# Json processor Parsing Issue Workaround

**URL:** <https://discuss.elastic.co/t/json-processor-parsing-issue-workaround/351208>\
**Category:** Elastic Agent\
**Created:** [January 16, 2024, 8:18pm UTC](https://discuss.elastic.co/t/json-processor-parsing-issue-workaround/351208 "2024-01-16T20:18:15Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![vishnu.a](https://avatars.discourse-cdn.com/v4/letter/v/9e8a1a/32.png) [@vishnu.a](https://discuss.elastic.co/u/vishnu.a)\
**Post date:** [January 16, 2024, 8:18pm UTC](https://discuss.elastic.co/t/json-processor-parsing-issue-workaround/351208/1 "2024-01-16T20:18:15Z")

</div>

Hello I'm trying to parse a field using the Json processor. the input is similar to the following:

```auto
{"json": {
\"field1\":\"...\",
\"field2\":\"...\",
... ,
\"Message\":\"<message here>\",
... ,
\"fieldn\":\"...\"
}

```

The issue is that in the message field, every now and then, the following example will break the entire processor:

```auto
... Command Line:\"c:/ProgramData...

```

I'm sure its because of the \<"\> that signals the end of the field.

Is there a work around within the current json processor, or am I better off using a Gsub to a different delimiter and then using the KV processor?

---

<div class="post-metadata">

**Author:** ![yago82](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yago82/32/97755_2.png) [@yago82](https://discuss.elastic.co/u/yago82)\
**Post date:** [January 17, 2024, 10:53am UTC](https://discuss.elastic.co/t/json-processor-parsing-issue-workaround/351208/2 "2024-01-17T10:53:49Z")

</div>

> [@vishnu.a](#):
>
> Hello I'm trying to parse a field using the Json processor. the input is similar to the following:
> 
> ```auto
> {"json": {
> \"field1\":\"...\",
> \"field2\":\"...\",
> ... ,
> \"Message\":\"<message here>\",
> ... ,
> \"fieldn\":\"...\"
> }
> 
> ```
> 
> The issue is that in the message field, every now and then, the following example will break the entire processor:
> 
> ```auto
> ... Command Line:\"c:/ProgramData...
> 
> ```
> 
> I'm sure its because of the \<"\> that signals the end of the field.
> 
> Is there a work around within the current json processor, or am I better off using a Gsub to a different delimiter and then using the KV processor?

Hi,

One way to handle this is to use the `gsub` processor before the `json` processor in your ingest pipeline. The `gsub` processor can replace the escaped quotes (`\"` ) within the "Message" field with a different character or sequence of characters that won't interfere with JSON parsing.

[Gsub processor | Elasticsearch Guide [8.11] | Elastic](https://www.elastic.co/guide/en/elasticsearch/reference/current/gsub-processor.html)

Regards

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 14, 2024, 10:54am UTC](https://discuss.elastic.co/t/json-processor-parsing-issue-workaround/351208/3 "2024-02-14T10:54:08Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
