# Json { source =\> "message" } not parsing all of it

**URL:** <https://discuss.elastic.co/t/json-source-message-not-parsing-all-of-it/297430>\
**Category:** Logstash\
**Created:** [February 17, 2022, 12:49am UTC](https://discuss.elastic.co/t/json-source-message-not-parsing-all-of-it/297430 "2022-02-17T00:49:36Z")\
**Posts on this page:** 20\
**Page:** 1

<div class="post-metadata">

**Author:** ![itschobot](https://avatars.discourse-cdn.com/v4/letter/i/439d5e/32.png) [@itschobot](https://discuss.elastic.co/u/itschobot)\
**Post date:** [February 17, 2022, 12:49am UTC](https://discuss.elastic.co/t/json-source-message-not-parsing-all-of-it/297430/1 "2022-02-17T00:49:36Z")

</div>

Hello, I'm new to Logstash and was wondering if someone could help with my filter and how can I parse the rest of my json fields the intent is to bring out the other fields in "message" such that I can map them to ECS:

here is what I have for my filter:

```auto
filter {
  if "redacted_platform" in [ls-source] {
    json {
      source => "message"
    }
    json {
      source => "message"
    }

    }
  }

```

here is what the result is coming out as the result:

```auto
       "message" => "<165>Feb 15 00:0000 redacted_platform.net.Example.com redacted_platform {\"model\":{\"description\":\"Test model used for testing alerting configuration.\",\"created\":{\"by\":\"System\"},\"edited\":{\"by\":\"Nobody\"},\"name\":\"Unrestricted Test Model\",\"priority\":5},\"device\":{\"ip\":\"0.1.2.3\",\"hostname\":\"test-device.example.com\",\"macaddress\":\"00:11:22:33:44:55\",\"vendor\":\"Test Vendor\",\"label\":\"Test Device\"},\"triggeredComponents\":[{\"metric\":{\"label\":\"Test Metric\"},\"triggeredFilters\":[{\"comparatorType\":\"display\",\"filterType\":\"Test Metric Filter\",\"trigger\":{\"value\":\"Test filter value\"}}]}],\"breachUrl\":\"\",\"pbid\":123,\"score\":1,\"creationTime\":123456,\"time\":123456}",
          "host" => "hostname.example.com",
      "log_type" => "redacted_platform",
    "@timestamp" => 2022-02-15 blah blah blah,
          "type" => "redacted_platform",
        "fields" => {
        "event_type" => "redacted_platform"
    },
     "ls-source" => "redacted_platform",
          "tags" => [
        [0] "_jsonparsefailure"
    ],
          "port" => 12345,
      "@version" => "1",
           "ecs" => {
        "version" => "1.2.3"
    },
        "origin" => "redacted_platform",
         "input" => {
        "type" => "log"
    },
         "agent" => {
                "name" => "123b456c",
                  "id" => "123b456c",
             "version" => "1.2.3",
            "hostname" => "123b456c",
                "type" => "filebeat",
        "ephemeral_id" => "123b456c"
    },
           "log" => {
        "offset" => 0,
          "file" => {
            "path" => "/var/log/logstash/redacted_platform/test.json"
        }
    }
}

```

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [February 17, 2022, 1:46am UTC](https://discuss.elastic.co/t/json-source-message-not-parsing-all-of-it/297430/2 "2022-02-17T01:46:45Z")

</div>

You need to remove the prefix from [message]. I would suggest something like [this](https://discuss.elastic.co/t/parse-json-format-logagregator-logs-in-logstash/182952/4), but if you do not care about the prefix it could be something as simple as

```
mutate { gsub => ["message", ".*{", "{"] }
```

---

<div class="post-metadata">

**Author:** ![itschobot](https://avatars.discourse-cdn.com/v4/letter/i/439d5e/32.png) [@itschobot](https://discuss.elastic.co/u/itschobot)\
**Post date:** [February 17, 2022, 9:44pm UTC](https://discuss.elastic.co/t/json-source-message-not-parsing-all-of-it/297430/3 "2022-02-17T21:44:13Z")

</div>

Thanks I'll be sure to try both those solutions out today!

what if i just wanted to remove below from [message]:

```auto
<165>Feb 15 00:0000 redacted_platform.net.Example.com redacted_platform

```

then do this a 3rd time:

```auto
   json {
      source => "message"
    }

```

would that work as well?  
would that be sloppy and not best practice?

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [February 17, 2022, 9:49pm UTC](https://discuss.elastic.co/t/json-source-message-not-parsing-all-of-it/297430/4 "2022-02-17T21:49:46Z")

</div>

> [@itschobot](#):
>
> what if i just wanted to remove below from [message]

That's what the mutate+gsub I suggested would do. Then do the third json filter.

---

<div class="post-metadata">

**Author:** ![itschobot](https://avatars.discourse-cdn.com/v4/letter/i/439d5e/32.png) [@itschobot](https://discuss.elastic.co/u/itschobot)\
**Post date:** [February 17, 2022, 9:59pm UTC](https://discuss.elastic.co/t/json-source-message-not-parsing-all-of-it/297430/5 "2022-02-17T21:59:01Z")

</div>

> [@Badger](#):
>
> hen do the third json filter.

will do thank you so much! you people are so much help here!

---

<div class="post-metadata">

**Author:** ![itschobot](https://avatars.discourse-cdn.com/v4/letter/i/439d5e/32.png) [@itschobot](https://discuss.elastic.co/u/itschobot)\
**Post date:** [February 18, 2022, 10:34pm UTC](https://discuss.elastic.co/t/json-source-message-not-parsing-all-of-it/297430/6 "2022-02-18T22:34:42Z")

</div>

If i did care about the prefix and wanted to parse out that data would it be the same thing as what you linked?

```auto
dissect { mapping => { "message" => "<%{pri}>%{f1} %{ts} [%{f2}] %{f3} ,%{[@metadata][json]}" } }
json { source => "[@metadata][json]" }

```

my current result came out with more back slashes

```auto
[2022-02-15T some time][WARN][org.logstash.dissect.Dissector][redacted_platform][123a456b789c] Dissector mapping, pattern not found {"field"=>"message", "pattern"=>"{pri}>%{f1} %{ts} [%{f2}] %{f3} ,%{[@metadata][json]}", "event"=>{"@version"=>"1", "ls-source"=>"redacted_platform", "message"=>"{\"host\":{\"name\":\"123a456b789c\"},\"@version\":\"1\",\"@timestamp\":\"2022-02-15T some time Z\",\"agent\":{\"version\":\"1.2.3\",\"name\":\"123a456b789c\",\"hostname\":\"12345abc\",\"type\":\"filebeat\",\"ephemeral_id\":\"123a456b789c\",\"id\":\"123a456b789c\"},\"log\":{\"offset\":123,\"file\":{\"path\":\"/var/log/logstash/redacted_platform.json\"}},\"fields\":{\"event_type\":\"redacted_platform\"},\"ecs\":{\"version\":\"1.2.3\"},\"log_type\":\"redacted_platform\",\"tags\":[\"some_company\",\"beats_input_codec_plain_applied\"],\"input\":{\"type\":\"log\"},\"message\":\"{\\\"type\\\":\\\"redacted_platform\\\",\\\"host\\\":\\\"sample.id.some_company\\\",\\\"port\\\":12345,\\\"origin\\\":\\\"redacted_platform\\\",\\\"@version\\\":\\\"1\\\",\\\"tags\\\":[\\\"_jsonparsefailure\\\"],\\\"@timestamp\\\":\\\"2022-02-15Tsome timeZ\\\",\\\"message\\\":\\\"<165>Feb 15 redacted_platform-01.example.some_company redacted_platform {\\\\\\\"model\\\\\\\":{\\\\\\\"description\\\\\\\":\\\\\\\"Test model used for testing alerting configuration.\\\\\\\",\\\\\\\"created\\\\\\\":{\\\\\\\"by\\\\\\\":\\\\\\\"System\\\\\\\"},\\\\\\\"edited\\\\\\\":{\\\\\\\"by\\\\\\\":\\\\\\\"Nobody\\\\\\\"},\\\\\\\"name\\\\\\\":\\\\\\\"Unrestricted Test Model\\\\\\\",\\\\\\\"priority\\\\\\\":5},\\\\\\\"device\\\\\\\":{\\\\\\\"ip\\\\\\\":\\\\\\\"0.1.2.3\\\\\\\",\\\\\\\"hostname\\\\\\\":\\\\\\\"test-device.example.com\\\\\\\",\\\\\\\"macaddress\\\\\\\":\\\\\\\"00:11:22:33:44:55\\\\\\\",\\\\\\\"vendor\\\\\\\":\\\\\\\"Test Vendor\\\\\\\",\\\\\\\"label\\\\\\\":\\\\\\\"Test Device\\\\\\\"},\\\\\\\"triggeredComponents\\\\\\\":[{\\\\\\\"metric\\\\\\\":{\\\\\\\"label\\\\\\\":\\\\\\\"Test Metric\\\\\\\"},\\\\\\\"triggeredFilters\\\\\\\":[{\\\\\\\"comparatorType\\\\\\\":\\\\\\\"display\\\\\\\",\\\\\\\"filterType\\\\\\\":\\\\\\\"Test Metric Filter\\\\\\\",\\\\\\\"trigger\\\\\\\":{\\\\\\\"value\\\\\\\":\\\\\\\"Test filter value\\\\\\\"}}]}],\\\\\\\"breachUrl\\\\\\\":\\\\\\\"\\\\\\\",\\\\\\\"pbid\\\\\\\":123,\\\\\\\"score\\\\\\\":1,\\\\\\\"creationTime\\\\\\\":12345,\\\\\\\"time\\\\\\\":12345}\\\"}\"}", "@timestamp"=>2022-02-15, "tags"=>["_dissectfailure"]}}
[2022-02-15T][WARN][logstash.filters.json][redacted_platform][1234a456b789c] Error parsing json {:source=>"message", :raw=>"{\"value\":\"Test filter value\"}}]}],\"breachUrl\":\"\",\"pbid\":123,\"score\":1,\"creationTime\":12345,\"time\":`12345}", :exception=>#<LogStash::Json::ParserError: Unexpected close marker '}': expected ']' (for root starting at [Source: (byte[])"{"value":"Test filter value"}}]}],"breachUrl":"","pbid":123,"score":1,"creationTime":12345,"time":12345}"; line: 1, column: 0])
 at [Source: (byte[])"{"value":"Test filter value"}}]}],"breachUrl":"","pbid":123,"score":1,"creationTime":12345,"time":12345}"; line: 1, column: 31]>}
{
      "@version" => "1",
         "agent" => {
                "name" => "123b456c",
            "hostname" => "123b456c",
                "type" => "filebeat",
                  "id" => "123b456c",
             "version" => "1.2.3",
        "ephemeral_id" => "123b456c"
    },
        "origin" => "redacted_platform",
           "ecs" => {
        "version" => "1.2.3"
    },
      "log_type" => "redacted_platform",
       "message" => "{\"value\":\"Test filter value\"}}]}],\"breachUrl\":\"\",\"pbid\":123,\"score\":1,\"creationTime\":12345,\"time\":12345}",
     "ls-source" => "redacted_platform",
           "log" => {
          "file" => {
            "path" => "/var/log/logstash/redacted_platform.json"
        },
        "offset" => 123
    },
          "port" => 123,
          "type" => "redacted_platform",
          "tags" => [
        [0] "_jsonparsefailure"
    ],
         "input" => {
        "type" => "log"
    },
          "host" => "sample.id.some_company",
        "fields" => {
        "event_type" => "redacted_platform"
    },
    "@timestamp" => 2022-02-15 it's 5'oclock somewhere
}

```

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [February 18, 2022, 10:51pm UTC](https://discuss.elastic.co/t/json-source-message-not-parsing-all-of-it/297430/7 "2022-02-18T22:51:39Z")

</div>

> [@itschobot](#):
>
> `"<165>Feb 15 00:0000 redacted_platform.net.Example.com redacted_platform {\"model\"`

I would suggest

```
dissect { mapping => { "message" => "<%{pri}>%{ts} %{+ts} %{+ts} %{h} %{p} %{[@metadata][json]}" } }

```

---

<div class="post-metadata">

**Author:** ![itschobot](https://avatars.discourse-cdn.com/v4/letter/i/439d5e/32.png) [@itschobot](https://discuss.elastic.co/u/itschobot)\
**Post date:** [February 18, 2022, 11:33pm UTC](https://discuss.elastic.co/t/json-source-message-not-parsing-all-of-it/297430/8 "2022-02-18T23:33:45Z")

</div>

> [@Badger](#):
>
> `dissect { mapping => { "message" => "<%{pri}>%{ts} %{+ts} %{+ts} %{h} %{p} %{[@metadata`

would my filter look like this?

```auto
filter {
  if "some_platform" in [ls-source] {
    json {
      source => "message"
    }
    json {
      source => "message"
    }
    dissect { mapping => { "message" => "<%{pri}>%{ts} %{+ts} %{+ts} %{h} %{p} %{[@metadata][json]}" } }
    
    json {
      source => "message"
    }
 

    }
  }

```

if so i'm still getting jsonparsefailure and dissectfailure.

is my formatting wrong?

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [February 19, 2022, 12:10am UTC](https://discuss.elastic.co/t/json-source-message-not-parsing-all-of-it/297430/9 "2022-02-19T00:10:08Z")

</div>

The third json filter should have `source => "[@metadata][json]"`. But at the moment the third duplicates the second, so that must be failing.

---

<div class="post-metadata">

**Author:** ![itschobot](https://avatars.discourse-cdn.com/v4/letter/i/439d5e/32.png) [@itschobot](https://discuss.elastic.co/u/itschobot)\
**Post date:** [February 19, 2022, 12:47am UTC](https://discuss.elastic.co/t/json-source-message-not-parsing-all-of-it/297430/10 "2022-02-19T00:47:36Z")

</div>

> [@Badger](#):
>
> source =\> "[@metadata][json]

```auto
filter {
  if "darktrace" in [ls-source] {
    json {
      source => "message"
    }
    json {
      source => "[@metadata][json]"
    }
    dissect { mapping => { "message" => "<%{pri}>%{ts} %{+ts} %{+ts} %{h} %{p} %{[@metadata][json]}" } }
 

    }
  }

```

so something like this?

yeah it's still failing. would it help if I posted the output again?

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [February 19, 2022, 1:24am UTC](https://discuss.elastic.co/t/json-source-message-not-parsing-all-of-it/297430/11 "2022-02-19T01:24:29Z")

</div>

No, I am saying

```
json { source => "message" }
json { source => "message" }
dissect { mapping => { "message" => "<%{pri}>%{ts} %{+ts} %{+ts} %{h} %{p} %{[@metadata][json]}" } }
json { source => "[@metadata][json]" }
```

---

<div class="post-metadata">

**Author:** ![itschobot](https://avatars.discourse-cdn.com/v4/letter/i/439d5e/32.png) [@itschobot](https://discuss.elastic.co/u/itschobot)\
**Post date:** [February 22, 2022, 7:22pm UTC](https://discuss.elastic.co/t/json-source-message-not-parsing-all-of-it/297430/12 "2022-02-22T19:22:45Z")

</div>

Hello, just circling back to this to make sure i'm understanding so far is good,  
the code below takes out the prefix but parsed out the json correct?

```auto
json { source => "message" }
json { source => "message" }
mutate { gsub => ["message", ".*{", "{"] }
json { source => "message" }

```

the intent of the code block is that the teal color portion is parsed and the red lined text gone:  
 ![image](https://us1.discourse-cdn.com/elastic/original/3X/f/7/f764e2aeede377f12624f1f1c234d0809027dd91.png)

and if I wanted the prefix that is red lined out in the picture above I would want to do the code block at the bottom correct?:

```auto
json { source => "message" }
json { source => "message" }
dissect { mapping => { "message" => "<%{pri}>%{ts} %{+ts} %{+ts} %{h} %{p} %{[@metadata][json]}" } }
json { source => "[@metadata][json]" }

```

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [February 22, 2022, 7:29pm UTC](https://discuss.elastic.co/t/json-source-message-not-parsing-all-of-it/297430/13 "2022-02-22T19:29:22Z")

</div>

I think both are correct.

---

<div class="post-metadata">

**Author:** ![itschobot](https://avatars.discourse-cdn.com/v4/letter/i/439d5e/32.png) [@itschobot](https://discuss.elastic.co/u/itschobot)\
**Post date:** [February 22, 2022, 7:39pm UTC](https://discuss.elastic.co/t/json-source-message-not-parsing-all-of-it/297430/14 "2022-02-22T19:39:15Z")

</div>

Sounds good, what seems to be happening as of a result for the gsub solution doesn't seem to match the intent.

here is what i'm getting as a result:

```auto
"message" => "{\"value\":\"Test filter value\"}}]}],\"breachUrl\":\"\",\"pbid\":123,\"score\":1,\"creationTime\":123456,\"time\":123456}",
           "log" => {
        "offset" => 5232,
          "file" => {
            "path" => "/var/log/logstash/redacted_platform/redacted_platform-2022-02-22.json"
        }
    },
    "@timestamp" => 2022-02-22T19:30:01.547Z,
          "type" => "redacted_platform",
         "input" => {
        "type" => "log"
    },
          "port" => 4321,
          "tags" => [
        [0] "_jsonparsefailure"
    ],
      "@version" => "1",
          "host" => "example_host.com",
      "log_type" => "redacted_platform",
        "fields" => {
        "event_type" => "redacted_platform"
    },
        "origin" => "redacted_platform",
     "ls-source" => "redacted_platform",
           "ecs" => {
        "version" => "1.11.0"
    }
}

```

based off the result above and comparing it to the picture the fields that should have been parsed but instead have disappeared. Is there something we are missing? it get's rid of the prefix but I don't see the other fields leading up to "value":"Test filter value"}}]}]

![image](https://us1.discourse-cdn.com/elastic/original/3X/c/9/c982efd57180b89c3dd870e7be62e0257b5730bf.png)

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [February 22, 2022, 7:47pm UTC](https://discuss.elastic.co/t/json-source-message-not-parsing-all-of-it/297430/15 "2022-02-22T19:47:22Z")

</div>

> [@itschobot](#):
>
> `mutate { gsub => ["message", ".*{", "{"] }`

Try changing that to

```
mutate { gsub => ["message", "^[^{]+", "" ] }

```

---

<div class="post-metadata">

**Author:** ![itschobot](https://avatars.discourse-cdn.com/v4/letter/i/439d5e/32.png) [@itschobot](https://discuss.elastic.co/u/itschobot)\
**Post date:** [February 22, 2022, 8:00pm UTC](https://discuss.elastic.co/t/json-source-message-not-parsing-all-of-it/297430/17 "2022-02-22T20:00:35Z")

</div>

Looks like it worked, is there anything that sticks out to you that I may have missed?  
It looks like now I can convert these fields to ECS now & delete "message" ! 🙂

```auto
"message" => "{\"model\":{\"description\":\"Test model used for testing alerting configuration.\",\"created\":{\"by\":\"System\"},\"edited\":{\"by\":\"Nobody\"},\"name\":\"Unrestricted Test Model\",\"priority\":5},\"device\":{\"ip\":\"0.1.2.3\",\"hostname\":\"test-device.example.com\",\"macaddress\":\"00:11:22:33:44:55\",\"vendor\":\"Test Vendor\",\"label\":\"Test Device\"},\"triggeredComponents\":[{\"metric\":{\"label\":\"Test Metric\"},\"triggeredFilters\":[{\"comparatorType\":\"display\",\"filterType\":\"Test Metric Filter\",\"trigger\":{\"value\":\"Test filter value\"}}]}],\"breachUrl\":\"\",\"pbid\":123,\"score\":1,\"creationTime\":123456,\"time\":123456}",
"creationTime" => 123456,
      "fields" => {
"event_type" => "redacted_platform"
},
        "pbid" => 123,
"triggeredComponents" => [
[0] {
           "metric" => {
     "label" => "Test Metric"
 },
 "triggeredFilters" => [
     [0] {
             "filterType" => "Test Metric Filter",
         "comparatorType" => "display",
                "trigger" => {
             "value" => "Test filter value"
         }
     }
 ]
}
],
        "time" => 123456,
        "port" => 123,
  "@timestamp" => 2022-02-22T19:49:42.855Z,
    "log_type" => "redacted_platform",
       "score" => 1,
   "ls-source" => "redacted_platform",
   "breachUrl" => "",
      "device" => {
  "label" => "Test Device",
"hostname" => "test-device.example.com",
 "vendor" => "Test Vendor",
     "ip" => "0.1.2.3",
"macaddress" => "00:11:22:33:44:55"
},
       "agent" => {
     "name" => "12a34b56c",
"ephemeral_id" => "12a34b56c",
       "id" => "12a34b56c",
  "version" => "1.2.3",
 "hostname" => "12a34b56c",
     "type" => "filebeat"
},
        "type" => "redacted_platform",
        "tags" => [
[0] "_jsonparsefailure"
],
         "ecs" => {
"version" => "1.11.0"
},
       "input" => {
"type" => "log"
},
         "log" => {
"file" => {
 "path" => "/var/log/logstash/redacted_platform/redacted_platform-2022-02-22.json"
},
"offset" => 123
},
    "@version" => "1",
      "origin" => "redacted_platform",
        "host" => "example_host.com",
       "model" => {
"description" => "Test model used for testing alerting configuration.",
 "created" => {
 "by" => "System"
},
  "edited" => {
 "by" => "Nobody"
},
    "name" => "Unrestricted Test Model",
"priority" => 5
}
}

```

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [February 22, 2022, 8:15pm UTC](https://discuss.elastic.co/t/json-source-message-not-parsing-all-of-it/297430/18 "2022-02-22T20:15:36Z")

</div>

Looks like you are set.

---

<div class="post-metadata">

**Author:** ![itschobot](https://avatars.discourse-cdn.com/v4/letter/i/439d5e/32.png) [@itschobot](https://discuss.elastic.co/u/itschobot)\
**Post date:** [February 22, 2022, 8:17pm UTC](https://discuss.elastic.co/t/json-source-message-not-parsing-all-of-it/297430/19 "2022-02-22T20:17:00Z")

</div>

TYSM you've been so much help! One last question: would a 4th json { source =\> "message" } be needed or is that unnecessary?

---

<div class="post-metadata">

**Author:** ![itschobot](https://avatars.discourse-cdn.com/v4/letter/i/439d5e/32.png) [@itschobot](https://discuss.elastic.co/u/itschobot)\
**Post date:** [February 22, 2022, 8:33pm UTC](https://discuss.elastic.co/t/json-source-message-not-parsing-all-of-it/297430/20 "2022-02-22T20:33:52Z")

</div>

Here are the current results with the 4th json source message added:

```auto
{
    "triggeredComponents" => [
        [0] {
                      "metric" => {
                "label" => "Test Metric"
            },
            "triggeredFilters" => [
                [0] {
                    "comparatorType" => "display",
                           "trigger" => {
                        "value" => "Test filter value"
                    },
                        "filterType" => "Test Metric Filter"
                }
            ]
        }
    ],
             "@timestamp" => 2022-02-22T20:11:51.675Z,
                  "score" => 1,
                   "pbid" => 123,
                    "ecs" => {
        "version" => "1.11.0"
    },
               "log_type" => "redacted_platform",
                   "tags" => [
        [0] "_jsonparsefailure"
    ],
                   "type" => "redacted_platform",
                   "port" => 123456,
                 "origin" => "redacted_platform",
              "ls-source" => "redacted_platform",
              "breachUrl" => "",
                   "time" => 123456,
                   "host" => "example_host.com",
                  "input" => {
        "type" => "log"
    },
                  "model" => {
           "priority" => 5,
            "created" => {
            "by" => "System"
        },
             "edited" => {
            "by" => "Nobody"
        },
               "name" => "Unrestricted Test Model",
        "description" => "Test model used for testing alerting configuration."
    },
                  "agent" => {
             "version" => "123456",
                "name" => "123456",
                "type" => "filebeat",
        "ephemeral_id" => "123456",
                  "id" => "123456",
            "hostname" => "123456"
    },
               "@version" => "1",
                    "log" => {
          "file" => {
            "path" => "/var/log/logstash/redacted_platform/redacted_platform-2022-02-22.json"
        },
        "offset" => 123456
    },
           "creationTime" => 123456,
                 "device" => {
        "macaddress" => "00:11:22:33:44:55",
          "hostname" => "test-device.example.com",
            "vendor" => "Test Vendor",
                "ip" => "0.1.2.3",
             "label" => "Test Device"
    },
                "message" => "{\"model\":{\"description\":\"Test model used for testing alerting configuration.\",\"created\":{\"by\":\"System\"},\"edited\":{\"by\":\"Nobody\"},\"name\":\"Unrestricted Test Model\",\"priority\":5},\"device\":{\"ip\":\"0.1.2.3\",\"hostname\":\"test-device.example.com\",\"macaddress\":\"00:11:22:33:44:55\",\"vendor\":\"Test Vendor\",\"label\":\"Test Device\"},\"triggeredComponents\":[{\"metric\":{\"label\":\"Test Metric\"},\"triggeredFilters\":[{\"comparatorType\":\"display\",\"filterType\":\"Test Metric Filter\",\"trigger\":{\"value\":\"Test filter value\"}}]}],\"breachUrl\":\"\",\"pbid\":123,\"score\":1,\"creationTime\":123456,\"time\":123456}",
                 "fields" => {
        "event_type" => "redacted_platform"
    }
}

```

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [February 22, 2022, 8:36pm UTC](https://discuss.elastic.co/t/json-source-message-not-parsing-all-of-it/297430/21 "2022-02-22T20:36:45Z")

</div>

A 4th json filter would only be needed if the previous json filter had overwritten the [message] field because there was nested JSON.

[Next page](https://discuss.elastic.co/t/json-source-message-not-parsing-all-of-it/297430.md?page=2)
