# Logstash 6.2 json parse failure

**URL:** <https://discuss.elastic.co/t/logstash-6-2-json-parse-failure/185995>\
**Category:** Logstash\
**Created:** [June 17, 2019, 5:58am UTC](https://discuss.elastic.co/t/logstash-6-2-json-parse-failure/185995 "2019-06-17T05:58:34Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Arnav\_Sengupta](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/arnav_sengupta/32/24059_2.png) [@Arnav\_Sengupta](https://discuss.elastic.co/u/Arnav_Sengupta)\
**Post date:** [June 17, 2019, 5:58am UTC](https://discuss.elastic.co/t/logstash-6-2-json-parse-failure/185995/1 "2019-06-17T05:58:34Z")

</div>

Hi,

I am trying to parse the below filebeat log

```
{ "event": {
"host": {
  "name": "lpcservices-dev-int-alln-75f4d6df98-t9wj2"
},
"beat": {
  "version": "6.4.2",
  "name": "lpcservices-dev-int-alln-75f4d6df98-t9wj2",
  "hostname": "lpcservices-dev-int-alln-75f4d6df98-t9wj2"
},
"source": "/home/jboss/lae-home/app-root/logs/lpcatalogservicesAppIO.log",
"input": {
  "type": "log"
},
"tags": [
  "applicationLogs",
  "beats_input_codec_plain_applied"
],
"message": "2019-06-14 02:25:48 [IOLogger] INFO {env=STAGE-YS2, serviceType=catalog_ITEM_PUBLISHABLE, transactionId=CAE-TEST-15} - {\"noOfLines\":0,\"request\":\"{\\\"requestHeader\\\":{\\\"transactionID\\\":\\\"CAE-TEST-15\\\",\\\"ccoID\\\":\\\"NETFORMX-XML\\\"},\\\"entries\\\":[{\\\"priceList\\\":\\\"WCH2\\\",\\\"items\\\":[\\\"L-CDACDN-UP3X\\\\u003d\\\",\\\"CAB-AC\\\\u003d\\\"]}]}\",\"timeTaken\":39}",
"@version": "1",
"@timestamp": "2019-06-14T09:25:48.647Z",
"offset": 1354,
"prospector": {
  "type": "log"
 }
}
}

```

I want to parse the json "host". I want to extract "name" from it into a field called "host" of my own. To break it down into step by step, I first just tried to parse the json by using the following filter

```
json { source => "host" }

```

However, when I do this, I get a '\_jsonparsefailure' tag in my output in logstash logs

```
output received {"event"=>{"type"=>"io", "offset"=>2716, "logLevel"=>"INFO ", "input"=>{"type"=>"log"}, "host"=>{"name"=>"lpcservices-dev-int-alln-75f4d6df98-t9wj2"}, "@timestamp"=>2019-06-17T05:45:48.000Z, "serviceType"=>"catalog_ITEM_PUBLISHABLE", "env"=>"STAGE-YS2", "noOfLines"=>0, "timeTaken"=>38, "request"=>"{\"requestHeader\":{\"transactionID\":\"CAE-TEST-15\",\"ccoID\":\"NETFORMX-XML\"},\"entries\":[{\"priceList\":\"WCH2\",\"items\":[\"L-CDACDN-UP3X\\u003d\",\"CAB-AC\\u003d\"]}]}", "timestamp"=>"2019-06-16 22:45:48", "source"=>"/home/jboss/lae-home/app-root/logs/lpcatalogservicesAppIO.log", "tags"=>["applicationLogs", "beats_input_codec_plain_applied", "_jsonparsefailure"], "@version"=>"1", "threadName"=>"IOLogger", "transactionId"=>"CAE-TEST-15", "prospector"=>{"type"=>"log"}}}

```

Any idea why it's throwing this error?

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [June 17, 2019, 1:22pm UTC](https://discuss.elastic.co/t/logstash-6-2-json-parse-failure/185995/2 "2019-06-17T13:22:50Z")

</div>

Can't you just reference [host][name]?

---

<div class="post-metadata">

**Author:** ![Arnav\_Sengupta](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/arnav_sengupta/32/24059_2.png) [@Arnav\_Sengupta](https://discuss.elastic.co/u/Arnav_Sengupta)\
**Post date:** [June 17, 2019, 1:50pm UTC](https://discuss.elastic.co/t/logstash-6-2-json-parse-failure/185995/3 "2019-06-17T13:50:28Z")

</div>

Okay, that worked. I think I know why my json filter didn't work. The debug log shows the input data as follows

```
"host"=>{"name"=>"lpcservices-dev-int-alln-75f4d6df98-t9wj2"}

```

This isn't really a json.

One question, does this mean nested fields from beats can be accessed as associative arrays?

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [June 17, 2019, 2:15pm UTC](https://discuss.elastic.co/t/logstash-6-2-json-parse-failure/185995/4 "2019-06-17T14:15:34Z")

</div>

If a field is an object then you can reference fields inside that object, yes. Like [host][name] or [beat][hostname].

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 15, 2019, 2:15pm UTC](https://discuss.elastic.co/t/logstash-6-2-json-parse-failure/185995/5 "2019-07-15T14:15:35Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
