# How to parse multiple json using logstash which can occure anywhere in the log

**URL:** <https://discuss.elastic.co/t/how-to-parse-multiple-json-using-logstash-which-can-occure-anywhere-in-the-log/227781>\
**Category:** Logstash\
**Created:** [April 13, 2020, 1:53pm UTC](https://discuss.elastic.co/t/how-to-parse-multiple-json-using-logstash-which-can-occure-anywhere-in-the-log/227781 "2020-04-13T13:53:25Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![Preyas\_Mistry](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/preyas_mistry/32/66223_2.png) [@Preyas\_Mistry](https://discuss.elastic.co/u/Preyas_Mistry)\
**Post date:** [April 13, 2020, 1:53pm UTC](https://discuss.elastic.co/t/how-to-parse-multiple-json-using-logstash-which-can-occure-anywhere-in-the-log/227781/1 "2020-04-13T13:53:25Z")

</div>

I want to parse this log into ES which has multiple JSON string in it, the position of JSON is not fixed!

`2020-03-30 17:42:15,672 INFO [DefaultMessageListenerContainer-4] (MeetingServiceImpl.getMeetingParticipants:270) - {"a": 123, "b": { "b1": 234 } } some text here {"c":"567","d":"789"}`

I have tried this logstash filter:

```
filter{
    grok {
        match => { "message" => "%{TIMESTAMP_ISO8601:time} %{LOGLEVEL:logLevel}\s*\[(?<thread>([\w\-]+|[\w\s]+))\] (\(%{DATA:className}\.%{DATA:methodName}:%{NUMBER:lineNumber}\)) - %{GREEDYDATA:message}"}
        overwrite => ["message"]
    }
ruby {
    code => "
        json1 = event.get('message').match(\{.*?\})[1]
        event.set('json1',json1)
        "
    }

    json { 
        source => "json1"
        target => "payload"
    }

    if "TRACE" in [logLevel]{
      drop { }
    }
    date{
        match => ["time","ISO8601"]
        target => "time"
    }
    mutate{
        convert => { "lineNumber" => "integer" }
    }
    mutate{
        remove_field => ["@version","offset","tags","agent","ecs"]
    }
    mutate {
      gsub => ["message","\(", "=("]
    }
    kv {
      source => "message"
      recursive => "true"
      field_split => ",\s\(\)"
      value_split => "="
      trim_key => "\s"
      target => "payload"
    }
    if "_grokparsefailure" in [tags] {
      drop { }
    }

    ruby {
        code => "
                  hash = event.to_hash
                  hash.each { |key,value|
                  if value != nil
                      str = value.to_s
                        if str.blank?
                          event.remove(key)
                        end
                  end
                }
              "
    }
}

```

But got this exception: **java.lang.IllegalStateException: Logstash stopped processing because of an error: (SyntaxError) (ruby filter code):3: syntax error, unexpected null json1 = event.get('message').match({.\*?})[1] ^**

Expected Output:  
{  
"logLevel" =\> "INFO",  
"lineNumber" =\> 270,  
"methodName" =\> "getMeetingParticipants",  
"payload" =\> {  
"b" =\> {  
"b1" =\> 234  
},  
"a" =\> 123,  
"c" =\> 567,  
"d" =\> 789  
},  
"@timestamp" =\> 2020-04-13T09:51:48.333Z,  
"host" =\> "ThinkPad-E470",  
"time" =\> 2020-03-30T12:12:15.672Z,  
"message" =\> "{"a": 123, "b": { "b1": 234 } } some text here {"c":567,"d":789}",  
"className" =\> "MeetingServiceImpl",  
"path" =\> "/logstashworks/logs/malogs.log",  
"thread" =\> "DefaultMessageListenerContainer-4"  
}

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 11, 2020, 1:53pm UTC](https://discuss.elastic.co/t/how-to-parse-multiple-json-using-logstash-which-can-occure-anywhere-in-the-log/227781/2 "2020-05-11T13:53:25Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
