# Log with json value and timestamp value from syslog

**URL:** <https://discuss.elastic.co/t/log-with-json-value-and-timestamp-value-from-syslog/117245>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [January 26, 2018, 6:02pm UTC](https://discuss.elastic.co/t/log-with-json-value-and-timestamp-value-from-syslog/117245 "2018-01-26T18:02:02Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![ramzey1981](https://avatars.discourse-cdn.com/v4/letter/r/d26b3c/32.png) [@ramzey1981](https://discuss.elastic.co/u/ramzey1981)\
**Post date:** [January 26, 2018, 6:02pm UTC](https://discuss.elastic.co/t/log-with-json-value-and-timestamp-value-from-syslog/117245/1 "2018-01-26T18:02:02Z")

</div>

we have a python application logging to syslog in json format but syslog allows appends a timestamp with the json message,

Jan 26 11:07:14 mkobit-ThinkPad {"@source\_host": "mkobit-ThinkPad", "module": "pyscratch", "lineno": 63, "pathname": "[pyscratch.py](http://pyscratch.py)", "funcName": "", "message": "HEY there!", "levelname": "INFO", "@timestamp": "2018-01-26T17:07:14.743Z"}

can filebeat handle such a message with this type of format?

---

<div class="post-metadata">

**Author:** ![pierhugues](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/pierhugues/32/48383_2.png) [@pierhugues](https://discuss.elastic.co/u/pierhugues)\
**Post date:** [January 26, 2018, 7:32pm UTC](https://discuss.elastic.co/t/log-with-json-value-and-timestamp-value-from-syslog/117245/2 "2018-01-26T19:32:36Z")

</div>

Hello @ramzey1981,

Out of the box you won't be able to parse that kind of message, you will either need to send the message to an [ingest pipeline](https://www.elastic.co/guide/en/elasticsearch/reference/master/ingest.html) or [Logstash](https://www.elastic.co/guide/en/logstash/master/index.html) and the [beats input](https://www.elastic.co/guide/en/logstash/current/plugins-inputs-beats.html) for more event parsing using grok and the json decoder.

Thanks

---

<div class="post-metadata">

**Author:** ![ramzey1981](https://avatars.discourse-cdn.com/v4/letter/r/d26b3c/32.png) [@ramzey1981](https://discuss.elastic.co/u/ramzey1981)\
**Post date:** [January 26, 2018, 7:54pm UTC](https://discuss.elastic.co/t/log-with-json-value-and-timestamp-value-from-syslog/117245/3 "2018-01-26T19:54:06Z")

</div>

thanks Pier,

Yes we thought that json decode would be able to do it but after reading the documentation seems like the first two strings has to be an actual json object which its really not because of the format.

If i send this to logstash i an grok the first field as timestamp and the second filed has hostname or source but then what would I do with the json message field?

---

<div class="post-metadata">

**Author:** ![pierhugues](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/pierhugues/32/48383_2.png) [@pierhugues](https://discuss.elastic.co/u/pierhugues)\
**Post date:** [January 26, 2018, 8:06pm UTC](https://discuss.elastic.co/t/log-with-json-value-and-timestamp-value-from-syslog/117245/4 "2018-01-26T20:06:45Z")

</div>

@ramzey1981 Use grok filter to extract the3 fields:

- date
- hostname
- json\_source

After use the [logstash-filer-json](https://github.com/logstash-plugins/logstash-filter-json) on the `json_source` field.

This scenario will work on either Logstash or the ingest pipeline, since they can both work with this kind of data.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 23, 2018, 8:06pm UTC](https://discuss.elastic.co/t/log-with-json-value-and-timestamp-value-from-syslog/117245/5 "2018-02-23T20:06:52Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
