# List json parsing

**URL:** <https://discuss.elastic.co/t/list-json-parsing/78993>\
**Category:** Logstash\
**Created:** [March 17, 2017, 10:00am UTC](https://discuss.elastic.co/t/list-json-parsing/78993 "2017-03-17T10:00:52Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![E.Eric](https://avatars.discourse-cdn.com/v4/letter/e/dec6dc/32.png) [@E.Eric](https://discuss.elastic.co/u/E.Eric)\
**Post date:** [March 17, 2017, 10:00am UTC](https://discuss.elastic.co/t/list-json-parsing/78993/1 "2017-03-17T10:00:52Z")

</div>

Hello,

I have a probleme to create a list of json object. this is my config:  
input {  
file {#settings...}  
}  
filter {  
mutate {  
add\_field =\> {"book\_title" =\> "%{Book\_title}"}  
add\_field =\> {"book\_price" =\> "%{Book\_price}"}}  
mutate {  
rename =\> { "book\_title" =\> "[book\_market][book\_title]"  
"book\_price" =\> "[book\_market][book\_price]" }  
}  
#I want book\_market be list for some reason even it has one object  
ruby {  
code =\> "  
event['book\_market'] = [event['book\_market']]  
"  
}  
}  
the result here after execution:  
"book\_market" : [ {  
"book\_title":"title",  
"book\_price":"price"  
}]  
it's that I want !  
But in a second time a new book arrives from another file... the probleme here with the same config I lost the first json object because book\_market is overwritten.. I want to insert the new object in book\_market list.

Thank you for help !

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [March 17, 2017, 11:34am UTC](https://discuss.elastic.co/t/list-json-parsing/78993/2 "2017-03-17T11:34:36Z")

</div>

Do you want to update existing documents in ES? Then you need use scripted updates, which seems to be possible with the elasticsearch output but I've never tried it myself.

---

<div class="post-metadata">

**Author:** ![E.Eric](https://avatars.discourse-cdn.com/v4/letter/e/dec6dc/32.png) [@E.Eric](https://discuss.elastic.co/u/E.Eric)\
**Post date:** [March 17, 2017, 1:52pm UTC](https://discuss.elastic.co/t/list-json-parsing/78993/3 "2017-03-17T13:52:21Z")

</div>

Yes, I want to update existing document in ES.  
I create a new configuration for update, I've extracted book information from input file and then I tryed to update th document in ES. This is my config:

```
output { 

   elasticsearch {
        hosts => ["172.16.25.9:9200"]
        index => "shopping"
        document_type => "book"
        action => "update"          
        #indicate the document ID to be updated
        document_id => "%{book_id}"
        #Enable Partial Update in ElasticSearch
        doc_as_upsert => true
        script_lang => "groovy"
        script_type => "inline"
        script => '
                ctx._source.book_market.add("%{book_title}" "%{book_price}");
            '
    }

```

"error"=\>{"type"=\>"illegal\_argument\_exception", "reason"=\>"failed to execute script", "caused\_by"=\>{"type"=\>"script\_exception", "reason"=\>"failed to run inline script [\n\t\t\t\t\tctx.\_source.book\_market..add("%{book\_title}" "%{book\_price}");"] using lang [groovy]", "caused\_by"=\>{"type"=\>"illegal\_argument\_exception", "reason"=\>"argument type mismatch"}}}}}, :level=\>:warn}

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 14, 2017, 1:52pm UTC](https://discuss.elastic.co/t/list-json-parsing/78993/4 "2017-04-14T13:52:36Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
