# How to parse multipart json in logstash

**URL:** <https://discuss.elastic.co/t/how-to-parse-multipart-json-in-logstash/178400>\
**Category:** Logstash\
**Created:** [April 25, 2019, 8:46am UTC](https://discuss.elastic.co/t/how-to-parse-multipart-json-in-logstash/178400 "2019-04-25T08:46:25Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![kunal\_p](https://avatars.discourse-cdn.com/v4/letter/k/f07891/32.png) [@kunal\_p](https://discuss.elastic.co/u/kunal_p)\
**Post date:** [April 25, 2019, 8:46am UTC](https://discuss.elastic.co/t/how-to-parse-multipart-json-in-logstash/178400/1 "2019-04-25T08:46:26Z")

</div>

We are having sample json logs as below

{  
"responseBody": {  
"Info": [ {  
"supplierBookReferences": [ {  
"field1": "NA",  
"field2": "NA",  
"field3": "",  
"field4": "NA",  
"field5": "",  
"field6": ""  
}],  
"status": "Confirmed"  
}],  
"field1": "NA"  
},  
"responseHeader": {  
"clientContext": {  
"field7": "NA",  
"field8": "NA"  
},  
"field9": "NA",  
"field10": "abc",  
"field11": "abc"  
}  
}

I am unable to parse the logs with the below logstash configuration.

input  
{  
file  
{  
path =\> "/elk/logstash-7.0.0/bin/multistepJSON.txt"  
start\_position =\> "beginning"

```
            }

```

}  
filter  
{  
grok  
{  
match =\> ["message", "%{GREEDYDATA:json\_payload}"]  
}  
mutate  
{  
gsub =\> ["json\_payload","[\r]",""]  
}  
json  
{  
source =\> "json\_payload"  
#target =\> "payload"  
}  
mutate  
{  
gsub =\>["json\_payload","\n\t",""]  
}

}  
output  
{  
stdout { codec =\> rubydebug}  
}

With this configuration getting jsonfarsefailure

Any help would be appreciated.

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [April 25, 2019, 3:12pm UTC](https://discuss.elastic.co/t/how-to-parse-multipart-json-in-logstash/178400/2 "2019-04-25T15:12:57Z")

</div>

```
grok { match => ["message", "%{GREEDYDATA:json_payload}"] }

```

It does not make sense to use grok to copy the whole of one field to another. Use [mutate+copy](https://www.elastic.co/guide/en/logstash/current/plugins-filters-mutate.html#plugins-filters-mutate-copy) instead

```
mutate { gsub => ["json_payload","[\r]",""] }
mutate { gsub =>["json_payload","\n\t",""] }

```

Unless you have [config.support\_escapes](https://www.elastic.co/guide/en/logstash/current/logstash-settings-file.html) enabled these do not do what you think they do. If you need to get rid of \n in a string then use a literal newline in the pattern

```
mutate { gsub =>["json_payload","
",""] }

```

That said, the json filter will work around newline, carriage return and tab, so you probably do not need to remove them.

A file input will consume a file one line at a time, so unless your JSON is a single line you will need to use a multiline codec to ingest it.

---

<div class="post-metadata">

**Author:** ![kunal\_p](https://avatars.discourse-cdn.com/v4/letter/k/f07891/32.png) [@kunal\_p](https://discuss.elastic.co/u/kunal_p)\
**Post date:** [April 26, 2019, 6:06am UTC](https://discuss.elastic.co/t/how-to-parse-multipart-json-in-logstash/178400/3 "2019-04-26T06:06:00Z")

</div>

Thank you , your idea of multine worked , will keep you posted fori further ..

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 24, 2019, 6:18am UTC](https://discuss.elastic.co/t/how-to-parse-multipart-json-in-logstash/178400/4 "2019-05-24T06:18:50Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
