# Locate json field with jsonpath (logstash)

**URL:** <https://discuss.elastic.co/t/locate-json-field-with-jsonpath-logstash/318812>\
**Category:** Logstash\
**Created:** [November 14, 2022, 12:49am UTC](https://discuss.elastic.co/t/locate-json-field-with-jsonpath-logstash/318812 "2022-11-14T00:49:48Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![AdxDaz](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/adxdaz/32/113305_2.png) [@AdxDaz](https://discuss.elastic.co/u/AdxDaz)\
**Post date:** [November 14, 2022, 12:49am UTC](https://discuss.elastic.co/t/locate-json-field-with-jsonpath-logstash/318812/1 "2022-11-14T00:49:48Z")

</div>

Hi Elastic team,

I have the next Json:

```auto
{"response-code":"4000","response":{"result":[{"DetailsPageURL":"/show.do?resourceid=22&method=show&PRINTER_FRIENDLY=true","TODAYUNAVAILPERCENT":"0","Attribute":[{"DISPLAYNAME":"Tiempo de respuesta","Value":"0","Units":" mins","AttributeID":"2202"}],"HEALTHATTRIBUTEID":"2201","TARGETADDRESS":"","RESOURCENAME":"test.sh","TODAYAVAILPERCENT":"100","TARGETNAME":"","TODAYSCHEDDOWNPERCENT":"0.0","AVAILABILITYATTRIBUTEID":"2200","HEALTHSEVERITY":"5","DISKUTIL":"-1","MANAGED":"true","PHYMEMUTIL":"-1","AVAILABILITYMESSAGE":"Resource up. <br>The resource test is available.","AVAILABILITYSEVERITY":"5","TYPESHORTNAME":"Script","TYPE":"Script Monitor","DESCRIPTION":"Script Monitor Monitoring: for test.sh","LASTPOLLEDTIME":"02-nov-2022 15:08","RESOURCEID":"22","TODAYUNMANGDPERCENT":"0.0","HEALTHMESSAGE":"Cleared by BR_Admin_wlibrev","CPUUTIL":"-1","CHILDMONITORS":[{"AVAILABILITYID":"10002766","DISPLAYNAME":"NumTrx","CHILDMONITORINFO":[{"DISPLAYNAME":"Nodo3","RESOURCEID":"30597165","CHILDATTRIBUTES":[{"DISPLAYNAME":"COUNT","Value":"2235.0","Units":" ","AttributeID":"10002801"}],"AVAILABILITYSEVERITY":"-","HEALTHSEVERITY":"-"},{"DISPLAYNAME":"Nodo4","RESOURCEID":"30597166","CHILDATTRIBUTES":[{"DISPLAYNAME":"COUNT","Value":"59.0","Units":" ","AttributeID":"10002801"}],"AVAILABILITYSEVERITY":"-","HEALTHSEVERITY":"-"},{"DISPLAYNAME":"Nodo5","RESOURCEID":"30597167","CHILDATTRIBUTES":[{"DISPLAYNAME":"COUNT","Value":"336.0","Units":" ","AttributeID":"10002801"}],"AVAILABILITYSEVERITY":"-","HEALTHSEVERITY":"-"},{"DISPLAYNAME":"Nodo6","RESOURCEID":"30597168","CHILDATTRIBUTES":[{"DISPLAYNAME":"COUNT","Value":"483.0","Units":" ","AttributeID":"10002801"}],"AVAILABILITYSEVERITY":"-","HEALTHSEVERITY":"-"},{"DISPLAYNAME":"Nodo7","RESOURCEID":"30597169","CHILDATTRIBUTES":[{"DISPLAYNAME":"COUNT","Value":"1726.0","Units":" ","AttributeID":"10002801"}],"AVAILABILITYSEVERITY":"-","HEALTHSEVERITY":"-"},{"DISPLAYNAME":"Nodo8","RESOURCEID":"30597170","CHILDATTRIBUTES":[{"DISPLAYNAME":"COUNT","Value":"401.0","Units":" ","AttributeID":"10002801"}],"AVAILABILITYSEVERITY":"-","HEALTHSEVERITY":"-"},{"DISPLAYNAME":"TotalNodos","RESOURCEID":"30597171","CHILDATTRIBUTES":[{"DISPLAYNAME":"COUNT","Value":"5240.0","Units":" ","AttributeID":"10002801"}],"AVAILABILITYSEVERITY":"-","HEALTHSEVERITY":"-"},{"DISPLAYNAME":"timestamp","RESOURCEID":"30597172","CHILDATTRIBUTES":[],"AVAILABILITYSEVERITY":"-","HEALTHSEVERITY":"-"},{"DISPLAYNAME":"timeStamp","RESOURCEID":"30890095","CHILDATTRIBUTES":[{"DISPLAYNAME":"COUNT","Value":"1509.0","Units":" ","AttributeID":"10002801"}],"AVAILABILITYSEVERITY":"-","HEALTHSEVERITY":"-"}],"HEALTHID":"10002767"}],"DISPLAYNAME":"test","HEALTHSTATUS":"clear","RCAPageURL":"/jsp/RCA.jsp?resourceid=22&attributeid=2201","IMAGEPATH":"/images/script.gif","AVAILABILITYSTATUS":"up"}],"uri":"/app/json/get"}}

```

I need to extract just the value into "Total Nodos" located in:

```auto
"prueba" => "%{[response][result][0][CHILDMONITORS][0][CHILDMONITORINFO][10][CHILDATTRIBUTES][0][Value]}"

```

if i search with this method works good, the problema is that sometimes the location of the filed change, for example from "10" with "12".

So, i need to be able to find the same value but with the name of the field into the json.

I tryed something like this:

```auto
"prueba" => "%{[response][result][0][CHILDMONITORS][0][CHILDMONITORINFO][DISPLAYNAME=="TotalNodos"][CHILDATTRIBUTES][0][Value]}"

```

But that sintaxis doesn't work.

I apreciate your help.

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [November 14, 2022, 2:35am UTC](https://discuss.elastic.co/t/locate-json-field-with-jsonpath-logstash/318812/2 "2022-11-14T02:35:31Z")

</div>

I would use a ruby filter to find the right entry in the array:

```
    ruby {
        code => '
            begin
                a = event.get("[response][result][0][CHILDMONITORS][0][CHILDMONITORINFO]")
                a = a.select { |x| x["DISPLAYNAME"] == "TotalNodos" }
                event.set("someField", a[0]["CHILDATTRIBUTES"][0]["Value"])
            rescue
            end
        '
    }

```

---

<div class="post-metadata">

**Author:** ![AdxDaz](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/adxdaz/32/113305_2.png) [@AdxDaz](https://discuss.elastic.co/u/AdxDaz)\
**Post date:** [November 14, 2022, 1:37pm UTC](https://discuss.elastic.co/t/locate-json-field-with-jsonpath-logstash/318812/3 "2022-11-14T13:37:51Z")

</div>

Great advice @Badger works perfect.

Thanks for your help.

---

<div class="post-metadata">

**Author:** ![AdxDaz](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/adxdaz/32/113305_2.png) [@AdxDaz](https://discuss.elastic.co/u/AdxDaz)\
**Post date:** [November 15, 2022, 11:13pm UTC](https://discuss.elastic.co/t/locate-json-field-with-jsonpath-logstash/318812/4 "2022-11-15T23:13:53Z")

</div>

Hi @Badger,

Despite the code works, i have the next error when the position of the value change:

```auto
[2022-11-15T09:30:17,191][WARN][logstash.javapipeline][log_trans] Waiting for input plugin to close {:pipeline_id=>"log_trans", :thread=>"#<Thread:0x7371c607@/home/logstash/logstash-7.12.0/logstash-core/lib/logstash/pipeline_action/create.rb:54 run>"}
[2022-11-15T09:30:18,192][WARN][logstash.javapipeline][log_trans] Waiting for input plugin to close {:pipeline_id=>"log_trans", :thread=>"#<Thread:0x7371c607@/home/logstash/logstash-7.12.0/logstash-core/lib/logstash/pipeline_action/create.rb:54 run>"}
[2022-11-15T09:30:19,202][ERROR][logstash.javapipeline][log_trans] Dropping events to unblock input plugin {:pipeline_id=>"log_trans", :count=>125, :thread=>"#<Thread:0x7371c607@/home/logstash/logstash-7.12.0/logstash-core/lib/logstash/pipeline_action/create.rb:54 run>"}
[2022-11-15T09:30:19,304][ERROR][logstash.javapipeline][log_trans] Dropping events to unblock input plugin {:pipeline_id=>"log_trans", :count=>1, :thread=>"#<Thread:0x7371c607@/home/logstash/logstash-7.12.0/logstash-core/lib/logstash/pipeline_action/create.rb:54 run>"}
[2022-11-15T09:30:27,750][INFO][logstash.javapipeline][log_trans] Pipeline terminated {"pipeline.id"=>"log_trans"}

```

This error kill the pipeline and i have to restart all logstash because don't start the pipeline on its own.

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [November 15, 2022, 11:31pm UTC](https://discuss.elastic.co/t/locate-json-field-with-jsonpath-logstash/318812/5 "2022-11-15T23:31:32Z")

</div>

I suggest you ask a new question about that.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 13, 2022, 11:31pm UTC](https://discuss.elastic.co/t/locate-json-field-with-jsonpath-logstash/318812/6 "2022-12-13T23:31:47Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
