# Logstash - Json file input question

**URL:** <https://discuss.elastic.co/t/logstash-json-file-input-question/232484>\
**Category:** Logstash\
**Created:** [May 13, 2020, 4:51pm UTC](https://discuss.elastic.co/t/logstash-json-file-input-question/232484 "2020-05-13T16:51:28Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Yawn](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yawn/32/52227_2.png) [@Yawn](https://discuss.elastic.co/u/Yawn)\
**Post date:** [May 13, 2020, 4:51pm UTC](https://discuss.elastic.co/t/logstash-json-file-input-question/232484/1 "2020-05-13T16:51:29Z")

</div>

Hello,

I am trying to load the following from a json file, and I had a couple of questions..

```
[
{
    "_index": "index-001",
    "_type": "xxx",
    "_id": "m2p2A3EBY37dRdt4jKyq",
    "_score": 1.0,
    "_source": {
                    "tags": [
                                 "tag 1",
                                 "tag 2",
                                 "tag 3"
                             ],
                    "eventtime": "1584817236",
                    "@timestamp": "2020-03-22T17:06:28.220Z"
                }
},
	{
    "_index": "index-002",
    "_type": "xxx",
    "_id": "m2p2A3EBY37dRdt4jKyz",
    "_score": 1.0,
    "_source": {
                    "tags": [
                                 "tag 1",
                                 "tag 2",
                                 "tag 3"
                             ],
                    "eventtime": "1584817200",
                    "@timestamp": "2020-03-22T17:06:28.220Z"
                }
}
]

```

I only need the data in \_source, with each item between "" as a field.

Do I need a multiline codec for this? And do I need to do something specific for the "tags" array?

Thanks

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [May 13, 2020, 10:11pm UTC](https://discuss.elastic.co/t/logstash-json-file-input-question/232484/2 "2020-05-13T22:11:27Z")

</div>

You can read the entire file as a single event using a multiline codec as described [here](https://discuss.elastic.co/t/parsing-array-of-json-objects-with-logstash-and-injesting-to-elastic/203197/2).

Then use a json filter with the target option set to parse the file contents. It will parse nested fields just fine,

Then use a split filter to split the array into multiple events.

Then use a prune filter with a whitelist to discard everything except \_source.

Then use a ruby filter as described in the link at the end of that post I linked to move the contents of \_source to the top level.

---

<div class="post-metadata">

**Author:** ![Yawn](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yawn/32/52227_2.png) [@Yawn](https://discuss.elastic.co/u/Yawn)\
**Post date:** [May 14, 2020, 4:39pm UTC](https://discuss.elastic.co/t/logstash-json-file-input-question/232484/3 "2020-05-14T16:39:16Z")

</div>

Thanks for the pointers. I will try that

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 11, 2020, 4:39pm UTC](https://discuss.elastic.co/t/logstash-json-file-input-question/232484/4 "2020-06-11T16:39:23Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
