# How to parse json values from http poller into event fields?

**URL:** <https://discuss.elastic.co/t/how-to-parse-json-values-from-http-poller-into-event-fields/136597>\
**Category:** Logstash\
**Created:** [June 20, 2018, 3:25am UTC](https://discuss.elastic.co/t/how-to-parse-json-values-from-http-poller-into-event-fields/136597 "2018-06-20T03:25:52Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![wailoont](https://avatars.discourse-cdn.com/v4/letter/w/c89c15/32.png) [@wailoont](https://discuss.elastic.co/u/wailoont)\
**Post date:** [June 20, 2018, 3:25am UTC](https://discuss.elastic.co/t/how-to-parse-json-values-from-http-poller-into-event-fields/136597/1 "2018-06-20T03:25:52Z")

</div>

I am using logstash http poller plugin to call an API to retrieve information. Below is my logstash conf.

```
input {
  http_poller {
    urls => {
      test2 => {
        method => get
        url => "http://localhost:9000/api/measures/component
        headers => {
          Accept => "application/json"
        }
     }
    }
    request_timeout => 60
    # Supports "cron", "every", "at" and "in" schedules by rufus scheduler
    schedule => { cron => "* * * * * UTC"}
    codec => "json"
    # A hash of request metadata info (timing, response headers, etc.) will be sent here
    metadata_target => "http_poller_metadata"
  }
}

output {
  elasticsearch { hosts => ["localhost:9200"] }
  stdout { codec => rubydebug }
}

```

The rubydebug output is below:

```
{
"measures" => [
            [0] {
                "periods" => [
                    [0] {
                        "index" => 1,
                        "value" => "-4"
                    }
                ],
                  "value" => "24",
                 "metric" => "ncloc"
            }
        ]
}

```

How do i parse the values in the json to key/value fields in the elasticsearch fields?  
for example.

measures.value = 24  
measures.metric = ncloc

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [June 20, 2018, 6:23am UTC](https://discuss.elastic.co/t/how-to-parse-json-values-from-http-poller-into-event-fields/136597/2 "2018-06-20T06:23:19Z")

</div>

The JSON has already been parsed into discrete fields. You only need to move/rename the `[measures][0][value]` and `[measures][0][metric]` fields to the desired location. Make sure you read [https://www.elastic.co/guide/en/logstash/current/event-dependent-configuration.html#logstash-config-field-references](https://www.elastic.co/guide/en/logstash/current/event-dependent-configuration.html#logstash-config-field-references) to understand the difference between `measures.value` and `[measures][value]`.

---

<div class="post-metadata">

**Author:** ![wailoont](https://avatars.discourse-cdn.com/v4/letter/w/c89c15/32.png) [@wailoont](https://discuss.elastic.co/u/wailoont)\
**Post date:** [June 21, 2018, 4:30am UTC](https://discuss.elastic.co/t/how-to-parse-json-values-from-http-poller-into-event-fields/136597/3 "2018-06-21T04:30:00Z")

</div>

Thank you magnus.

I managed to do it after added a filter function.

Final configuration is as below.

```
        input {
          http_poller {
            urls => {
              test2 => {
                method => get
                url => "http://localhost:9000/api/measures/component
                headers => {
                  Accept => "application/json"
                }
             }
            }
            request_timeout => 60
            # Supports "cron", "every", "at" and "in" schedules by rufus scheduler
            schedule => { cron => "* * * * * UTC"}
            codec => "json"
            # A hash of request metadata info (timing, response headers, etc.) will be sent here
            metadata_target => "http_poller_metadata"
          }
        }

        filter {
        json{
            source => "message"
        }
    	mutate { 
    	add_field => { "metric" => "%{[component][measures][0][metric]}" } 
    	add_field => { "value" => "%{[component][measures][0][value]}" } 
    	}
     }

        output {
          elasticsearch { hosts => ["localhost:9200"] }
          stdout { codec => rubydebug }
        }
```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 19, 2018, 4:30am UTC](https://discuss.elastic.co/t/how-to-parse-json-values-from-http-poller-into-event-fields/136597/4 "2018-07-19T04:30:06Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
