# How to parse mix json logs

**URL:** <https://discuss.elastic.co/t/how-to-parse-mix-json-logs/167594>\
**Category:** Logstash\
**Created:** [February 8, 2019, 9:14am UTC](https://discuss.elastic.co/t/how-to-parse-mix-json-logs/167594 "2019-02-08T09:14:34Z")\
**Posts on this page:** 1\
**Showing post:** 2

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [February 8, 2019, 12:22pm UTC](https://discuss.elastic.co/t/how-to-parse-mix-json-logs/167594/2 "2019-02-08T12:22:57Z")

</div>

You can parse a message like that using

```
    dissect { mapping => { "message" => "%{ts} %{+ts} | %{restOfLine}" } }
    json { source => "restOfLine" }
    date { match => ["ts", "ISO8601"] }

```

How to query the number of documents that contain a given field is an elasticsearch (or kibana) question, not a logstash question.

---

_[View the full topic](https://discuss.elastic.co/t/how-to-parse-mix-json-logs/167594)._
