# Logstash cannot extract json key

**URL:** <https://discuss.elastic.co/t/logstash-cannot-extract-json-key/162753>\
**Category:** Logstash\
**Created:** [January 3, 2019, 7:15am UTC](https://discuss.elastic.co/t/logstash-cannot-extract-json-key/162753 "2019-01-03T07:15:51Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![t.b](https://avatars.discourse-cdn.com/v4/letter/t/ecccb3/32.png) [@t.b](https://discuss.elastic.co/u/t.b)\
**Post date:** [January 3, 2019, 7:15am UTC](https://discuss.elastic.co/t/logstash-cannot-extract-json-key/162753/1 "2019-01-03T07:15:52Z")

</div>

Hi guys, I need help regarding logstash filter to extract json key/value to new\_field. The following is my logstash conf.

```
input {
	tcp {
		port => 5044
	}
}

filter {
	json {
		source => "message"
		add_field => {
			"data" => "%{[message][data]}"
		}
	}
}

output {
		stdout { codec => rubydebug }
}

```

I have tried with mutate:

```
filter {
    json {
        source => "message"
    }
    mutate {
        add_field => {
            "data" => "%{[message][data]}"
        }
    }
}

```

I have tried with . instead of []:

```
filter {
    json {
        source => "message"
    }
    mutate {
        add_field => {
            "data" => "%{message.data}"
        }
    }
}

```

I have tried with index number:

```
filter {
    json {
        source => "message"
    }
    mutate {
        add_field => {
            "data" => "%{[message][0]}"
        }
    }
}

```

**All with no luck. ☹**

The following json is sent to port 5044:

```
{"data": "blablabla"}

```

The problem is the new field not able to extract value from the key of the json.  
  
**"data" =\> "%{[message][data]}"**  
  
  
The following is my stdout:

```
{
           "@version" => "1",
               "host" => "localhost",
               "type" => "logstash",
               "data" => "%{[message][data]}",
               "path" => "/path/from/my/app",
         "@timestamp" => 2019-01-11T20:39:10.845Z,
            "message" => "{\"data\": \"blablabla\"}"
}

```

However if I use **"data" =\> "%{[message]}"** instead:

```
filter {
    json {
        source => "message"
        add_field => {
            "data" => "%{[message]}"
        }
    }
}

```

I will get the whole json from stdout.

```
{
           "@version" => "1",
               "host" => "localhost",
               "type" => "logstash",
               "data" => "{\"data\": \"blablabla\"}",
               "path" => "/path/from/my/app",
         "@timestamp" => 2019-01-11T20:39:10.845Z,
            "message" => "{\"data\": \"blablabla\"}"
}

```

Can anyone please tell me what I did wrong.  
  
Thank you in advance.  
  
I use docker-elk stack, ELK\_VERSION=6.5.4

---

<div class="post-metadata">

**Author:** ![Chris\_Lyons](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/chris_lyons/32/48107_2.png) [@Chris\_Lyons](https://discuss.elastic.co/u/Chris_Lyons)\
**Post date:** [January 12, 2019, 12:27am UTC](https://discuss.elastic.co/t/logstash-cannot-extract-json-key/162753/3 "2019-01-12T00:27:45Z")

</div>

I don't believe your json filter is working because you really just have a Key/Value pair. Simply add the json\_lines codec to you input....

input {  
tcp {  
port =\> 5044  
codec =\> "json\_lines"  
}  
}

---

<div class="post-metadata">

**Author:** ![t.b](https://avatars.discourse-cdn.com/v4/letter/t/ecccb3/32.png) [@t.b](https://discuss.elastic.co/u/t.b)\
**Post date:** [January 14, 2019, 8:35pm UTC](https://discuss.elastic.co/t/logstash-cannot-extract-json-key/162753/4 "2019-01-14T20:35:09Z")

</div>

I did just that but it didn't work.

I found the solution to this issue, it was simply a nested json.

```
 message: {
     message: {
     }
 }

```

all I did was to use target.

```auto
filter {
  json {
    source => "message"
    target => "message"
  }
}

filter {
  json {
    source => "data[message]"
    target => "message"
  }
}

```

---

<div class="post-metadata">

**Author:** ![t.b](https://avatars.discourse-cdn.com/v4/letter/t/ecccb3/32.png) [@t.b](https://discuss.elastic.co/u/t.b)\
**Post date:** [January 14, 2019, 8:35pm UTC](https://discuss.elastic.co/t/logstash-cannot-extract-json-key/162753/5 "2019-01-14T20:35:45Z")

</div>

I did just that but it didn't work.

I found the solution to this issue, it was simply a nested json.

```
 message: {
   message: {
   }
 }

```

all I did was to use target.

```auto
filter {
  json {
    source => "message"
    target => "data"
  }
}

filter {
  json {
    source => "data[message]"
    target => "message"
  }
}

```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 11, 2019, 8:42pm UTC](https://discuss.elastic.co/t/logstash-cannot-extract-json-key/162753/6 "2019-02-11T20:42:16Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
