# How to parse array of objects into separate field

**URL:** <https://discuss.elastic.co/t/how-to-parse-array-of-objects-into-separate-field/340692>\
**Category:** Logstash\
**Created:** [August 12, 2023, 7:18pm UTC](https://discuss.elastic.co/t/how-to-parse-array-of-objects-into-separate-field/340692 "2023-08-12T19:18:55Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Subhashini](https://avatars.discourse-cdn.com/v4/letter/s/da6949/32.png) [@Subhashini](https://discuss.elastic.co/u/Subhashini)\
**Post date:** [August 12, 2023, 7:18pm UTC](https://discuss.elastic.co/t/how-to-parse-array-of-objects-into-separate-field/340692/1 "2023-08-12T19:18:55Z")

</div>

I have some log look like

########2023-08-12#########

{‘crewrosters’: [{ ‘crew\_roster’ : ‘det1’, 'empno': 1} , {‘crew\_roster’ : ‘det2’, 'empno': 2} , {‘crew\_roster’ : ‘det3’, 'empno': 3}] }

I need to parse the data to get the value of each 'empno' and 'crew\_roster' fields separately.  
Please suggest.

Thanks in advance!

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [August 13, 2023, 12:51am UTC](https://discuss.elastic.co/t/how-to-parse-array-of-objects-into-separate-field/340692/2 "2023-08-13T00:51:43Z")

</div>

I would suggest

```
    mutate { gsub => ["message", "‘", '"', "message", "’", '"', "message", "'", '"'] }
    json { source => "message" remove_field => ["message"] }
    split { field => "crewrosters" }

```

which results in three events like

```
{
 "@timestamp" => 2023-08-13T00:50:45.486366051Z,
   "@version" => "1",
"crewrosters" => {
    "crew_roster" => "det3",
          "empno" => 3
    }
}

```

---

<div class="post-metadata">

**Author:** ![Subhashini](https://avatars.discourse-cdn.com/v4/letter/s/da6949/32.png) [@Subhashini](https://discuss.elastic.co/u/Subhashini)\
**Post date:** [August 15, 2023, 8:20am UTC](https://discuss.elastic.co/t/how-to-parse-array-of-objects-into-separate-field/340692/3 "2023-08-15T08:20:55Z")

</div>

Hi Badger,  
Thanks for your reply. I tried the same.  
I could see that you have used the conversion of single quote to double quote thrice. Because number of events in my data is dynamic, it is not always three.

There is a date\_time field in my data. Few date\_time fields are empty here. When I replace from '(single quote) to "(double quote) the date\_time field is not getting converted. With the below error message  
"Can not be converted from type [date] to [text]"

Thank you!

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [August 15, 2023, 4:01pm UTC](https://discuss.elastic.co/t/how-to-parse-array-of-objects-into-separate-field/340692/4 "2023-08-15T16:01:00Z")

</div>

> [@Subhashini](#):
>
> I could see that you have used the conversion of single quote to double quote thrice. Because number of events in my data is dynamic, it is not always three.

I am not converting it three times, I am globally converting three different characters: left and right curly single quote, plus straight single quote.

> [@Subhashini](#):
>
> "Can not be converted from type [date] to [text]"

Is that a mapping exception from elasticsearch? If your field is empty you will need to modify it in logstash to either delete the field or set a default date.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 12, 2023, 4:01pm UTC](https://discuss.elastic.co/t/how-to-parse-array-of-objects-into-separate-field/340692/5 "2023-09-12T16:01:09Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
