# Log line with multiple JSON Objects

**URL:** <https://discuss.elastic.co/t/log-line-with-multiple-json-objects/227562>\
**Category:** Logstash\
**Created:** [April 10, 2020, 9:18pm UTC](https://discuss.elastic.co/t/log-line-with-multiple-json-objects/227562 "2020-04-10T21:18:06Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![ccabral](https://avatars.discourse-cdn.com/v4/letter/c/b4bc9f/32.png) [@ccabral](https://discuss.elastic.co/u/ccabral)\
**Post date:** [April 10, 2020, 9:18pm UTC](https://discuss.elastic.co/t/log-line-with-multiple-json-objects/227562/1 "2020-04-10T21:18:06Z")

</div>

Hello, apologies if this has already been asked and answered but I can't seem to find a way to achieve what I'm looking for. I'm using logstash to break down log lines and I have everything separated but I run into a string that has two JSON objects in it.

```auto
{
    "topic": "testing",
    "payload": {
        "context": {
            "processed_event_name": "TRANSACTION_CREATED",
            "processed_event_context": {
                "transaction_id": 139597215,
                "type_of_transaction": 1
            }
        },
        "eventName": "MESSAGE_PROCESSED",
        "correlationId": "954625b4-1307-4298-b206-c0949613f603",
        "timestamp": "2019-04-12T13:01:35-07:00"
    }
}
{
    "correlationId": "954625b4-1307-4298-b206-c0949613f603",
    "eventId": "TRANSACTION_CREATED",
    "hostname": "ccabrals-MacBook-Pro.local"
}

```

Running this on the above string results in the second JSON object being parsed into top level key value pairs in the output

```auto
 json {
    source => "json"
    target => "[json_object]"
  }

```

But I can't match the first nested JSON Object.

My desired output would be something like this:

```auto
nested_json_object: {
       nested_key_value_pairs: {
         key:value
      }
},
json_object: {
  key: value,
}

```

Any help would be appreciated, thanks.

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [April 10, 2020, 11:28pm UTC](https://discuss.elastic.co/t/log-line-with-multiple-json-objects/227562/2 "2020-04-10T23:28:06Z")

</div>

You need to split it into two fields. [That](https://discuss.elastic.co/t/how-to-parse-json-in-grok/129465/2) may be simple, or may involve some complicated ruby code.

---

<div class="post-metadata">

**Author:** ![ccabral](https://avatars.discourse-cdn.com/v4/letter/c/b4bc9f/32.png) [@ccabral](https://discuss.elastic.co/u/ccabral)\
**Post date:** [April 10, 2020, 11:52pm UTC](https://discuss.elastic.co/t/log-line-with-multiple-json-objects/227562/3 "2020-04-10T23:52:13Z")

</div>

Perfect, thank you, that works.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 8, 2020, 11:52pm UTC](https://discuss.elastic.co/t/log-line-with-multiple-json-objects/227562/4 "2020-05-08T23:52:14Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
