# Kubernetes annotation - array value declaration

**URL:** <https://discuss.elastic.co/t/kubernetes-annotation-array-value-declaration/335304>\
**Category:** Beats\
**Tags:** docker, filebeat\
**Created:** [June 6, 2023, 8:51am UTC](https://discuss.elastic.co/t/kubernetes-annotation-array-value-declaration/335304 "2023-06-06T08:51:21Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Vijayakumar\_Kannan](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/vijayakumar_kannan/32/34873_2.png) [@Vijayakumar\_Kannan](https://discuss.elastic.co/u/Vijayakumar_Kannan)\
**Post date:** [June 6, 2023, 8:51am UTC](https://discuss.elastic.co/t/kubernetes-annotation-array-value-declaration/335304/1 "2023-06-06T08:51:21Z")

</div>

How do we convert the following filebeat config into kubernetes pod annotation level.

```auto
  processors:
    - decode_json_fields:
        fields: ["message","msg"]
        target: "qrapp"
        add_error_key: true

```

**kubernetes pod annotation**

```auto
co.elastic.logs/processors.decode_json_fields.fields: ["message","msg"]    
co.elastic.logs/processors.decode_json_fields.target: "qrapp"
co.elastic.logs/processors.decode_json_fields.add_error_key" 'true'

```

Doubt is on co.elastic.logs/processors.decode\_json\_fields.fields: ["message","msg"] this.

---

<div class="post-metadata">

**Author:** ![Andreas\_Gkizas](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andreas_gkizas/32/117035_2.png) [@Andreas\_Gkizas](https://discuss.elastic.co/u/Andreas_Gkizas)\
**Post date:** [June 6, 2023, 10:56am UTC](https://discuss.elastic.co/t/kubernetes-annotation-array-value-declaration/335304/2 "2023-06-06T10:56:13Z")

</div>

Looks ok apart from a typo:

```auto
co.elastic.logs/processors.decode_json_fields.add_error_key: 'true'

```

Also the field is message. Do you need the `msg`?

---

<div class="post-metadata">

**Author:** ![Vijayakumar\_Kannan](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/vijayakumar_kannan/32/34873_2.png) [@Vijayakumar\_Kannan](https://discuss.elastic.co/u/Vijayakumar_Kannan)\
**Post date:** [June 6, 2023, 12:36pm UTC](https://discuss.elastic.co/t/kubernetes-annotation-array-value-declaration/335304/3 "2023-06-06T12:36:51Z")

</div>

> [@Vijayakumar\_Kannan](#):
>
> ```auto
> co.elastic.logs/processors.decode_json_fields.fields: ["message","msg"]    
> co.elastic.logs/processors.decode_json_fields.target: "qrapp"
> co.elastic.logs/processors.decode_json_fields.add_error_key" 'true'
> 
> ```

```auto
co.elastic.logs/processors.decode_json_fields.fields: 'message'   
co.elastic.logs/processors.decode_json_fields.target: "qrapp"
co.elastic.logs/processors.decode_json_fields.add_error_key: 'true'

```

is ok, but is it ok to declare as string "message" because as per the url [Decode JSON fields | Filebeat Reference [8.8] | Elastic](https://www.elastic.co/guide/en/beats/filebeat/8.8/decode-json-fields.html) "fields" is array type.

---

<div class="post-metadata">

**Author:** ![Andreas\_Gkizas](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andreas_gkizas/32/117035_2.png) [@Andreas\_Gkizas](https://discuss.elastic.co/u/Andreas_Gkizas)\
**Post date:** [June 6, 2023, 1:39pm UTC](https://discuss.elastic.co/t/kubernetes-annotation-array-value-declaration/335304/4 "2023-06-06T13:39:11Z")

</div>

Yes there is no problem.

Used this annotations in my dummy nginx pod:

```yaml
annotations:
        co.elastic.logs/processors.decode_json_fields.fields: 'message'   
        co.elastic.logs/processors.decode_json_fields.target: "qrapp"
        co.elastic.logs/processors.decode_json_fields.add_error_key: 'true'

```

And see the result:

 ![Screenshot 2023-06-06 at 4.34.17 PM](https://us1.discourse-cdn.com/elastic/original/3X/b/4/b4cd206e64d11e8ebe862d8171f59cdf96e59412.png)  
 ![Screenshot 2023-06-06 at 4.34.36 PM](https://us1.discourse-cdn.com/elastic/original/3X/e/a/ea34bee28788990b4da78e3436515b228893cecf.png)

Mind that this is the json entry I create in my message field:  
`'{"test":"hello"}'`

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 4, 2023, 3:39pm UTC](https://discuss.elastic.co/t/kubernetes-annotation-array-value-declaration/335304/5 "2023-07-04T15:39:45Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
