# Logstash json filter parsed fields cannot be read within logstash

**URL:** <https://discuss.elastic.co/t/logstash-json-filter-parsed-fields-cannot-be-read-within-logstash/74598>\
**Category:** Logstash\
**Created:** [February 10, 2017, 5:07am UTC](https://discuss.elastic.co/t/logstash-json-filter-parsed-fields-cannot-be-read-within-logstash/74598 "2017-02-10T05:07:01Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![gringo](https://avatars.discourse-cdn.com/v4/letter/g/f19dbf/32.png) [@gringo](https://discuss.elastic.co/u/gringo)\
**Post date:** [February 10, 2017, 5:07am UTC](https://discuss.elastic.co/t/logstash-json-filter-parsed-fields-cannot-be-read-within-logstash/74598/1 "2017-02-10T05:07:01Z")

</div>

I am parsing a json file with "codec =\> json" in the input and " json { source=\>message }" in the filter.

I have also tried alternating the two.

The parsed fields cannot be read by logstash using "if [comment]". This will not work despite the being about to see the field with values with "stdout { codec =\> rubydebug }" as output

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [February 10, 2017, 7:39am UTC](https://discuss.elastic.co/t/logstash-json-filter-parsed-fields-cannot-be-read-within-logstash/74598/2 "2017-02-10T07:39:59Z")

</div>

Please show us an example event (from your stdout output) and your configuration.

---

<div class="post-metadata">

**Author:** ![gringo](https://avatars.discourse-cdn.com/v4/letter/g/f19dbf/32.png) [@gringo](https://discuss.elastic.co/u/gringo)\
**Post date:** [February 10, 2017, 7:55am UTC](https://discuss.elastic.co/t/logstash-json-filter-parsed-fields-cannot-be-read-within-logstash/74598/3 "2017-02-10T07:55:25Z")

</div>

Below is a section of the output

```
            "host" => "ksa-op",
            "type" => "NP-Alerts",
            "rule" => {
         "level" => 10,
       "comment" => "Windows error.......",
         "aadid" => 101010,
    "watereddtimes" => 1,
        "groups" => [
        [0] "redhat"
    ],
       "PCK_DOS" => [
        [0] "1.12.5"
    ]
},

```

The if statements below cannot be satisfied  
if [comment]  
if [level]

I need to rename the fields but it seems that it does not even exist

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [February 10, 2017, 8:15am UTC](https://discuss.elastic.co/t/logstash-json-filter-parsed-fields-cannot-be-read-within-logstash/74598/4 "2017-02-10T08:15:02Z")

</div>

`level` and `comment` are subfields of `rule`, i.e. you need to refer to them as `[rule][level]` and `[rule][comment]`.

---

<div class="post-metadata">

**Author:** ![gringo](https://avatars.discourse-cdn.com/v4/letter/g/f19dbf/32.png) [@gringo](https://discuss.elastic.co/u/gringo)\
**Post date:** [February 13, 2017, 5:37am UTC](https://discuss.elastic.co/t/logstash-json-filter-parsed-fields-cannot-be-read-within-logstash/74598/5 "2017-02-13T05:37:35Z")

</div>

Thanks for your help! Problem solved.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 13, 2017, 5:37am UTC](https://discuss.elastic.co/t/logstash-json-filter-parsed-fields-cannot-be-read-within-logstash/74598/6 "2017-03-13T05:37:56Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
