# How to parse mix json logs

**URL:** <https://discuss.elastic.co/t/how-to-parse-mix-json-logs/167594>\
**Category:** Logstash\
**Created:** [February 8, 2019, 9:14am UTC](https://discuss.elastic.co/t/how-to-parse-mix-json-logs/167594 "2019-02-08T09:14:34Z")\
**Posts on this page:** 20\
**Page:** 1

<div class="post-metadata">

**Author:** ![amolp](https://avatars.discourse-cdn.com/v4/letter/a/7993a0/32.png) [@amolp](https://discuss.elastic.co/u/amolp)\
**Post date:** [February 8, 2019, 9:14am UTC](https://discuss.elastic.co/t/how-to-parse-mix-json-logs/167594/1 "2019-02-08T09:14:34Z")

</div>

hi,  
i am very new to elk.so i do not know how to parse the mixed json logs here is sample log that i want parse,i getting these logs from filebeat.

2019-02-03 23:51:54,263 | {" MACID":"00009934","ID":"1","SS":"26","FW":"V5.1.14","TSRC":"R", "STATUS":"SOFT RESET","SN":"25925","PCK":{"M26":"AQPAQF5GUJAERk93BUZPwnhGTy0eRrRuhUazKspGtLcXOVFJUjmdqII4+8z3OhLFrLcnzPe5kgAAAAC3F7lRqIK4+6iCOPsAAD+AAAA/gAAAP4AAAD+AAAAAAJumu0QAAAAAm6a7RBJvuwMSb7qDEm86gxJvuwMSbzsDEm87gxJvOoMSbzuDsTBC8PefQu5aAELwWh1CSJqZOnwAAEIQCj0/V7hSP14KPT9XAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAx3QBAxDPfEuB5/9LhswgSoH0AEgcXOgBAxDXBwAOmVUAAr1iAA4ZpAAA2h4BAwwgAAAABAAAAHW+Ons7l36HXFduJw=="},"RTC":"19/02/03,23:51:35"}

use cases  
1.i want to calculate total number logs based on particular field from logs  
for example =\>  
I want find out total number of logs that matches with MACID":"00009934"

2.how to filter the logs based on one the field.  
let say i want to search the logs for "STATUS":"SOFT RESET" so it shoud return me all the logs where it found "STATUS":"SOFT RESET"

any one have any clue please help me  
Thank you

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [February 8, 2019, 12:22pm UTC](https://discuss.elastic.co/t/how-to-parse-mix-json-logs/167594/2 "2019-02-08T12:22:57Z")

</div>

You can parse a message like that using

```
    dissect { mapping => { "message" => "%{ts} %{+ts} | %{restOfLine}" } }
    json { source => "restOfLine" }
    date { match => ["ts", "ISO8601"] }

```

How to query the number of documents that contain a given field is an elasticsearch (or kibana) question, not a logstash question.

---

<div class="post-metadata">

**Author:** ![amolp](https://avatars.discourse-cdn.com/v4/letter/a/7993a0/32.png) [@amolp](https://discuss.elastic.co/u/amolp)\
**Post date:** [February 12, 2019, 6:37am UTC](https://discuss.elastic.co/t/how-to-parse-mix-json-logs/167594/3 "2019-02-12T06:37:16Z")

</div>

Thanks Badger for four valuable reply.  
How to add field from JSON here so that i can filter records in kibana based on that field.I have one doubt here why don't we use grok here.and when to use grok and when to use dissect.it would be appreciable.

Thank you

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [February 12, 2019, 12:38pm UTC](https://discuss.elastic.co/t/how-to-parse-mix-json-logs/167594/4 "2019-02-12T12:38:12Z")

</div>

The filter I showed will result in an event that looks like this once you mutate+remove fields like ts, restOfLine, message, etc.

{  
"STATUS" =\> "SOFT RESET",  
"@timestamp" =\> 2019-02-04T04:51:54.263Z,  
"RTC" =\> "19/02/03,23:51:35",  
"PCK" =\> {  
"M26" =\> "AQPAQF5GUJAERk93BUZPwnhGTy0eRrRuhUazKspGtLcXOVFJUjmdqII4+8z3OhLFrLcnzPe5kgAAAAC3F7lRqIK4+6iCOPsAAD+AAAA/gAAAP4AAAD+AAAAAAJumu0QAAAAAm6a7RBJvuwMSb7qDEm86gxJvuwMSbzsDEm87gxJvOoMSbzuDsTBC8PefQu5aAELwWh1CSJqZOnwAAEIQCj0/V7hSP14KPT9XAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAx3QBAxDPfEuB5/9LhswgSoH0AEgcXOgBAxDXBwAOmVUAAr1iAA4ZpAAA2h4BAwwgAAAABAAAAHW+Ons7l36HXFduJw=="  
},  
" MACID" =\> "00009934",  
"FW" =\> "V5.1.14",  
"SS" =\> "26",  
"SN" =\> "25925",  
"ID" =\> "1",  
"TSRC" =\> "R"  
}

If you ingest that into elasticsearch you will be able to search on a field like STATUS. Note that " MACID" has a leading space in the field name, so you may want to mutate+rename that.

When to use grok and when to use dissect is a matter of taste. I prefer to use dissect on well structured parts of logs, but grok can do the same job.

---

<div class="post-metadata">

**Author:** ![amolp](https://avatars.discourse-cdn.com/v4/letter/a/7993a0/32.png) [@amolp](https://discuss.elastic.co/u/amolp)\
**Post date:** [February 12, 2019, 1:33pm UTC](https://discuss.elastic.co/t/how-to-parse-mix-json-logs/167594/5 "2019-02-12T13:33:26Z")

</div>

thanks for reply,here is my configuration file its not working

#INPUT

input {  
beats {  
port =\> 5044  
}  
}

#FILTER

filter {  
if [type] == "log" {

dissect { mapping =\> { "message" =\> "%{ts} %{+ts} | %{restOfLine}" } }

```
json { source => "restOfLine"
   target => "message"	
   add_field => {
  "mac_addr" => "%{MACID}"
}
   }

```

#this is another way that i tried still not working  
mutate {  
add\_field =\> ["status", "i want to add value from json filed here"]  
}

```
date { match => ["ts", "ISO8601"] }

```

}  
}

#OUTPUT

output {  
elasticsearch {  
hosts =\> ["localhost:9200"]  
index =\> "todayslogs-%{+YYYY.MM.dd}"  
}  
stdout {  
codec =\> rubydebug  
}  
}

i am really very confused with flow of execution.please help me.

thank you

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [February 12, 2019, 1:43pm UTC](https://discuss.elastic.co/t/how-to-parse-mix-json-logs/167594/6 "2019-02-12T13:43:38Z")

</div>

You are making changes to the solutions I am suggesting that do not make a lot of sense. Start off with

```
    dissect { mapping => { "message" => "%{ts} %{+ts} | %{restOfLine}" } }
    json { source => "restOfLine" }
    mutate {
        remove_field => ["message", "restOfLine"]
        rename => { " MACID" => "MACID" }
    }
    date { match => ["ts", "ISO8601"] }

```

If you change the json filter to include the option 'target =\> "message" then all of the fields are output inside an object called message. I don't see how that can possibly help. You need to approach this systematically. Don't even bother putting the data into elasticsearch at this point. Just look at the output you get from the rubydebug codec on stdout. When you make a change to the filter, see if the the change to the output is an improvement. If it is not, then undo the change.

---

<div class="post-metadata">

**Author:** ![amolp](https://avatars.discourse-cdn.com/v4/letter/a/7993a0/32.png) [@amolp](https://discuss.elastic.co/u/amolp)\
**Post date:** [February 12, 2019, 7:18pm UTC](https://discuss.elastic.co/t/how-to-parse-mix-json-logs/167594/7 "2019-02-12T19:18:07Z")

</div>

I followed the same script provided by you still getting same output as i was getting previously below is sample output that i am getting :

"\_index": "todayslogs-2019.02.12",  
"\_type": "doc",  
"\_id": "4nQD42gBCBNxC0o5rrkh",  
"\_version": 1,  
"\_score": null,  
"\_source": {  
"@version": "1",  
"@timestamp": "2019-02-12T18:41:34.668Z",  
"source": "/var/log/test\_logs.log",  
"input": {  
"type": "log"  
},  
"offset": 54500584,  
"tags": [  
"beats\_input\_codec\_plain\_applied"  
],  
"beat": {  
"hostname": "amolpc-HP-Laptop-14-bs0xx",  
"version": "6.6.0",  
"name": "amolpc-HP-Laptop-14-bs0xx"  
},  
"host": {  
"architecture": "x86\_64",  
"containerized": false,  
"os": {  
"platform": "ubuntu",  
"version": "16.04.2 LTS (Xenial Xerus)",  
"family": "debian",  
"name": "Ubuntu",  
"codename": "xenial"  
},  
"id": "810d928d8f414904937f2c900154e8ee",  
"name": "amolpc-HP-Laptop-14-bs0xx"  
},  
"message": "2019-02-03 23:51:54,263 | {"MACID":"0418003f","ID":"1","SS":"26","FW":"V5.1.14","TSRC":"R","SN":"25925","PCK":{"M26":"AQPAQF5GUJAERk93BUZPwnhGTy0eRrRuhUazKspGtLcXOVFJUjmdqII4+8z3OhLFrLcnzPe5kgAAAAC3F7lRqIK4+6iCOPsAAD+AAAA/gAAAP4AAAD+AAAAAAJumu0QAAAAAm6a7RBJvuwMSb7qDEm86gxJvuwMSbzsDEm87gxJvOoMSbzuDsTBC8PefQu5aAELwWh1CSJqZOnwAAEIQCj0/V7hSP14KPT9XAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAx3QBAxDPfEuB5/9LhswgSoH0AEgcXOgBAxDXBwAOmVUAAr1iAA4ZpAAA2h4BAwwgAAAABAAAAHW+Ons7l36HXFduJw=="},"RTC":"19/02/03,23:51:35"}",  
"prospector": {  
"type": "log"  
},  
"log": {  
"file": {  
"path": "/var/log/test\_logs.log"  
}  
}  
},  
"fields": {  
"@timestamp": [  
"2019-02-12T18:41:34.668Z"  
]  
},  
"sort": [  
1549996894668  
]  
}

there is no change in output.if i remove the filter part from configuration still will get the same result.my only intension behind this is to map the fields from json so that i can use those fields in kibana for filtering the data.

Thank you

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [February 12, 2019, 7:41pm UTC](https://discuss.elastic.co/t/how-to-parse-mix-json-logs/167594/8 "2019-02-12T19:41:52Z")

</div>

> [@amolp](#):
>
> "\_type": "doc",  
> "input": {  
> "type": "log"  
> },  
> "prospector": {  
> "type": "log"  
> }

You made the filter conditional upon '[type] == "log"'

You do not have a field called type. You have \_type, [input][type], or [prospector][type]

---

<div class="post-metadata">

**Author:** ![amolp](https://avatars.discourse-cdn.com/v4/letter/a/7993a0/32.png) [@amolp](https://discuss.elastic.co/u/amolp)\
**Post date:** [February 13, 2019, 2:56pm UTC](https://discuss.elastic.co/t/how-to-parse-mix-json-logs/167594/9 "2019-02-13T14:56:45Z")

</div>

now i have removed if condition from configuration see below

filter {  
dissect { mapping =\> { "message" =\> "%{ts} %{+ts} | %{restOfLine}" } }  
json { source =\> "restOfLine" }  
mutate {  
#add\_field =\> ["macid" : "dynamic field from json"] it should visible in kibana for filtering the #data  
remove\_field =\> ["message", "restOfLine"]  
rename =\> { " MACID" =\> "MACID" }  
}  
date { match =\> ["ts", "ISO8601"] }  
}

and i have written output to the file and its showing below output

{"FW":"V5.1.14","prospector":{"type":"log"},"RTC":"19/02/03,23:51:35","input":{"type":"log"},"PCK":{"M26":"AQPAQF5GUJAERk93BUZPwnhGTy0eRrRuhUazKspGtLcXOVFJUjmdqII4+8z3OhLFrLcnzPe5kgAAAAC3F7lRqIK4+6iCOPsAAD+AAAA/gAAAP4AAAD+AAAAAAJumu0QAAAAAm6a7RBJvuwMSb7qDEm86gxJvuwMSbzsDEm87gxJvOoMSbzuDsTBC8PefQu5aAELwWh1CSJqZOnwAAEIQCj0/V7hSP14KPT9XAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAx3QBAxDPfEuB5/9LhswgSoH0AEgcXOgBAxDXBwAOmVUAAr1iAA4ZpAAA2h4BAwwgAAAABAAAAHW+Ons7l36HXFduJw=="},"@version":"1","MACID":"0418003f","host":{"containerized":false,"architecture":"x86\_64","name":"amolpc-HP-Laptop-14-bs0xx","os":{"codename":"xenial","platform":"ubuntu","name":"Ubuntu","version":"16.04.2 LTS (Xenial Xerus)","family":"debian"},"id":"810d928d8f414904937f2c900154e8ee"},"beat":{"name":"amolpc-HP-Laptop-14-bs0xx","version":"6.6.0","hostname":"amolpc-HP-Laptop-14-bs0xx"},"TSRC":"R","@timestamp":"2019-02-03T18:21:54.263Z","offset":55569056,"SN":"25925","macid":"MACID","source":"/var/log/test\_logs.log","ID":"1","SS":"26","log":{"file":{"path":"/var/log/test\_logs.log"}},"ts":"2019-02-03 23:51:54,263","tags":["beats\_input\_codec\_plain\_applied"]}

and then i have pointed output to elastic search and its able to create index and data also available there but its not showing in kibana.  
even if i get the data in kibana its not useful for me because what i want is all log data along with fields extracted from json like SN,MACID so that filter the records in kibana based on extracted fields.

all log data should remain in message field,and at same time i need exracted fields from json like SN,MACID to filter the data in kibana,so that i create dashboard,chart something like this.

please help me to get this thing done,will really appreciate your support.

note : there is no need of removing space from MACID because that was mistake made by me while copy/paste

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [February 13, 2019, 3:01pm UTC](https://discuss.elastic.co/t/how-to-parse-mix-json-logs/167594/10 "2019-02-13T15:01:10Z")

</div>

So the data is in elasticsearch but you cannot see it in Kibana? Did you update the index pattern? Did you set the time picker to include 2019-02-03T18:21:54.263Z? (Use something like Last Month.)

---

<div class="post-metadata">

**Author:** ![amolp](https://avatars.discourse-cdn.com/v4/letter/a/7993a0/32.png) [@amolp](https://discuss.elastic.co/u/amolp)\
**Post date:** [February 13, 2019, 3:05pm UTC](https://discuss.elastic.co/t/how-to-parse-mix-json-logs/167594/11 "2019-02-13T15:05:10Z")

</div>

i have deleted previous index from elasticsearch and created new one still problem is same  
when i remove the code from filter provided by you its able send the logs in elasticsearch and its showing logs in kibana too.  
like this  
filter {}

---

<div class="post-metadata">

**Author:** ![amolp](https://avatars.discourse-cdn.com/v4/letter/a/7993a0/32.png) [@amolp](https://discuss.elastic.co/u/amolp)\
**Post date:** [February 13, 2019, 3:07pm UTC](https://discuss.elastic.co/t/how-to-parse-mix-json-logs/167594/12 "2019-02-13T15:07:57Z")

</div>

how can i see extracted fileds from json in kibana for filtering but original log data should be available in message fileld,this is my actual required.

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [February 13, 2019, 3:11pm UTC](https://discuss.elastic.co/t/how-to-parse-mix-json-logs/167594/13 "2019-02-13T15:11:53Z")

</div>

Comment out the mutate filter, leaving the dissect and json filters. What do you then get when you use

```
output { stdout { codec => rubydebug } }
```

---

<div class="post-metadata">

**Author:** ![amolp](https://avatars.discourse-cdn.com/v4/letter/a/7993a0/32.png) [@amolp](https://discuss.elastic.co/u/amolp)\
**Post date:** [February 13, 2019, 3:14pm UTC](https://discuss.elastic.co/t/how-to-parse-mix-json-logs/167594/14 "2019-02-13T15:14:00Z")

</div>

where do i see the output of this ?  
i tried with file,i i have written output the file

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [February 13, 2019, 3:26pm UTC](https://discuss.elastic.co/t/how-to-parse-mix-json-logs/167594/15 "2019-02-13T15:26:35Z")

</div>

You would see it on stdout. But no matter, we can see from that entry you wrote to the file that the individual fields of the message were parsed out. For example in

"TSRC":"R","@timestamp":"2019-02-03T18:21:54.263Z","offset":55569056,"SN":"25925"

both TSRC and SN are fields that were in the log message and are now fields on the event. So, once again... Did you update the index pattern in Kibana? Did you set the time picker to include 2019-02-03T18:21:54.263Z?

---

<div class="post-metadata">

**Author:** ![amolp](https://avatars.discourse-cdn.com/v4/letter/a/7993a0/32.png) [@amolp](https://discuss.elastic.co/u/amolp)\
**Post date:** [February 13, 2019, 3:30pm UTC](https://discuss.elastic.co/t/how-to-parse-mix-json-logs/167594/16 "2019-02-13T15:30:27Z")

</div>

> [@Badger](#):
>
> 2019-02-03T18:21:54.263Z

 ![pick](https://us1.discourse-cdn.com/elastic/original/3X/7/8/78271eaeffc069fa6fe3876fcbaaa3f338dd365e.png)

---

<div class="post-metadata">

**Author:** ![amolp](https://avatars.discourse-cdn.com/v4/letter/a/7993a0/32.png) [@amolp](https://discuss.elastic.co/u/amolp)\
**Post date:** [February 13, 2019, 3:31pm UTC](https://discuss.elastic.co/t/how-to-parse-mix-json-logs/167594/17 "2019-02-13T15:31:24Z")

</div>

output to the file is follows

{"message":"2019-02-03 23:51:54,263 | {"MACID":"0418003f","ID":"1","SS":"26","FW":"V5.1.14","TSRC":"R","SN":"25925","PCK":{"M26":"AQPAQF5GUJAERk93BUZPwnhGTy0eRrRuhUazKspGtLcXOVFJUjmdqII4+8z3OhLFrLcnzPe5kgAAAAC3F7lRqIK4+6iCOPsAAD+AAAA/gAAAP4AAAD+AAAAAAJumu0QAAAAAm6a7RBJvuwMSb7qDEm86gxJvuwMSbzsDEm87gxJvOoMSbzuDsTBC8PefQu5aAELwWh1CSJqZOnwAAEIQCj0/V7hSP14KPT9XAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAx3QBAxDPfEuB5/9LhswgSoH0AEgcXOgBAxDXBwAOmVUAAr1iAA4ZpAAA2h4BAwwgAAAABAAAAHW+Ons7l36HXFduJw=="},"RTC":"19/02/03,23:51:35"}","offset":61875000,"@timestamp":"2019-02-03T18:21:54.263Z","restOfLine":"{"MACID":"0418003f","ID":"1","SS":"26","FW":"V5.1.14","TSRC":"R","SN":"25925","PCK":{"M26":"AQPAQF5GUJAERk93BUZPwnhGTy0eRrRuhUazKspGtLcXOVFJUjmdqII4+8z3OhLFrLcnzPe5kgAAAAC3F7lRqIK4+6iCOPsAAD+AAAA/gAAAP4AAAD+AAAAAAJumu0QAAAAAm6a7RBJvuwMSb7qDEm86gxJvuwMSbzsDEm87gxJvOoMSbzuDsTBC8PefQu5aAELwWh1CSJqZOnwAAEIQCj0/V7hSP14KPT9XAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAx3QBAxDPfEuB5/9LhswgSoH0AEgcXOgBAxDXBwAOmVUAAr1iAA4ZpAAA2h4BAwwgAAAABAAAAHW+Ons7l36HXFduJw=="},"RTC":"19/02/03,23:51:35"}","SS":"26","PCK":{"M26":"AQPAQF5GUJAERk93BUZPwnhGTy0eRrRuhUazKspGtLcXOVFJUjmdqII4+8z3OhLFrLcnzPe5kgAAAAC3F7lRqIK4+6iCOPsAAD+AAAA/gAAAP4AAAD+AAAAAAJumu0QAAAAAm6a7RBJvuwMSb7qDEm86gxJvuwMSbzsDEm87gxJvOoMSbzuDsTBC8PefQu5aAELwWh1CSJqZOnwAAEIQCj0/V7hSP14KPT9XAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAx3QBAxDPfEuB5/9LhswgSoH0AEgcXOgBAxDXBwAOmVUAAr1iAA4ZpAAA2h4BAwwgAAAABAAAAHW+Ons7l36HXFduJw=="},"tags":["beats\_input\_codec\_plain\_applied"],"input":{"type":"log"},"MACID":"0418003f","ID":"1","TSRC":"R","host":{"architecture":"x86\_64","name":"amolpc-HP-Laptop-14-bs0xx","id":"810d928d8f414904937f2c900154e8ee","os":{"name":"Ubuntu","version":"16.04.2 LTS (Xenial Xerus)","platform":"ubuntu","family":"debian","codename":"xenial"},"containerized":false},"ts":"2019-02-03 23:51:54,263","prospector":{"type":"log"},"FW":"V5.1.14","SN":"25925","@version":"1","beat":{"hostname":"amolpc-HP-Laptop-14-bs0xx","name":"amolpc-HP-Laptop-14-bs0xx","version":"6.6.0"},"log":{"file":{"path":"/var/log/test\_logs.log"}},"RTC":"19/02/03,23:51:35","source":"/var/log/test\_logs.log"}

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [February 13, 2019, 3:58pm UTC](https://discuss.elastic.co/t/how-to-parse-mix-json-logs/167594/18 "2019-02-13T15:58:11Z")

</div>

My final attempt... the timestamp on the document is

```
"@timestamp":"2019-02-03T18:21:54.263Z"

```

That's Feb 3rd. Today is Feb 13th where I am. You have Kibana set to display documents from "Today". That's not going to include documents from the 3rd. Adjust the time picker.

---

<div class="post-metadata">

**Author:** ![amolp](https://avatars.discourse-cdn.com/v4/letter/a/7993a0/32.png) [@amolp](https://discuss.elastic.co/u/amolp)\
**Post date:** [February 13, 2019, 4:42pm UTC](https://discuss.elastic.co/t/how-to-parse-mix-json-logs/167594/19 "2019-02-13T16:42:24Z")

</div>

Apologize if I trubbled you,but the logs that you are refering above all are sample logs for testing purpose that why it's showing older dates in logs

I have commenitted the date field in filter code noe it's showing the logs.

Thank you very much for your kind support.

---

<div class="post-metadata">

**Author:** ![amolp](https://avatars.discourse-cdn.com/v4/letter/a/7993a0/32.png) [@amolp](https://discuss.elastic.co/u/amolp)\
**Post date:** [February 15, 2019, 9:03am UTC](https://discuss.elastic.co/t/how-to-parse-mix-json-logs/167594/20 "2019-02-15T09:03:52Z")

</div>

every thing is working fine for first type of log but i getting different types of logs from the server how do map those logs too,here are some sample logs  
working fine ------\>  
2019-02-03 23:51:54,263 | {"MACID":"00009934","ID":"1","SS":"26","FW":"V5.1.14","TSRC":"R","SN":"25925","PCK":{"M26":"AQPAQF5GUJAERk93BUZPwnhGTy0eRrRuhUazKspGtLcXOVFJUjmdqII4+8z3OhLFrLcnzPe5kgAAAAC3F7lRqIK4+6iCOPsAAD+AAAA/gAAAP4AAAD+AAAAAAJumu0QAAAAAm6a7RBJvuwMSb7qDEm86gxJvuwMSbzsDEm87gxJvOoMSbzuDsTBC8PefQu5aAELwWh1CSJqZOnwAAEIQCj0/V7hSP14KPT9XAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAx3QBAxDPfEuB5/9LhswgSoH0AEgcXOgBAxDXBwAOmVUAAr1iAA4ZpAAA2h4BAwwgAAAABAAAAHW+Ons7l36HXFduJw=="},"RTC":"19/02/03,23:51:35"}

* * *

not workng getting error for this ----\>

2019-02-03 23:52:11,940 | [V4,0833364F,533.330,0,0,533.330,0,0,0,0,-0.849,0,0,-0.849,628.064,0,0,628.064,432.013,  
431.847,433.645,430.547,249.423,247.824,251.089,249.355,1.055,0,0,3.164,49.975,38982176.000,0  
,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,19/02/03,23:52:12]

how do i map both type of logs,would be appreciable if you can help me in this.  
Thank you

[Next page](https://discuss.elastic.co/t/how-to-parse-mix-json-logs/167594.md?page=2)
