# JSON codec plugin - target option (http input)

**URL:** <https://discuss.elastic.co/t/json-codec-plugin-target-option-http-input/304217>\
**Category:** Logstash\
**Created:** [May 9, 2022, 8:04am UTC](https://discuss.elastic.co/t/json-codec-plugin-target-option-http-input/304217 "2022-05-09T08:04:41Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![sectex](https://avatars.discourse-cdn.com/v4/letter/s/ba9def/32.png) [@sectex](https://discuss.elastic.co/u/sectex)\
**Post date:** [May 9, 2022, 8:04am UTC](https://discuss.elastic.co/t/json-codec-plugin-target-option-http-input/304217/1 "2022-05-09T08:04:41Z")

</div>

I am having some issues using the [JSON codec plugin](https://www.elastic.co/guide/en/logstash/current/plugins-codecs-json.html) in my Logstash (v8.1.2) pipeline.

`pipeline.conf`:

```nohighlight
input {
    http {
        codec => json
        port => 5046
    }
}
output {
    stdout {
        codec => rubydebug
    }
}

```

input:

```json
[
    {"message":"message 1"},
    {"message":"message 2"},
    {"message":"message 3"}
]

```

The plugin itself generates multiple events if the data sent is a JSON array, so this configuration will generate events like the following:

```nohighlight
{ "message" => "message 1" }
{ "message" => "message 2" }
{ "message" => "message 3" }

```

This also produces the following log message in Logstash:

```nohighlight
[INFO][logstash.codecs.json][main][060a60e30dc5b27b453c31a99b7494beee922048c3d0b8261b9894d53753ba46] ECS compatibility is enabled but `target` option was not specified. This may cause fields to be set at the top-level of the event where they are likely to clash with the Elastic Common Schema. It is recommended to set the `target` option to avoid potential schema conflicts (if your data is ECS compliant or non-conflicting, feel free to ignore this message)

```

Setting the `target` option does not seem to have any effect. Neither the log message nor the structure of the generated events has changed.  
The [documentation](https://www.elastic.co/guide/en/logstash/current/plugins-codecs-json.html#plugins-codecs-json-target) states that this option is used to define the target field for placing the parsed data. By changing this option to `[document]` I expected the plugin to generate events like this, but that is not the case:

```nohighlight
{ "document" => { "message" => "message 1" }}
{ "document" => { "message" => "message 2" }}
{ "document" => { "message" => "message 3" }}

```

Is there a way to place the parsed data in a target field?  
What is the `target` option used for? Did I misunderstand something here?  
Is there a way to suppress the log message?

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [May 9, 2022, 1:28pm UTC](https://discuss.elastic.co/t/json-codec-plugin-target-option-http-input/304217/2 "2022-05-09T13:28:01Z")

</div>

> [@sectex](#):
>
> Is there a way to suppress the log message?

You can append

```auto
logger.randomname.name = logstash.codec.json
logger.randomname.level = ERROR

```

to your log4j2.properties file. When I set the target option on a json codec the fields are moved under the target. For example,

```
input { generator { count => 1 lines => ['{ "a": 1 }'] codec => json { target => "[document]" } } }
filter {}
output { stdout { codec => rubydebug { metadata => false } } }

```

produces

```
  "document" => {
    "a" => 1
},

```

---

<div class="post-metadata">

**Author:** ![sectex](https://avatars.discourse-cdn.com/v4/letter/s/ba9def/32.png) [@sectex](https://discuss.elastic.co/u/sectex)\
**Post date:** [May 9, 2022, 2:17pm UTC](https://discuss.elastic.co/t/json-codec-plugin-target-option-http-input/304217/3 "2022-05-09T14:17:48Z")

</div>

I can confirm that this works when using the [input generator plugin](https://www.elastic.co/guide/en/logstash/current/plugins-inputs-generator.html).  
However, when using the [http input plugin](https://www.elastic.co/guide/en/logstash/current/plugins-inputs-http.html) the `target` option seems to be ignored. For example,

```auto
input { 
    http {
        port => 5046
        codec => json {
            target => "[document]"
        }
    }
}
filter {}
output {
    stdout {
        codec => rubydebug {
            metadata => false 
        }
    }
}

```

+ request

```bash
curl -d '{"a":1}' -H "Content-Type: application/json" -X POST http://localhost:5046/

```

produces

```auto
{
    "a" => 1,
    "http" => ...
    "@timestamp" => ...
}

```

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [May 9, 2022, 2:26pm UTC](https://discuss.elastic.co/t/json-codec-plugin-target-option-http-input/304217/4 "2022-05-09T14:26:07Z")

</div>

> [@sectex](#):
>
> `Content-Type: application/json`

That feels like a bug to me. The input applies a codec itself before seeing what codec the user configured. See [here](https://github.com/logstash-plugins/logstash-input-http/blob/9fb2f674a97be34acde2c7d234d13de914cf5a84/lib/logstash/inputs/http.rb#L99). You could try

```
additional_codecs => {}
codec => json { target => "[document]" }

```

---

<div class="post-metadata">

**Author:** ![sectex](https://avatars.discourse-cdn.com/v4/letter/s/ba9def/32.png) [@sectex](https://discuss.elastic.co/u/sectex)\
**Post date:** [May 9, 2022, 3:12pm UTC](https://discuss.elastic.co/t/json-codec-plugin-target-option-http-input/304217/5 "2022-05-09T15:12:02Z")

</div>

Many thanks, that worked!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 6, 2022, 3:12pm UTC](https://discuss.elastic.co/t/json-codec-plugin-target-option-http-input/304217/6 "2022-06-06T15:12:11Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
