# Logstash is replacing : with =\> How can I get : on the output

**URL:** <https://discuss.elastic.co/t/logstash-is-replacing-with-how-can-i-get-on-the-output/186433>\
**Category:** Logstash\
**Created:** [June 19, 2019, 10:38am UTC](https://discuss.elastic.co/t/logstash-is-replacing-with-how-can-i-get-on-the-output/186433 "2019-06-19T10:38:43Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![Raj\_Sekhar](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/raj_sekhar/32/48355_2.png) [@Raj\_Sekhar](https://discuss.elastic.co/u/Raj_Sekhar)\
**Post date:** [June 19, 2019, 10:38am UTC](https://discuss.elastic.co/t/logstash-is-replacing-with-how-can-i-get-on-the-output/186433/1 "2019-06-19T10:38:43Z")

</div>

Logstash is replacing : with =\> How can I get : on the output

My input file:

{  
"customfield\_10150": [  
{"key": "caanyimi",  
"displayName": "Anyimi, Charles"}  
]  
}

Output:

"name""=\>""caanyimi"",  
""emailAddress""=\>""charles.anyimi@intel.com"

---

<div class="post-metadata">

**Author:** ![harshbajaj16](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/harshbajaj16/32/44970_2.png) [@harshbajaj16](https://discuss.elastic.co/u/harshbajaj16)\
**Post date:** [June 19, 2019, 10:51am UTC](https://discuss.elastic.co/t/logstash-is-replacing-with-how-can-i-get-on-the-output/186433/2 "2019-06-19T10:51:45Z")

</div>

Hi @Raj_Sekhar,

Could you please explain bit more about your use case what you are trying to do and what you want to achieve.

Regards,  
Harsh Bajaj

---

<div class="post-metadata">

**Author:** ![Raj\_Sekhar](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/raj_sekhar/32/48355_2.png) [@Raj\_Sekhar](https://discuss.elastic.co/u/Raj_Sekhar)\
**Post date:** [June 19, 2019, 11:01am UTC](https://discuss.elastic.co/t/logstash-is-replacing-with-how-can-i-get-on-the-output/186433/3 "2019-06-19T11:01:06Z")

</div>

Hi Harsh,

I have an nested array of values inside the json.  
When I am trying to write to a csv file, the colons are getting replaced with =\>

"customfield\_10150": [  
{  
"key": "caanyimi",  
"displayName": "Anyimi, Charles",  
"self": "[https://nsg-jira.intel.com/rest/api/2/user?username=caanyimi](https://nsg-jira.intel.com/rest/api/2/user?username=caanyimi)",  
"avatarUrls": {  
"16x16": "[https://nsg-jira.intel.com/secure/useravatar?size=xsmall&ownerId=caanyimi&avatarId=18136](https://nsg-jira.intel.com/secure/useravatar?size=xsmall&ownerId=caanyimi&avatarId=18136)",  
"48x48": "[https://nsg-jira.intel.com/secure/useravatar?ownerId=caanyimi&avatarId=18136](https://nsg-jira.intel.com/secure/useravatar?ownerId=caanyimi&avatarId=18136)",  
"32x32": "[https://nsg-jira.intel.com/secure/useravatar?size=medium&ownerId=caanyimi&avatarId=18136](https://nsg-jira.intel.com/secure/useravatar?size=medium&ownerId=caanyimi&avatarId=18136)",  
"24x24": "[https://nsg-jira.intel.com/secure/useravatar?size=small&ownerId=caanyimi&avatarId=18136](https://nsg-jira.intel.com/secure/useravatar?size=small&ownerId=caanyimi&avatarId=18136)"  
},  
"active": true,  
"name": "caanyimi",  
"timeZone": "US/Pacific",  
"emailAddress": "charles.anyimi@intel.com"  
},  
{  
"key": "dablunde",  
"displayName": "Blunden, David",  
"self": "[https://nsg-jira.intel.com/rest/api/2/user?username=dablunde](https://nsg-jira.intel.com/rest/api/2/user?username=dablunde)",  
"avatarUrls": {  
"16x16": "[https://www.gravatar.com/avatar/28dd9333e6b5dc333179817530ded97e?d=mm&s=16](https://www.gravatar.com/avatar/28dd9333e6b5dc333179817530ded97e?d=mm&s=16)",  
"48x48": "[https://www.gravatar.com/avatar/28dd9333e6b5dc333179817530ded97e?d=mm&s=48](https://www.gravatar.com/avatar/28dd9333e6b5dc333179817530ded97e?d=mm&s=48)",  
"32x32": "[https://www.gravatar.com/avatar/28dd9333e6b5dc333179817530ded97e?d=mm&s=32](https://www.gravatar.com/avatar/28dd9333e6b5dc333179817530ded97e?d=mm&s=32)",  
"24x24": "[https://www.gravatar.com/avatar/28dd9333e6b5dc333179817530ded97e?d=mm&s=24](https://www.gravatar.com/avatar/28dd9333e6b5dc333179817530ded97e?d=mm&s=24)"  
},  
"active": true,  
"name": "dablunde",  
"timeZone": "US/Pacific",  
"emailAddress": "david.blunden@intel.com"  
}  
]

---

<div class="post-metadata">

**Author:** ![harshbajaj16](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/harshbajaj16/32/44970_2.png) [@harshbajaj16](https://discuss.elastic.co/u/harshbajaj16)\
**Post date:** [June 19, 2019, 11:07am UTC](https://discuss.elastic.co/t/logstash-is-replacing-with-how-can-i-get-on-the-output/186433/4 "2019-06-19T11:07:22Z")

</div>

Hi @Raj_Sekhar,

I understood your point. For this please try with below line adding in filter section.

> ruby {code =\> 'open("/tmp/test.json", "w") { |file| file.write(event.get("json").to\_json) }' }

Please do let me know if still you are not able achieve the same.

Regards,  
Harsh Bajaj

---

<div class="post-metadata">

**Author:** ![Raj\_Sekhar](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/raj_sekhar/32/48355_2.png) [@Raj\_Sekhar](https://discuss.elastic.co/u/Raj_Sekhar)\
**Post date:** [June 19, 2019, 11:24am UTC](https://discuss.elastic.co/t/logstash-is-replacing-with-how-can-i-get-on-the-output/186433/5 "2019-06-19T11:24:58Z")

</div>

Hi @harshbajaj16, Tried it, but the same result.  
May I know where is the file writing in your command ?

---

<div class="post-metadata">

**Author:** ![harshbajaj16](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/harshbajaj16/32/44970_2.png) [@harshbajaj16](https://discuss.elastic.co/u/harshbajaj16)\
**Post date:** [June 19, 2019, 11:32am UTC](https://discuss.elastic.co/t/logstash-is-replacing-with-how-can-i-get-on-the-output/186433/6 "2019-06-19T11:32:21Z")

</div>

Hi @Raj_Sekhar,

You need to add this in your logstash configuration file which is in /conf.d/ directory.

There are three section in conf file Input, Filter and Output. You need to add this in filter section.

Please find document link for filter ruby plugin.

> **[Ruby filter plugin | Logstash Reference \[8.11\] | Elastic](https://www.elastic.co/guide/en/logstash/current/plugins-filters-ruby.html)**

Also, i found a discussion for similar problem. You can look into this and can get more idea about filter plugin.

> [@JSON parsing problem](https://discuss.elastic.co/t/json-parsing-problem/166413):
>
> Hi there! My target is very simple (as it seems): I want logstash to receive a json from http, process this json with some scrypt, and bypass it as json next. I've started with json codec, but I've not found any way to properly access the root of event object, so I could not get the whole json content. So, I saw this [How to read JSON input sent to Http input plugin in filter section](https://discuss.elastic.co/t/how-to-read-json-input-sent-to-http-input-plugin-in-filter-section/118090) topic and tried to make config like in the answer. Let's say I've this config now: input { http { id =\> …

File in the command is /tmp/test.json.

Please do let me know if you need more help in this regard.

Regards,  
Harsh Bajaj

---

<div class="post-metadata">

**Author:** ![Raj\_Sekhar](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/raj_sekhar/32/48355_2.png) [@Raj\_Sekhar](https://discuss.elastic.co/u/Raj_Sekhar)\
**Post date:** [June 19, 2019, 11:42am UTC](https://discuss.elastic.co/t/logstash-is-replacing-with-how-can-i-get-on-the-output/186433/7 "2019-06-19T11:42:49Z")

</div>

Hi @harshbajaj16,

Below is my conf file after adding what you have suggested to add.  
input {  
stdin {  
codec =\> "json"  
}  
}

filter {

```
    if "_jsonparsefailure" in [tags] {drop { }} # for last record which comes with text->Impala query scan limit reached

```

ruby {code =\> 'open("/tmp/abc.json", "w") { |file| file.write(event.get("json").to\_json) }' }  
}

mutate {  
rename =\> {"[priority][name]" =\> "priority\_name"}  
rename =\> {"[priority][id]" =\> "priority\_id"}  
rename =\> {"[priority][self]" =\> "priority\_self"}  
}  
output {  
stdout {codec =\> rubydebug { metadata =\> true }}  
stdout { codec =\> dots }

file {  
codec =\> "json"  
path =\> ["/tmp/logstash\_output/test/%{key}.json"]  
write\_behavior =\> "overwrite"  
}

```
csv {fields => ["priority_name","priority_id","priority_self"]
	path => ["/tmp/output_csv/%{key}.csv"]
	write_behavior => "overwrite"
}

```

}

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [June 19, 2019, 1:15pm UTC](https://discuss.elastic.co/t/logstash-is-replacing-with-how-can-i-get-on-the-output/186433/8 "2019-06-19T13:15:56Z")

</div>

> [@Raj\_Sekhar](#):
>
> stdout {codec =\> rubydebug { metadata =\> true }}

rubydebug always displays data using =\> but that should not affect the format written to your file or csv output.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 17, 2019, 1:16pm UTC](https://discuss.elastic.co/t/logstash-is-replacing-with-how-can-i-get-on-the-output/186433/9 "2019-07-17T13:16:00Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
