# Issue with message field while parsing JSON

**URL:** <https://discuss.elastic.co/t/issue-with-message-field-while-parsing-json/188894>\
**Category:** Logstash\
**Created:** [July 4, 2019, 10:58am UTC](https://discuss.elastic.co/t/issue-with-message-field-while-parsing-json/188894 "2019-07-04T10:58:57Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![ankamraok](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ankamraok/32/49498_2.png) [@ankamraok](https://discuss.elastic.co/u/ankamraok)\
**Post date:** [July 4, 2019, 10:58am UTC](https://discuss.elastic.co/t/issue-with-message-field-while-parsing-json/188894/1 "2019-07-04T10:58:57Z")

</div>

Hi,

I am parsing jboss fuse container logs ,which are JSON messags,following a sample JSON message.

{"@timestamp":"2019-06-25T08:34:36.517Z","source\_host":"sitfabr02.local","level":"INFO","thread\_name":"qtp1821745282-22143","@version":1,"logger\_name":"org.apache.cxf.services.FlightsSearchBaseFaresV1RestClient.REQ\_OUT","message": "{"released":true}","mdc":{"camel.messageId":"ID--local-36712-1561427486681-16-239094","portTypeName":"RestClient","headers":"{X-Client-Transaction-Id=1098.69747568.0, X-Client-Id=PS, Accept=application/json, breadcrumbId=topic\_com.AL.ChangedV1\_\_com..InventoryChangedV1\_null, X-POS-Id=DigitalWeb, Content-Type=application/json}","exchangeId":"349f6de5-58f1-46ce-ba7f-b2269c5b5ca7","x-client-transaction-id":"1098.69747568.0","fps.service-id":"SVC\_FPS\_00022","messageId":"be67a43d-cc5c-40ab-ba25-35eca640f920","content-type":"application/json","portName":"SearchBaseFaresV1RestClient","bundle.id":899,"fps.client-ip":"127.0.0.1","bundle.version":"3.1.5.redhat-630371"}}

Filebeat and Logstash configs are standard.

Filebeat:  
json.keys\_under\_root: true  
json.overwrite\_keys: true  
json.add\_error\_key: true

Logstash:  
input {  
beats {  
port =\> 6001  
codec =\> json  
client\_inactivity\_timeout =\> 2400  
}  
}  
I didn't had any filter section and standard output to Elastic.

All versions used are 6.2(beats,logstash and elastic)

The issue i am facing is these is no message field coming in the event even though we had it in JSON instead the message field getting tread as JSON itself and adding a field "released" with value "true".

How can we keep the message field intact and keep as is.

As these are fuse framework logs,my development team don't want to change their framework.

any help will be appreciated,thanks.

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [July 4, 2019, 1:54pm UTC](https://discuss.elastic.co/t/issue-with-message-field-while-parsing-json/188894/2 "2019-07-04T13:54:04Z")

</div>

You have told filebeat to parse the json and add fields. That will result in it sending a [message] field that contains the string '{"released":true}'.

Then you have told the beats input to parse the [message] it receives as JSON, which results in it creating a [released] field. Remove the codec.

---

<div class="post-metadata">

**Author:** ![ankamraok](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ankamraok/32/49498_2.png) [@ankamraok](https://discuss.elastic.co/u/ankamraok)\
**Post date:** [July 5, 2019, 9:57am UTC](https://discuss.elastic.co/t/issue-with-message-field-while-parsing-json/188894/3 "2019-07-05T09:57:25Z")

</div>

Thanks Badger.Worked perfect.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 2, 2019, 9:57am UTC](https://discuss.elastic.co/t/issue-with-message-field-while-parsing-json/188894/4 "2019-08-02T09:57:26Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
