# Logstash extract a nested json object

**URL:** <https://discuss.elastic.co/t/logstash-extract-a-nested-json-object/265307>\
**Category:** Logstash\
**Created:** [February 24, 2021, 9:43am UTC](https://discuss.elastic.co/t/logstash-extract-a-nested-json-object/265307 "2021-02-24T09:43:13Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![imsystem](https://avatars.discourse-cdn.com/v4/letter/i/46a35a/32.png) [@imsystem](https://discuss.elastic.co/u/imsystem)\
**Post date:** [February 24, 2021, 9:43am UTC](https://discuss.elastic.co/t/logstash-extract-a-nested-json-object/265307/1 "2021-02-24T09:43:13Z")

</div>

Hello!  
I have input json:

```auto
{
   "fields":{
      "created_date":1614158456696703782,
      "value":"\u001B[35m-\u001B[0m | \u001B[32m2021-02-20T12:48:10.367337+0300\u001B[0m | \u001B[1mINFO \u001B[0m | application.app:<module>:98 - \u001B[1mtest info"
   },
   "@version":"1",
   "@timestamp":"2021-02-24T09:31:50.208Z",
   "tags":{
      "data_tags":"[\"tag1\",\"tag2\"]",
      "collection_platform":"telegraf",
      "index_name":"test_alias",
      "source_type":"file",
      "data_type":"raw",
      "path":"/opt/map/hub/logs/trace.log",
      "host":"hub"
   },
   "timestamp":1614158456,
   "name":"logparser"
}

```

How extract fields: `created_date` , `value`, if i dont know them?

If i use json plugin:

```auto
json {
  skip_on_invalid_json => false
  source => "fields"
}

```

or

```auto
mutate {
  convert => { "fields" => "string" }
}
json {
  skip_on_invalid_json => false
  source => "fields"
}

```

I have error:

```auto
Feb 24 12:21:24 elk logstash[2868]: [2021-02-24T12:21:24,951][WARN][logstash.filters.json][main] Exception caught in json filter {:exception=>"class java.util.HashMap cannot be cast to class java.lang.String (java.util.HashMap and java.lang.String are in module java.base of loader 'bootstrap')", :source=>"fields", :raw=>{"created_date"=>1614158456696703782, "value"=>"\e[35m-\e[0m | \e[32m2021-02-20T12:48:10.367337+0300\e[0m | \e[1mINFO \e[0m | application.app:<module>:98 - \e[1mtest info"}}
Feb 24 12:21:24 elk logstash[2868]: [2021-02-24T12:21:24,977][ERROR][org.logstash.execution.WorkerLoop][main] Exception in pipelineworker, the pipeline stopped processing new events, please check your filter configuration and restart Logstash.
Feb 24 12:21:24 elk logstash[2868]: java.lang.ClassCastException: class java.util.HashMap cannot be cast to class java.lang.String (java.util.HashMap and java.lang.String are in module java.base of loader 'bootstrap')

```

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [February 24, 2021, 2:42pm UTC](https://discuss.elastic.co/t/logstash-extract-a-nested-json-object/265307/2 "2021-02-24T14:42:06Z")

</div>

The error message shows that [fields] is an object, not a string (see [here](https://discuss.elastic.co/t/json-parsing-issue/265219/2) to understand why). You can move arbitrary fields within an object to the root using a ruby filter. See [here](https://discuss.elastic.co/t/how-to-dynamically-move-nested-key-value-to-root-level/180006/2) for an example.

---

<div class="post-metadata">

**Author:** ![imsystem](https://avatars.discourse-cdn.com/v4/letter/i/46a35a/32.png) [@imsystem](https://discuss.elastic.co/u/imsystem)\
**Post date:** [February 24, 2021, 5:51pm UTC](https://discuss.elastic.co/t/logstash-extract-a-nested-json-object/265307/3 "2021-02-24T17:51:13Z")

</div>

Thanks!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 24, 2021, 5:51pm UTC](https://discuss.elastic.co/t/logstash-extract-a-nested-json-object/265307/4 "2021-03-24T17:51:44Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
