# How to remove backslash from weird formatted json

**URL:** <https://discuss.elastic.co/t/how-to-remove-backslash-from-weird-formatted-json/279084>\
**Category:** Logstash\
**Created:** [July 19, 2021, 3:18pm UTC](https://discuss.elastic.co/t/how-to-remove-backslash-from-weird-formatted-json/279084 "2021-07-19T15:18:30Z")\
**Posts on this page:** 1\
**Showing post:** 2

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [July 19, 2021, 3:43pm UTC](https://discuss.elastic.co/t/how-to-remove-backslash-from-weird-formatted-json/279084/2 "2021-07-19T15:43:59Z")

</div>

It looks like your JSON is pretty printed, in which case you need a multiline codec to put the parts of the object back together. There is an example of consuming a file as a single event [here](https://discuss.elastic.co/t/parsing-array-of-json-objects-with-logstash-and-injesting-to-elastic/203197/2).

Once you do that you have a event containing JSON that contains nested JSON. You can use a json filter to do the parsing.

```
    json { source => "message" remove_field => ["message"] target => "[someField]" }
    json { source => "[someField][0][log]" target => "[someField][0][stuff]" }

```

That will result in

```
 "someField" => [
    [0] {
          "date" => "2021-04-16 09:24:50",
           "log" => "{\"date\":\"16/04/2021\",\"time\":\"09h24\",\"t_1\":\"20.7\",\"t_2\":\"20.0\",\"t_3\":\"12.6\",\"t_4\":\"19.1\",\"p_1\":\"115\",\"w_1\":\"0.52\",\"w_2\":\"3.72\",\"w_4\":\"1.64\"}",
        "source" => "192.168.10.230",
            "sn" => "00:1E:C0:8D:9A:CD",
            "id" => "1",
         "udate" => "1618557890",
         "stuff" => {
            "date" => "16/04/2021",
             "p_1" => "115",
             "t_2" => "20.0",
             "t_1" => "20.7",
             "w_1" => "0.52",
             "t_4" => "19.1",
             "t_3" => "12.6",
             "w_2" => "3.72",
            "time" => "09h24",
             "w_4" => "1.64"
        }
    },

```

You might, or might not, want to use a split filter to divide the [someField] array into multiple events.

If the array is variable length and you need to iterate over it, parsing each entry, then you would need a ruby filter.

---

_[View the full topic](https://discuss.elastic.co/t/how-to-remove-backslash-from-weird-formatted-json/279084)._
