# Logstash filter for records of nested json messages from eventhub

**URL:** <https://discuss.elastic.co/t/logstash-filter-for-records-of-nested-json-messages-from-eventhub/314930>\
**Category:** Logstash\
**Created:** [September 22, 2022, 9:34am UTC](https://discuss.elastic.co/t/logstash-filter-for-records-of-nested-json-messages-from-eventhub/314930 "2022-09-22T09:34:51Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Sivaramakrishhna\_Amb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sivaramakrishhna_amb/32/108564_2.png) [@Sivaramakrishhna\_Amb](https://discuss.elastic.co/u/Sivaramakrishhna_Amb)\
**Post date:** [September 22, 2022, 9:34am UTC](https://discuss.elastic.co/t/logstash-filter-for-records-of-nested-json-messages-from-eventhub/314930/1 "2022-09-22T09:34:51Z")

</div>

Input message looks like below

{  
"records": [  
{  
"level": "Informational",  
"properties": {  
"Keywords": 0,  
"ProviderName": "Core.LogRecord",  
"Message": "2022-09-08 08:17:02,935 [23] INFO {"Message":"9/8/2022 8:17:02 AM - StarhubAuthTokenFunc - Identifier =\> 0 CanRefreshToken = False","Exception":null,"Environment":"NANANA","Server":"XXXXXX","ContextType":"Message","CorrelationId":null,"ApplicationName":"Microsoft.Azure.WebJobs.Script.WebHost","ApplicationVersion":"2.0.0.0","Data":""}"  
},  
"time": "2022-09-08T08:17:02.9358854+00:00"  
}  
]  
}

Output:  
all tags should be able to see in kibana as key and associated value

Can I get any help in this regard .

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [September 22, 2022, 11:51am UTC](https://discuss.elastic.co/t/logstash-filter-for-records-of-nested-json-messages-from-eventhub/314930/2 "2022-09-22T11:51:09Z")

</div>

What are you trying to do? What is not working? And what is the expected result?

You need to provide more information.

---

<div class="post-metadata">

**Author:** ![Sivaramakrishhna\_Amb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sivaramakrishhna_amb/32/108564_2.png) [@Sivaramakrishhna\_Amb](https://discuss.elastic.co/u/Sivaramakrishhna_Amb)\
**Post date:** [September 22, 2022, 2:50pm UTC](https://discuss.elastic.co/t/logstash-filter-for-records-of-nested-json-messages-from-eventhub/314930/3 "2022-09-22T14:50:03Z")

</div>

Thanks Leandro for response,  
logstash filter I'm using is as below

filter{  
json {

```
source => "message"
remove_field => ["message"]

```

}

split {  
field =\> "records"  
}  
ruby {  
code =\> '  
records\_size = event.get("[records]").size  
records\_size.times do |index|  
event.set("[records][#{index}][properties][Message]", event.get("[records][#{index}][Message]"))

```
  end
'

```

}  
date {  
match =\> ["time", "ISO8601"]  
}  
mutate {  
add\_field =\> { "feed\_site" =\> "netherlands" }  
add\_field =\> { "feed\_name" =\> "teleena" }  
add\_field =\> { "feed\_type" =\> "logs" }  
add\_field =\> { "feed\_doc" =\> "afandsf-eventhub" }  
}  
}

Output is like this but requirement is it should show all the key-values including inside the Message  
Please suggest filter for it

 ![1663857996612587757321850949416](https://us1.discourse-cdn.com/elastic/original/3X/f/2/f26aea8b874e67f0e75d804291aa0568e5220a32.jpeg)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 20, 2022, 2:50pm UTC](https://discuss.elastic.co/t/logstash-filter-for-records-of-nested-json-messages-from-eventhub/314930/4 "2022-10-20T14:50:08Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
