# How to parse nested json

**URL:** <https://discuss.elastic.co/t/how-to-parse-nested-json/57505>\
**Category:** Logstash\
**Created:** [August 8, 2016, 5:01pm UTC](https://discuss.elastic.co/t/how-to-parse-nested-json/57505 "2016-08-08T17:01:01Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![eladio](https://avatars.discourse-cdn.com/v4/letter/e/c57346/32.png) [@eladio](https://discuss.elastic.co/u/eladio)\
**Post date:** [August 8, 2016, 5:01pm UTC](https://discuss.elastic.co/t/how-to-parse-nested-json/57505/1 "2016-08-08T17:01:01Z")

</div>

this is my json

```
{"objId":"5586560001","id":"48013895","ts":"2016-03-08 14:45:05.799888","type":"001","comp":"DVD","message":"{\"id_Ext\":\"5586560001\",\"id\":\"001099223100316 12\",\"entryContainerID\":\"1\",\"movement\":\"MODIFIED\",\"coreAttribs\":[{\"id\":\"/Product_CPS\",\"type\":\"SPEC\",\"children\":[{\"id\":\"ExternalCode\",\"type\":\"STRING\",\"value\":\"5586560001\"},{\"id\":\"RefECI\",\"type\":\"STRING\",\"value\":\"001099223100316 12\"},{\"id\":\"General\",\"type\":\"GROUPING\",\"children\":[{\"id\":\"CodigoEmpresa\",\"type\":\"STRING\",\"value\":\"01\"},{\"id\":\"EanGtin\",\"type\":\" ....

```

i use this conf

# file: simple-out.conf

input {  
jdbc {  
# Oracle jdbc connection string to our database, mydb  
jdbc\_connection\_string =\> "jdbc:oracle:thin:@(description=(address\_list=(address=(protocol=tcp) (host=imdm.pre.eci.geci)(port=1534))(address=(protocol=tcp) (host=imdm.pre.eci.geci)(port=1535)))(connect\_data=(service\_name=eci\_mdmrpp)))"

```
    # The user we wish to execute our statement as
    jdbc_user => "consulta_mdm"
  jdbc_password => "consulta_mdm"
    # The path to our downloaded jdbc driver
    jdbc_driver_library => "C:\wrk\elasticsearch-2.3.4\logstash-2.3.4\lib\ojdbc6.jar"
    # The name of the driver class for Postgresql
    jdbc_driver_class => "Java::oracle.jdbc.driver.OracleDriver"
    # our query
    statement => "select id_msg as id , message as mensaje from DBMDMRPP.mensajes_dvd WHERE ID_MSG between 48013816 and 48013900 "
}

```

}  
filter{

```
	json {
      source => "mensaje"

}

```

}  
output {  
# Para pruebas  
# stdout { codec =\> json\_lines }

```
elasticsearch {
	index => "catalogo"
	document_type => "catalogo"
	hosts => "localhost:9200"	
}

```

}

this conf parse the json correctly but i try to parse the message field in the json , objid , ts ... are no relevant for me

do youw know how i parse this nested json ?

thanks

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [August 10, 2016, 5:51am UTC](https://discuss.elastic.co/t/how-to-parse-nested-json/57505/2 "2016-08-10T05:51:32Z")

</div>

The question isn't clear to me. Are you having trouble parsing the JSON field? Or do you want to remove e.g. the `objId` field afterwards? Please show what your event current look like (preferably using a `stdout { codec => rubydebug }` output) and what you want it to look like instead.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 4:44am UTC](https://discuss.elastic.co/t/how-to-parse-nested-json/57505/3 "2017-07-06T04:44:09Z")

</div>


