# JSON filter plugin explain example please

**URL:** <https://discuss.elastic.co/t/json-filter-plugin-explain-example-please/152608>\
**Category:** Logstash\
**Created:** [October 16, 2018, 8:43am UTC](https://discuss.elastic.co/t/json-filter-plugin-explain-example-please/152608 "2018-10-16T08:43:54Z")\
**Posts on this page:** 10\
**Page:** 1

<div class="post-metadata">

**Author:** ![humalog](https://avatars.discourse-cdn.com/v4/letter/h/cc9497/32.png) [@humalog](https://discuss.elastic.co/u/humalog)\
**Post date:** [October 16, 2018, 8:43am UTC](https://discuss.elastic.co/t/json-filter-plugin-explain-example-please/152608/1 "2018-10-16T08:43:55Z")

</div>

One moment, i need to correct my post. I converted the file into json. Is it easier to work with xml or json files or is it the same difficulty?

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [October 16, 2018, 8:47am UTC](https://discuss.elastic.co/t/json-filter-plugin-explain-example-please/152608/2 "2018-10-16T08:47:45Z")

</div>

That is not JSON, that is XML. Therefore use the [xml filter plugin](https://www.elastic.co/guide/en/logstash/6.4/plugins-filters-xml.html).

---

<div class="post-metadata">

**Author:** ![humalog](https://avatars.discourse-cdn.com/v4/letter/h/cc9497/32.png) [@humalog](https://discuss.elastic.co/u/humalog)\
**Post date:** [October 16, 2018, 9:06am UTC](https://discuss.elastic.co/t/json-filter-plugin-explain-example-please/152608/3 "2018-10-16T09:06:07Z")

</div>

I got JSON file looks like this:

{  
"NessusClientData\_v2": {  
"Policy": {  
"policyName": "Arena Standard",  
"Preferences": {  
"ServerPreferences": {  
"preference": [  
{ "name": "max\_simult\_tcp\_sessions" },  
{  
"name": "use\_mac\_addr",  
"value": "no"  
},  
{  
"name": "sc\_version",  
"value": "5.6.1"  
},  
......  
{  
"-port": "80",  
"-svc\_name": "www",  
"-protocol": "tcp",  
"-severity": "0",  
"-pluginID": "11219",  
"-pluginName": "bli",  
"-pluginFamily": "bla",  
"description": "blub",  
"fname": "123  
},  
{  
"-port": "443",  
"-svc\_name": "www",  
"-protocol": "tcp",  
"-severity": "0",  
"-pluginID": "11219",  
"-pluginName": "bliii",  
"-pluginFamily": "blaaa",  
"description": "blub"  
}  
]  
}  
]  
}  
}  
}

As result i want every block in one event:

port: "80"  
svc\_name: "www"  
protocol: "tcp"  
severity: "0"  
pluginID: "11219"  
pluginName": "bli"  
pluginFamily": "bla"  
description": "blub"  
fname": "123"

I tried to work with multilines. I got one event with all entries of the file and i didn't know how to split this up to get more events. Can someone give a small example or link where it's explained a bit?

My logstash configs looks like this atm:

```auto
input {
  file {
        path => "/home/vagrant/test.json"
        start_position => "beginning"
        type => "123"
  }
}

filter {
  if [message] == "123" {
     json {
       source => "message"
       skip_on_invalid_json => "true"

    }
  }
}

output {
  elasticsearch {
    index => "123"
    hosts => "127.0.0.1"
  }
}
```

---

<div class="post-metadata">

**Author:** ![OphyTe](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ophyte/32/36444_2.png) [@OphyTe](https://discuss.elastic.co/u/OphyTe)\
**Post date:** [October 16, 2018, 9:10am UTC](https://discuss.elastic.co/t/json-filter-plugin-explain-example-please/152608/4 "2018-10-16T09:10:55Z")

</div>

I would do it with the [ruby plugin filter](https://www.elastic.co/guide/en/logstash/current/plugins-filters-ruby.html#_using_a_ruby_script_file).

Once you have your entire json file in one single event, you have to loop on your items in your ruby script and put them in separate event array fields.

---

<div class="post-metadata">

**Author:** ![humalog](https://avatars.discourse-cdn.com/v4/letter/h/cc9497/32.png) [@humalog](https://discuss.elastic.co/u/humalog)\
**Post date:** [October 16, 2018, 9:16am UTC](https://discuss.elastic.co/t/json-filter-plugin-explain-example-please/152608/5 "2018-10-16T09:16:13Z")

</div>

When i take a look at your link, i don't know how to start to get my result. Is there somewhere an example where i can learn it with my issue?

---

<div class="post-metadata">

**Author:** ![OphyTe](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ophyte/32/36444_2.png) [@OphyTe](https://discuss.elastic.co/u/OphyTe)\
**Post date:** [October 16, 2018, 9:53am UTC](https://discuss.elastic.co/t/json-filter-plugin-explain-example-please/152608/6 "2018-10-16T09:53:57Z")

</div>

You can begin with that [http://bfy.tw/KNhK](http://bfy.tw/KNhK) and if you need help on your specific implementation we'll see.

By the way, I'm not sure your json file is valid because your block elements don't seem to have a name ... Are they in an array structure ? If not, I don't know how you gonna loop on them 🤔

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [October 16, 2018, 10:00am UTC](https://discuss.elastic.co/t/json-filter-plugin-explain-example-please/152608/7 "2018-10-16T10:00:42Z")

</div>

Use a [multiline codec](https://www.elastic.co/guide/en/logstash/6.4/plugins-codecs-multiline.html) to gather the full event into one message, then apply a [json filter](https://www.elastic.co/guide/en/logstash/6.4/plugins-filters-json.html). To split this into multiple events, you might be able to use a [split filter](https://www.elastic.co/guide/en/logstash/6.4/plugins-filters-split.html) on the `preference` field. If that does not work for you, you may need a ruby filter.

---

<div class="post-metadata">

**Author:** ![humalog](https://avatars.discourse-cdn.com/v4/letter/h/cc9497/32.png) [@humalog](https://discuss.elastic.co/u/humalog)\
**Post date:** [October 16, 2018, 10:02am UTC](https://discuss.elastic.co/t/json-filter-plugin-explain-example-please/152608/8 "2018-10-16T10:02:31Z")

</div>

originally it looks like this

```auto
"ReportItem": [
            {
              "-port": "0",
              "-svc_name": "general",
              "-protocol": "tcp",
              "-severity": "0",
              "-pluginID": "117886",
              "-pluginName": "Local Checks Not Enabled (info)",
              "-pluginFamily": "Settings",
              "description": "bla",
              "fname": "bla",
              "plugin_modification_date": "bla",
              "plugin_name": "bla",
              "plugin_publication_date": "2016/10/02",
              "plugin_type": "summary",
              "risk_factor": "None",
              "script_version": "1.2",
              "solution": "n/a",
              "synopsis": "bla",
              "plugin_output": "bla"
},
            {
              "-port": "0",
              "-svc_name": "general",
              "-protocol": "tcp",
              "-severity": "0",
              "-pluginID": "19506",
             .....
```

---

<div class="post-metadata">

**Author:** ![humalog](https://avatars.discourse-cdn.com/v4/letter/h/cc9497/32.png) [@humalog](https://discuss.elastic.co/u/humalog)\
**Post date:** [October 16, 2018, 10:03am UTC](https://discuss.elastic.co/t/json-filter-plugin-explain-example-please/152608/9 "2018-10-16T10:03:21Z")

</div>

ok i will try that, thx

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 13, 2018, 10:29am UTC](https://discuss.elastic.co/t/json-filter-plugin-explain-example-please/152608/11 "2018-11-13T10:29:21Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
