# Json array splitting in logstash

**URL:** <https://discuss.elastic.co/t/json-array-splitting-in-logstash/82139>\
**Category:** Logstash\
**Created:** [April 12, 2017, 10:40am UTC](https://discuss.elastic.co/t/json-array-splitting-in-logstash/82139 "2017-04-12T10:40:43Z")\
**Posts on this page:** 12\
**Page:** 1

<div class="post-metadata">

**Author:** ![Shweta](https://avatars.discourse-cdn.com/v4/letter/s/839c29/32.png) [@Shweta](https://discuss.elastic.co/u/Shweta)\
**Post date:** [April 12, 2017, 10:40am UTC](https://discuss.elastic.co/t/json-array-splitting-in-logstash/82139/1 "2017-04-12T10:40:43Z")

</div>

Hi,

We have following kind of logs in json files.

{"info":{"tstmp":1.2,"from":"avshdd","hostid":"jahgcjha","log":{"version":"jhasgc","id":"jsadh","jobname":"xzcj","lognm":{"class":"jscjks","msg":[{"users":"kjdfk","commands":"jhscjhs","pririty":"jhasj","host":"kjsjcksjd"},{"users":"kjdfkxc","commands":"jhscjhsdsf","pririty":"jhasjdd","host":"kjsdfsjcksjd"}],"severity":"info"}},"mtype":"kjsjs"}}

We tried splitting arrays in it. But no luck. We are new in parsing json. Following is the logstash config we are using:

input  
{  
file  
{  
path =\> ["/var/log/validjson3.log"]  
type =\> "json"  
codec =\> "json"  
sincedb\_path =\> "/dev/null"  
start\_position =\> "beginning"  
}  
}

filter  
{  
split { field =\> "[info][log][lognm]lmsg" }  
}

output {  
elasticsearch {  
hosts =\> ["xyz:9200"]  
sniffing =\> false  
manage\_template =\> false  
user =\> user  
password =\> passwd  
index =\> "json-%{+YYYY.MM.dd}"  
}  
stdout {  
codec =\> rubydebug  
}  
}

While using this config we got following error:

Please let us know if we are missing something in logstash config.

Regards,  
Shweta

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [April 12, 2017, 1:18pm UTC](https://discuss.elastic.co/t/json-array-splitting-in-logstash/82139/2 "2017-04-12T13:18:06Z")

</div>

> ```
> split { field => "[info][log][lognm]lmsg" }
> 
> ```

"lmsg"? Try this:

```
 split { field => "[info][log][lognm][msg]" }

```

---

<div class="post-metadata">

**Author:** ![Shweta](https://avatars.discourse-cdn.com/v4/letter/s/839c29/32.png) [@Shweta](https://discuss.elastic.co/u/Shweta)\
**Post date:** [April 13, 2017, 7:11am UTC](https://discuss.elastic.co/t/json-array-splitting-in-logstash/82139/3 "2017-04-13T07:11:17Z")

</div>

Thank you Magnus. That was typing mistake.

We have following nested array structure:

{  
"info": {  
"tstmp": 1.2,  
"from": "avshdd",  
"hostid": "jahgcjha",  
"log": {  
"version": "jhasgc",  
"id": "jsadh",  
"jobname": "xzcj",  
"lognm": {  
"msg": {  
"groups": [{  
"name": "asg",  
"gid": 0  
}],  
"user": [{  
"users": "kjdfk",  
"commands": "jhscjhs",  
"pririty": "jhasj",  
"host": "kjsjcksjd"  
}, {  
"users": "kjdfkxc",  
"commands": "jhscjhsdsf",  
"pririty": "jhasjdd",  
"host": "kjsdfsjcksjd"  
}]  
},  
"severity": "info"  
}  
},  
"mtype": "kjsjs"  
}  
}

There are two nested arrays in "msg" named "greops" and "user".

Please help us with filter for it.

Thanks in advance.

Regards,  
Shweta

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [April 13, 2017, 7:14am UTC](https://discuss.elastic.co/t/json-array-splitting-in-logstash/82139/4 "2017-04-13T07:14:12Z")

</div>

Please show the wanted outcome for the given example event.

---

<div class="post-metadata">

**Author:** ![Shweta](https://avatars.discourse-cdn.com/v4/letter/s/839c29/32.png) [@Shweta](https://discuss.elastic.co/u/Shweta)\
**Post date:** [April 13, 2017, 7:25am UTC](https://discuss.elastic.co/t/json-array-splitting-in-logstash/82139/5 "2017-04-13T07:25:02Z")

</div>

@magnusbaeck: We want fields to be seen in kibana like following:

[info.log.msg.groups.name](http://info.log.msg.groups.name)  
info.log.msg.groups.gid

info.log.msg.user.users  
info.log.msg.user.commands  
info.log.msg.user.pririty  
info.log.msg.user.host

Thanks and Regards,  
Shweta

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [April 13, 2017, 7:27am UTC](https://discuss.elastic.co/t/json-array-splitting-in-logstash/82139/6 "2017-04-13T07:27:42Z")

</div>

Please be more explicit. What do the wanted event JSON object(s) look like?

---

<div class="post-metadata">

**Author:** ![Shweta](https://avatars.discourse-cdn.com/v4/letter/s/839c29/32.png) [@Shweta](https://discuss.elastic.co/u/Shweta)\
**Post date:** [April 13, 2017, 7:41am UTC](https://discuss.elastic.co/t/json-array-splitting-in-logstash/82139/7 "2017-04-13T07:41:54Z")

</div>

@magnusbaeck

We have provided following filter configuration:

filter  
{  
split { field =\> "[info][log][lognm][msg]groups" }  
}

which gives us following result in Kibana

 ![](https://us1.discourse-cdn.com/elastic/original/3X/5/4/545a1aca1fe4c327fb4389b814d0d8594fb47131.png)

We want user and groups array to be parsed on same level. We are not able to provide filter configuration for same level arrays in Json.

Thanks and regards,  
Shweta

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [April 13, 2017, 8:00am UTC](https://discuss.elastic.co/t/json-array-splitting-in-logstash/82139/8 "2017-04-13T08:00:08Z")

</div>

You are not answering my question. I'm not asking what you _currently_ have. I'm asking what you _want_. Last chance: What do the wanted event JSON object(s) look like?

---

<div class="post-metadata">

**Author:** ![NITIN-BHAISARE](https://avatars.discourse-cdn.com/v4/letter/n/c89c15/32.png) [@NITIN-BHAISARE](https://discuss.elastic.co/u/NITIN-BHAISARE)\
**Post date:** [April 13, 2017, 8:03am UTC](https://discuss.elastic.co/t/json-array-splitting-in-logstash/82139/9 "2017-04-13T08:03:52Z")

</div>

@magnusbaeck I do have same type of problem. Can somebody please help me on this?? I am stuck at this. Please help

Thanks  
Nitin Bhaisare

---

<div class="post-metadata">

**Author:** ![Shweta](https://avatars.discourse-cdn.com/v4/letter/s/839c29/32.png) [@Shweta](https://discuss.elastic.co/u/Shweta)\
**Post date:** [April 13, 2017, 8:13am UTC](https://discuss.elastic.co/t/json-array-splitting-in-logstash/82139/10 "2017-04-13T08:13:47Z")

</div>

Sorry @magnusbaeck . I want to have fields like this:

info.log.lognm.msg.user.users: kjdfk  
info.log.lognm.msg.user.commands: jhscjhs  
info.log.lognm.msg.user.pririty: jhasj  
info.log.lognm.msg.user.host: kjsjcksjd

But with the current configuration we are getting this in kibana,

info.log.lognm.msg.user {  
"users": "kjdfk",  
"commands": "jhscjhs",  
"pririty": "jhasj",  
"host": "kjsjcksjd"  
},  
{  
"users": "kjdfkxc",  
"commands": "jhscjhsdsf",  
"pririty": "jhasjdd",  
"host": "kjsdfsjcksjd"  
}

Hope this is the thing,you asked for.

I wanted to have flattened event.

---

<div class="post-metadata">

**Author:** ![Shweta](https://avatars.discourse-cdn.com/v4/letter/s/839c29/32.png) [@Shweta](https://discuss.elastic.co/u/Shweta)\
**Post date:** [April 13, 2017, 8:18am UTC](https://discuss.elastic.co/t/json-array-splitting-in-logstash/82139/12 "2017-04-13T08:18:28Z")

</div>

We got following in logstash.stdout

{  
"info" =\> {  
"tstmp" =\> 1.2,  
"from" =\> "avshdd",  
"hostid" =\> "jahgcjha",  
"log" =\> {  
"version" =\> "jhasgc",  
"id" =\> "jsadh",  
"jobname" =\> "xzcj",  
"lognm" =\> {  
"msg" =\> {  
"groups" =\> {  
"name" =\> "gasg",  
"gid" =\> 0  
},  
"user" =\> [  
[0] {  
"users" =\> "kjdfk",  
"commands" =\> "jhscjhs",  
"pririty" =\> "jhasj",  
"host" =\> "kjsjcksjd"  
},  
[1] {  
"users" =\> "kjdfkxc",  
"commands" =\> "jhscjhsdsf",  
"pririty" =\> "jhasjdd",  
"host" =\> "kjsdfsjcksjd"  
}  
]  
},  
"severity" =\> "info"  
}  
},  
"mtype" =\> "kjsjs"  
},  
"@version" =\> "1",  
"@timestamp" =\> "2017-04-13T07:36:54.912Z",  
"path" =\> "/var/log/123.log",  
"host" =\> "test"  
}

Thanks and regards,  
Shweta

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 11, 2017, 8:21am UTC](https://discuss.elastic.co/t/json-array-splitting-in-logstash/82139/13 "2017-05-11T08:21:44Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
