Created:** [November 26, 2015, 2:32pm UTC](https://discuss.elastic.co/t/how-to-make-filter-when-using-json-format-file/35680 "2015-11-26T14:32:31Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Young\_Heon\_Kim](https://avatars.discourse-cdn.com/v4/letter/y/e19b73/32.png) [@Young\_Heon\_Kim](https://discuss.elastic.co/u/Young_Heon_Kim)\
**Post date:** [November 26, 2015, 2:32pm UTC](https://discuss.elastic.co/t/how-to-make-filter-when-using-json-format-file/35680/1 "2015-11-26T14:32:31Z")

</div>

Hi everyone.

I would like to parse json format log file which logged on Percona audit plugin.  
Actually format of log file is following

* * *

## Nov 25 23:25:18 serverHostName percona-audit: {"audit\_record":{"name":"Query", "record":"01T00:00:00", "timestamp":"2015-11-26T07:25:18 UTC", "command\_class":"select", "connection\_id":"3", "status":0,"sqltext":"select version()","user":"root[root] @ localhost []","host":"localhost","os\_user":"","ip":""}}

How can I make filter file ?

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [November 26, 2015, 9:30pm UTC](https://discuss.elastic.co/t/how-to-make-filter-when-using-json-format-file/35680/2 "2015-11-26T21:30:09Z")

</div>

Use a grok filter to extract the timestamp, hostname, whatever percona-audit is, and finally the JSON payload into separate fields. The log format looks very similar to syslog so it should be easy to find something that's very close to what you need (and [http://grokconstructor.appspot.com/](http://grokconstructor.appspot.com/) can also be helpful). Then use a json filter to parse the field with the JSON payload.

---

<div class="post-metadata">

**Author:** ![Young\_Heon\_Kim](https://avatars.discourse-cdn.com/v4/letter/y/e19b73/32.png) [@Young\_Heon\_Kim](https://discuss.elastic.co/u/Young_Heon_Kim)\
**Post date:** [November 27, 2015, 2:25am UTC](https://discuss.elastic.co/t/how-to-make-filter-when-using-json-format-file/35680/3 "2015-11-27T02:25:03Z")

</div>

Thank you for your answer.  
But, actually I use logstash at first time, so I don't have any knowledge.  
I try to add\_field of json module, but I can't parse.

Could you show me some sample or config file ?

---

<div class="post-metadata">

**Author:** ![Young\_Heon\_Kim](https://avatars.discourse-cdn.com/v4/letter/y/e19b73/32.png) [@Young\_Heon\_Kim](https://discuss.elastic.co/u/Young_Heon_Kim)\
**Post date:** [November 27, 2015, 5:18am UTC](https://discuss.elastic.co/t/how-to-make-filter-when-using-json-format-file/35680/4 "2015-11-27T05:18:59Z")

</div>

Hi @magnusbaeck  
I can parse this log.

The site which you talked is very helpful for me.  
Thanks a lot.

I share config file for percona audit log.

* * *

input { stdin { } }  
output { stdout { codec =\> "rubydebug" } }  
filter {  
grok {  
match =\> { "message" =\> "%{SYSLOGTIMESTAMP:sys\_timestamp}%{SPACE}%{HOSTNAME:host\_name}%{SPACE} percona-audit: %{GREEDYDATA:json\_data}"}  
}  
json {  
source =\> "json\_data"  
}  
}

* * *

Result of parsing

* * *

# echo 'Nov 25 23:25:18 hostA percona-audit: {"audit\_record":{"name":"Query","record":"35\_1970-01-01T00:00:00","timestamp":"2015-11-26T07:25:18 UTC","command\_class":"select","connection\_id":"3","status":0,"sqltext":"select version()","user":"root[root] @ localhost []","host":"localhost","os\_user":"","ip":""}}' | /opt/logstash/bin/logstash -f test.config

Logstash startup completed  
{  
"message" =\> "Nov 25 23:25:18 hostA percona-audit: {"audit\_record":{"name":"Query","record":"35\_1970-01-01T00:00:00","timestamp":"2015-11-26T07:25:18 UTC","command\_class":"select","connection\_id":"3","status":0,"sqltext":"select version()","user":"root[root] @ localhost []","host":"localhost","os\_user":"","ip":""}}",  
"@version" =\> "1",  
"@timestamp" =\> "2015-11-27T04:04:16.994Z",  
"host" =\> "hostB",  
"sys\_timestamp" =\> "Nov 25 23:25:18",  
"host\_name" =\> "hostA",  
"json\_data" =\> "{"audit\_record":{"name":"Query","record":"35\_1970-01-01T00:00:00","timestamp":"2015-11-26T07:25:18 UTC","command\_class":"select","connection\_id":"3","status":0,"sqltext":"select version()","user":"root[root] @ localhost []","host":"localhost","os\_user":"","ip":""}}",  
"audit\_record" =\> {  
"name" =\> "Query",  
"record" =\> "35\_1970-01-01T00:00:00",  
"timestamp" =\> "2015-11-26T07:25:18 UTC",  
"command\_class" =\> "select",  
"connection\_id" =\> "3",  
"status" =\> 0,  
"sqltext" =\> "select version()",  
"user" =\> "root[root] @ localhost []",  
"host" =\> "localhost",  
"os\_user" =\> "",  
"ip" =\> ""  
}  
}  
Logstash shutdown completed

* * *

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 5:21am UTC](https://discuss.elastic.co/t/how-to-make-filter-when-using-json-format-file/35680/5 "2017-07-06T05:21:04Z")

</div>


