# Json Data not getting parsed when sent to Elasticsearch

**URL:** <https://discuss.elastic.co/t/json-data-not-getting-parsed-when-sent-to-elasticsearch/19424>\
**Category:** Elasticsearch\
**Created:** [August 24, 2014, 1:54pm UTC](https://discuss.elastic.co/t/json-data-not-getting-parsed-when-sent-to-elasticsearch/19424 "2014-08-24T13:54:08Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![Didjit](https://avatars.discourse-cdn.com/v4/letter/d/58f4c7/32.png) [@Didjit](https://discuss.elastic.co/u/Didjit)\
**Post date:** [August 24, 2014, 1:54pm UTC](https://discuss.elastic.co/t/json-data-not-getting-parsed-when-sent-to-elasticsearch/19424/1 "2014-08-24T13:54:08Z")

</div>

Hi,

The following is a debug from Logstash:

{  
"message" =\>  
"{"EventTime":"2014-08-24T09:44:46-0400","URI":"[http://ME/rest/venue/ME/hours/2014-08-24","uri\_payload":{"value":[{"open":"2014-08-24T13:00:00.000+0000","close":"2014-08-24T23:00:00.000+0000","isOpen":true,"date":"2014-08-24"}],"Count":1}}\r"](http://ME/rest/venue/ME/hours/2014-08-24%22,%22uri_payload%22:%7B%22value%22:%5B%7B%22open%22:%222014-08-24T13:00:00.000+0000%22,%22close%22:%222014-08-24T23:00:00.000+0000%22,%22isOpen%22:true,%22date%22:%222014-08-24%22%7D%5D,%22Count%22:1%7D%7D%5Cr%22),  
"@version" =\> "1",  
"@timestamp" =\> "2014-08-24T13:44:48.036Z",  
"host" =\> "127.0.0.1:60778",  
"type" =\> "MY\_Detail",  
"EventTime" =\> "2014-08-24T09:44:46-0400",  
"URI" =\> "[http://ME/rest/venue/ME//hours/2014-08-24](http://ME/rest/venue/ME//hours/2014-08-24)",  
"uri\_payload" =\> {  
"value" =\> [  
[0] {  
"open" =\> "2014-08-24T13:00:00.000+0000",  
"close" =\> "2014-08-24T23:00:00.000+0000",  
"isOpen" =\> true,  
"date" =\> "2014-08-24"  
}  
],  
"Count" =\> 1,  
"0" =\> {}  
},  
"MYId" =\> "ME"  
}

* * *

When i look into Elasticsearch, the fields under URI Payload are not  
parsed. It shows:

uri\_payload.value as the field with "  
{"open":"2014-08-21T13:00:00.000+0000","close":"2014-08-21T23:00:00.000+0000","isOpen":true,"date":"2014-08-21"}"

How can I get all the parsed values as fields in elasticsearch? In my  
example, fields Open, Close, IsOpen. Initially I thought Logstash was not  
parsing all the json, but looking at the debug it is.

Thank you,

Chris

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/af983e1d-a67b-4d9f-afa1-2a8c99c4d897%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/af983e1d-a67b-4d9f-afa1-2a8c99c4d897%40googlegroups.com).  
For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

---

<div class="post-metadata">

**Author:** ![moshe\_zada](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/moshe_zada/32/53780_2.png) [@moshe\_zada](https://discuss.elastic.co/u/moshe_zada)\
**Post date:** [August 24, 2014, 2:11pm UTC](https://discuss.elastic.co/t/json-data-not-getting-parsed-when-sent-to-elasticsearch/19424/2 "2014-08-24T14:11:44Z")

</div>

what is your logstash configuration?  
did you tried the json codec [http://logstash.net/docs/1.4.2/codecs/json](http://logstash.net/docs/1.4.2/codecs/json)?

On Sunday, August 24, 2014 4:54:08 PM UTC+3, Didjit wrote:

> Hi,
> 
> The following is a debug from Logstash:
> 
> {  
> "message" =\>  
> "{"EventTime":"2014-08-24T09:44:46-0400","URI":"  
> [http://ME/rest/venue/ME/hours/2014-08-24\](http://ME/rest/venue/ME/hours/2014-08-24%5C)  
> ","uri\_payload":{"value":[{"open":"2014-08-24T13:00:00.000+0000","close":"2014-08-24T23:00:00.000+0000","isOpen":true,"date":"2014-08-24"}],"Count":1}}\r",  
> "@version" =\> "1",  
> "@timestamp" =\> "2014-08-24T13:44:48.036Z",  
> "host" =\> "127.0.0.1:60778",  
> "type" =\> "MY\_Detail",  
> "EventTime" =\> "2014-08-24T09:44:46-0400",  
> "URI" =\> "[http://ME/rest/venue/ME//hours/2014-08-24](http://ME/rest/venue/ME//hours/2014-08-24)",  
> "uri\_payload" =\> {  
> "value" =\> [  
> [0] {  
> "open" =\> "2014-08-24T13:00:00.000+0000",  
> "close" =\> "2014-08-24T23:00:00.000+0000",  
> "isOpen" =\> true,  
> "date" =\> "2014-08-24"  
> }  
> ],  
> "Count" =\> 1,  
> "0" =\> {}  
> },  
> "MYId" =\> "ME"  
> }
> 
> * * *
> 
> When i look into Elasticsearch, the fields under URI Payload are not  
> parsed. It shows:
> 
> uri\_payload.value as the field with "  
> {"open":"2014-08-21T13:00:00.000+0000","close":"2014-08-21T23:00:00.000+0000","isOpen":true,"date":"2014-08-21"}"
> 
> How can I get all the parsed values as fields in elasticsearch? In my  
> example, fields Open, Close, IsOpen. Initially I thought Logstash was not  
> parsing all the json, but looking at the debug it is.
> 
> Thank you,
> 
> Chris

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/fe60df4d-cd36-43c9-a08c-7213abc2dd18%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/fe60df4d-cd36-43c9-a08c-7213abc2dd18%40googlegroups.com).  
For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

---

<div class="post-metadata">

**Author:** ![Didjit](https://avatars.discourse-cdn.com/v4/letter/d/58f4c7/32.png) [@Didjit](https://discuss.elastic.co/u/Didjit)\
**Post date:** [August 24, 2014, 2:32pm UTC](https://discuss.elastic.co/t/json-data-not-getting-parsed-when-sent-to-elasticsearch/19424/3 "2014-08-24T14:32:23Z")

</div>

Pretty simple (below). . I just added to json codec and tried again and  
received the same results. Thank you!

elasticsearch {  
host =\> localhost  
cluster =\> cjceswin  
node\_name =\> cjcnode  
codec =\> json  
index =\> "logstash-dwhse-%{+YYYY.MM.dd}"  
workers =\> 3  
}

}

On Sunday, August 24, 2014 10:11:44 AM UTC-4, moshe zada wrote:

> what is your logstash configuration?  
> did you tried the json codec [http://logstash.net/docs/1.4.2/codecs/json](http://logstash.net/docs/1.4.2/codecs/json)?
> 
> On Sunday, August 24, 2014 4:54:08 PM UTC+3, Didjit wrote:
> 
> > Hi,
> > 
> > The following is a debug from Logstash:
> > 
> > {  
> > "message" =\>  
> > "{"EventTime":"2014-08-24T09:44:46-0400","URI":"  
> > [http://ME/rest/venue/ME/hours/2014-08-24\](http://ME/rest/venue/ME/hours/2014-08-24%5C)  
> > ","uri\_payload":{"value":[{"open":"2014-08-24T13:00:00.000+0000","close":"2014-08-24T23:00:00.000+0000","isOpen":true,"date":"2014-08-24"}],"Count":1}}\r",  
> > "@version" =\> "1",  
> > "@timestamp" =\> "2014-08-24T13:44:48.036Z",  
> > "host" =\> "127.0.0.1:60778",  
> > "type" =\> "MY\_Detail",  
> > "EventTime" =\> "2014-08-24T09:44:46-0400",  
> > "URI" =\> "[http://ME/rest/venue/ME//hours/2014-08-24](http://ME/rest/venue/ME//hours/2014-08-24)",  
> > "uri\_payload" =\> {  
> > "value" =\> [  
> > [0] {  
> > "open" =\> "2014-08-24T13:00:00.000+0000",  
> > "close" =\> "2014-08-24T23:00:00.000+0000",  
> > "isOpen" =\> true,  
> > "date" =\> "2014-08-24"  
> > }  
> > ],  
> > "Count" =\> 1,  
> > "0" =\> {}  
> > },  
> > "MYId" =\> "ME"  
> > }
> > 
> > * * *
> > 
> > When i look into Elasticsearch, the fields under URI Payload are not  
> > parsed. It shows:
> > 
> > uri\_payload.value as the field with "  
> > {"open":"2014-08-21T13:00:00.000+0000","close":"2014-08-21T23:00:00.000+0000","isOpen":true,"date":"2014-08-21"}"
> > 
> > How can I get all the parsed values as fields in elasticsearch? In my  
> > example, fields Open, Close, IsOpen. Initially I thought Logstash was not  
> > parsing all the json, but looking at the debug it is.
> > 
> > Thank you,
> > 
> > Chris

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/0afd4105-a521-487a-8889-4bcabee419b6%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/0afd4105-a521-487a-8889-4bcabee419b6%40googlegroups.com).  
For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

---

<div class="post-metadata">

**Author:** ![Didjit](https://avatars.discourse-cdn.com/v4/letter/d/58f4c7/32.png) [@Didjit](https://discuss.elastic.co/u/Didjit)\
**Post date:** [August 25, 2014, 4:31pm UTC](https://discuss.elastic.co/t/json-data-not-getting-parsed-when-sent-to-elasticsearch/19424/4 "2014-08-25T16:31:24Z")

</div>

bump. Anyone?  
Thank you,  
Chris

On Sunday, August 24, 2014 10:32:23 AM UTC-4, Didjit wrote:

> Pretty simple (below). . I just added to json codec and tried again and  
> received the same results. Thank you!
> 
> elasticsearch {  
> host =\> localhost  
> cluster =\> cjceswin  
> node\_name =\> cjcnode  
> codec =\> json  
> index =\> "logstash-dwhse-%{+YYYY.MM.dd}"  
> workers =\> 3  
> }
> 
> }
> 
> On Sunday, August 24, 2014 10:11:44 AM UTC-4, moshe zada wrote:
> 
> > what is your logstash configuration?  
> > did you tried the json codec [http://logstash.net/docs/1.4.2/codecs/json](http://logstash.net/docs/1.4.2/codecs/json)  
> > ?
> > 
> > On Sunday, August 24, 2014 4:54:08 PM UTC+3, Didjit wrote:
> > 
> > > Hi,
> > > 
> > > The following is a debug from Logstash:
> > > 
> > > {  
> > > "message" =\>  
> > > "{"EventTime":"2014-08-24T09:44:46-0400","URI":"  
> > > [http://ME/rest/venue/ME/hours/2014-08-24\](http://ME/rest/venue/ME/hours/2014-08-24%5C)  
> > > ","uri\_payload":{"value":[{"open":"2014-08-24T13:00:00.000+0000","close":"2014-08-24T23:00:00.000+0000","isOpen":true,"date":"2014-08-24"}],"Count":1}}\r",  
> > > "@version" =\> "1",  
> > > "@timestamp" =\> "2014-08-24T13:44:48.036Z",  
> > > "host" =\> "127.0.0.1:60778",  
> > > "type" =\> "MY\_Detail",  
> > > "EventTime" =\> "2014-08-24T09:44:46-0400",  
> > > "URI" =\> "[http://ME/rest/venue/ME//hours/2014-08-24](http://ME/rest/venue/ME//hours/2014-08-24)",  
> > > "uri\_payload" =\> {  
> > > "value" =\> [  
> > > [0] {  
> > > "open" =\> "2014-08-24T13:00:00.000+0000",  
> > > "close" =\> "2014-08-24T23:00:00.000+0000",  
> > > "isOpen" =\> true,  
> > > "date" =\> "2014-08-24"  
> > > }  
> > > ],  
> > > "Count" =\> 1,  
> > > "0" =\> {}  
> > > },  
> > > "MYId" =\> "ME"  
> > > }
> > > 
> > > * * *
> > > 
> > > When i look into Elasticsearch, the fields under URI Payload are not  
> > > parsed. It shows:
> > > 
> > > uri\_payload.value as the field with "  
> > > {"open":"2014-08-21T13:00:00.000+0000","close":"2014-08-21T23:00:00.000+0000","isOpen":true,"date":"2014-08-21"}"
> > > 
> > > How can I get all the parsed values as fields in elasticsearch? In my  
> > > example, fields Open, Close, IsOpen. Initially I thought Logstash was not  
> > > parsing all the json, but looking at the debug it is.
> > > 
> > > Thank you,
> > > 
> > > Chris

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/860ab9c6-1867-43d0-b5da-12660ac7eab0%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/860ab9c6-1867-43d0-b5da-12660ac7eab0%40googlegroups.com).  
For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

---

<div class="post-metadata">

**Author:** ![Didjit](https://avatars.discourse-cdn.com/v4/letter/d/58f4c7/32.png) [@Didjit](https://discuss.elastic.co/u/Didjit)\
**Post date:** [August 27, 2014, 5:12pm UTC](https://discuss.elastic.co/t/json-data-not-getting-parsed-when-sent-to-elasticsearch/19424/5 "2014-08-27T17:12:07Z")

</div>

FYI, I used this fine persons chunk of code(last post) in my Logstash  
filter.

> <https://stackoverflow.com/questions/22067346/logstash-indexing-json-arrays>

Sharing,

Thank you

Chris

On Monday, August 25, 2014 12:31:24 PM UTC-4, Didjit wrote:

> bump. Anyone?  
> Thank you,  
> Chris
> 
> On Sunday, August 24, 2014 10:32:23 AM UTC-4, Didjit wrote:
> 
> > Pretty simple (below). . I just added to json codec and tried again and  
> > received the same results. Thank you!
> > 
> > elasticsearch {  
> > host =\> localhost  
> > cluster =\> cjceswin  
> > node\_name =\> cjcnode  
> > codec =\> json  
> > index =\> "logstash-dwhse-%{+YYYY.MM.dd}"  
> > workers =\> 3  
> > }
> > 
> > }
> > 
> > On Sunday, August 24, 2014 10:11:44 AM UTC-4, moshe zada wrote:
> > 
> > > what is your logstash configuration?  
> > > did you tried the json codec  
> > > [http://logstash.net/docs/1.4.2/codecs/json](http://logstash.net/docs/1.4.2/codecs/json)?
> > > 
> > > On Sunday, August 24, 2014 4:54:08 PM UTC+3, Didjit wrote:
> > > 
> > > > Hi,
> > > > 
> > > > The following is a debug from Logstash:
> > > > 
> > > > {  
> > > > "message" =\>  
> > > > "{"EventTime":"2014-08-24T09:44:46-0400","URI":"  
> > > > [http://ME/rest/venue/ME/hours/2014-08-24\](http://ME/rest/venue/ME/hours/2014-08-24%5C)  
> > > > ","uri\_payload":{"value":[{"open":"2014-08-24T13:00:00.000+0000","close":"2014-08-24T23:00:00.000+0000","isOpen":true,"date":"2014-08-24"}],"Count":1}}\r",  
> > > > "@version" =\> "1",  
> > > > "@timestamp" =\> "2014-08-24T13:44:48.036Z",  
> > > > "host" =\> "127.0.0.1:60778",  
> > > > "type" =\> "MY\_Detail",  
> > > > "EventTime" =\> "2014-08-24T09:44:46-0400",  
> > > > "URI" =\> "[http://ME/rest/venue/ME//hours/2014-08-24](http://ME/rest/venue/ME//hours/2014-08-24)",  
> > > > "uri\_payload" =\> {  
> > > > "value" =\> [  
> > > > [0] {  
> > > > "open" =\> "2014-08-24T13:00:00.000+0000",  
> > > > "close" =\> "2014-08-24T23:00:00.000+0000",  
> > > > "isOpen" =\> true,  
> > > > "date" =\> "2014-08-24"  
> > > > }  
> > > > ],  
> > > > "Count" =\> 1,  
> > > > "0" =\> {}  
> > > > },  
> > > > "MYId" =\> "ME"  
> > > > }
> > > > 
> > > > * * *
> > > > 
> > > > When i look into Elasticsearch, the fields under URI Payload are not  
> > > > parsed. It shows:
> > > > 
> > > > uri\_payload.value as the field with "  
> > > > {"open":"2014-08-21T13:00:00.000+0000","close":"2014-08-21T23:00:00.000+0000","isOpen":true,"date":"2014-08-21"}"
> > > > 
> > > > How can I get all the parsed values as fields in elasticsearch? In my  
> > > > example, fields Open, Close, IsOpen. Initially I thought Logstash was not  
> > > > parsing all the json, but looking at the debug it is.
> > > > 
> > > > Thank you,
> > > > 
> > > > Chris

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/1ec009ee-5914-466a-a6e5-378ec0801625%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/1ec009ee-5914-466a-a6e5-378ec0801625%40googlegroups.com).  
For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 1:06am UTC](https://discuss.elastic.co/t/json-data-not-getting-parsed-when-sent-to-elasticsearch/19424/6 "2017-07-06T01:06:00Z")

</div>


