# Index attributes from a multiline json string

**URL:** <https://discuss.elastic.co/t/index-attributes-from-a-multiline-json-string/258132>\
**Category:** Elasticsearch\
**Created:** [December 9, 2020, 1:43pm UTC](https://discuss.elastic.co/t/index-attributes-from-a-multiline-json-string/258132 "2020-12-09T13:43:12Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![Luca\_P](https://avatars.discourse-cdn.com/v4/letter/l/bbe5ce/32.png) [@Luca\_P](https://discuss.elastic.co/u/Luca_P)\
**Post date:** [December 9, 2020, 1:43pm UTC](https://discuss.elastic.co/t/index-attributes-from-a-multiline-json-string/258132/1 "2020-12-09T13:43:12Z")

</div>

Hi All,

I need some advice here, I don't want to reinvent the wheel.  
With Filebeat 6.7.0 I'm picking up logs in typical docker format, , i.e. json strings with "log", "stream" and "time" attributes.  
In the logs, each event is actually split in multiple lines of the same format, that I re-assemble back using multiline.pattern in Filebeat..  
So for example, in the logs I find 1 event split in these lines (I added spaces to show the log-stream-time format):

```auto
{"log":"2020-12-08T10:36:03.621Z - info: Request \n", "stream":"stdout", "time":"2020-12-08T10:36:03.621670333Z"}
{"log":"{ attr01: 'value01',\n", "stream":"stdout", "time":"2020-12-08T10:36:03.621687063Z"}
{"log":" attr02: 'value02',\n", "stream":"stdout", "time":"2020-12-08T10:36:03.621691804Z"}
{"log":" attr03: 'vslue03',\n", "stream":"stdout", "time":"2020-12-08T10:36:03.621695644Z"}
{"log":" attr04: { attr05: 'value05', attr06: 'value06' },\n", "stream":"stdout", "time":"2020-12-08T10:36:03.621702493Z"}
{"log":" attr07: { attr08: 'value08', attr09: 'value09' },\n", "stream":"stdout", "time":"2020-12-08T10:36:03.621702493Z"}
{"log":" attr10:\n", "stream":"stdout", "time":"2020-12-08T10:36:03.621707294Z"}
{"log":" { attr11: 'value11',\n", "stream":"stdout", "time":"2020-12-08T10:36:03.621721053Z"}
{"log":" attr12: 'value12',\n", "stream":"stdout", "time":"2020-12-08T10:36:03.621724964Z"}
{"log":" attr13: 'value13' } }\n", "stream":"stdout", "time":"2020-12-08T10:36:03.621739265Z"}

```

And thanks to multiline.pattern, Filebeat reassembles the "log" values, giving me 1 single event in ElasticSearch where "message" is a multiline string, like:

```auto
2020-12-08T10:36:03.621Z - info: Request
{ attr01: 'value01',
  attr02: 'value02',
  attr03: 'value03',
  attr04: { attr05: 'value05', attr06: 'value06' },
  attr07: { attr08: 'value08', attr09: 'value09' },
  attr10:
   { attr11: 'value11',
     attr12: 'value12',
     attr13: 'value13' } }

```

My question: I wish to see all those attr\* in the json multiline string as searchable attributes, as now I have only a multline string in message.  
Ideally in the ES event I wish to see attributes like:

```auto
....
message.attr01: 'value01'
message.attr02: 'value02'
....

```

Is it easy to achieve? Any hint is more than welcome

Cheers

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 6, 2021, 1:43pm UTC](https://discuss.elastic.co/t/index-attributes-from-a-multiline-json-string/258132/2 "2021-01-06T13:43:30Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
