# Keep hierarchy in json data

**URL:** <https://discuss.elastic.co/t/keep-hierarchy-in-json-data/31881>\
**Category:** Logstash\
**Created:** [October 8, 2015, 8:38pm UTC](https://discuss.elastic.co/t/keep-hierarchy-in-json-data/31881 "2015-10-08T20:38:54Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![Ducheol\_Kim](https://avatars.discourse-cdn.com/v4/letter/d/8edcca/32.png) [@Ducheol\_Kim](https://discuss.elastic.co/u/Ducheol_Kim)\
**Post date:** [October 8, 2015, 8:38pm UTC](https://discuss.elastic.co/t/keep-hierarchy-in-json-data/31881/1 "2015-10-08T20:38:54Z")

</div>

Hi All.

I try to parse the hierarchical json data.  
Problem is there are same field in different level like below.  
{"id":"TEST","level2":{"id":"Level2 id"}}

In above case, final appeared id is overwrite previous one and it looks basic behavior of json filter.

Is there any workaround to keep json hierarchy like below ?  
id : TEST  
level2.id : Level2 id

Thanks  
Ducheol

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [October 8, 2015, 8:42pm UTC](https://discuss.elastic.co/t/keep-hierarchy-in-json-data/31881/2 "2015-10-08T20:42:29Z")

</div>

> {"id":"TEST",{"id","Level2"}}

But... this isn't valid JSON.

---

<div class="post-metadata">

**Author:** ![Ducheol\_Kim](https://avatars.discourse-cdn.com/v4/letter/d/8edcca/32.png) [@Ducheol\_Kim](https://discuss.elastic.co/u/Ducheol_Kim)\
**Post date:** [October 8, 2015, 8:43pm UTC](https://discuss.elastic.co/t/keep-hierarchy-in-json-data/31881/3 "2015-10-08T20:43:25Z")

</div>

Sorry, I just updated my original document.

{"id":"TEST","level2":{"id":"Level2 id"}}

Above is valid json.

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [October 9, 2015, 5:29am UTC](https://discuss.elastic.co/t/keep-hierarchy-in-json-data/31881/4 "2015-10-09T05:29:56Z")

</div>

Yes. But I don't know what overwriting you're talking about. Logstash handles that JSON snippet as I'd expect it to:

```
$ cat test.config 
input { stdin { } }
output { stdout { codec => rubydebug } }
filter {
  json {
    source => "message"
  }
}
$ echo '{"id":"TEST","level2":{"id":"Level2 id"}}' | /opt/logstash/bin/logstash -f test.config
Logstash startup completed
{
       "message" => "{\"id\":\"TEST\",\"level2\":{\"id\":\"Level2 id\"}}",
      "@version" => "1",
    "@timestamp" => "2015-10-09T05:28:36.484Z",
          "host" => "lnxolofon",
            "id" => "TEST",
        "level2" => {
        "id" => "Level2 id"
    }
}
Logstash shutdown completed
```

---

<div class="post-metadata">

**Author:** ![Ducheol\_Kim](https://avatars.discourse-cdn.com/v4/letter/d/8edcca/32.png) [@Ducheol\_Kim](https://discuss.elastic.co/u/Ducheol_Kim)\
**Post date:** [October 9, 2015, 6:34pm UTC](https://discuss.elastic.co/t/keep-hierarchy-in-json-data/31881/5 "2015-10-09T18:34:21Z")

</div>

You're right. In the logstash log, it show as hierarchical.

But in the ES, only 'Level2 id' is shown under id field and 'TEST' which is id value in parent is gone.

[https://www.elastic.co/guide/en/logstash/current/plugins-filters-json.html](https://www.elastic.co/guide/en/logstash/current/plugins-filters-json.html)  
In above, I see below sentence  
By default it will place the parsed JSON in the root (top level) of the Logstash event, but this filter can be configured to place the JSON into any arbitrary event field, using the target configuration.

I'm not sure. But I think same element is appeared, previous data is overwritten by last one.  
If the json filter named the field hierarchically, then I think it could be resolved.

Thanks  
Ducheol

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 5:26am UTC](https://discuss.elastic.co/t/keep-hierarchy-in-json-data/31881/6 "2017-07-06T05:26:57Z")

</div>


