# Logstash json line by line

**URL:** <https://discuss.elastic.co/t/logstash-json-line-by-line/256787>\
**Category:** Logstash\
**Created:** [November 26, 2020, 2:46pm UTC](https://discuss.elastic.co/t/logstash-json-line-by-line/256787 "2020-11-26T14:46:46Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Didi\_Sisi](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/didi_sisi/32/79762_2.png) [@Didi\_Sisi](https://discuss.elastic.co/u/Didi_Sisi)\
**Post date:** [November 26, 2020, 2:46pm UTC](https://discuss.elastic.co/t/logstash-json-line-by-line/256787/1 "2020-11-26T14:46:47Z")

</div>

Hello;

I have this logstash.conf file:

input {  
exec {  
command =\> "python3 news.py"  
interval =\> 30  
codec =\> "json"  
}  
}

output {  
stdout { }  
}

without the code =\> json I obtain this result:

"message" =\> "  
{\n "authors": ,\n "id": "1",\n "publish\_date": "2020-10-16 23:01:45+00:00",\n "title": "Edition du 17/10/2020"\n}

\n{\n "authors": ,\n "id": "2",\n "publish\_date": "2020-11-26 10:00:13+00:00",\n "title": "Communication officielle"\n}

\n{\n "authors": ,\n "id": "3",\n "publish\_date": "2020-11-26 09:56:14+00:00",\n "title": "Non remboursé"\n}  
"

when I add codec =\> json

it returns me just the 1st element ie.  
"authors": ,  
"id": "1",  
"publish\_date": "2020-10-16 23:01:45+00:00",  
"title": "Edition du 17/10/2020"

but I need all the row, one by one jsonified.  
pliz how to do that?

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [November 26, 2020, 4:03pm UTC](https://discuss.elastic.co/t/logstash-json-line-by-line/256787/2 "2020-11-26T16:03:15Z")

</div>

Indeed, the codec will just consume the first JSON object. You could try

```
    # Remove newlines, because mutate+split will not match them
    mutate { gsub => ["message", "\n", ""] }
    # This removes the "}{"
    mutate { split => { "message" => "}{" } }
    split { field => "message" }
    # Add { at the start of the string and } at the end if not present
    if [message] =~ /^[^{]/ { mutate { gsub => ["message", "^", "{"] } }
    if [message] =~ /[^}]$/ { mutate { gsub => ["message", "$", "}"] } }
    json { source => "message" }
```

---

<div class="post-metadata">

**Author:** ![Didi\_Sisi](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/didi_sisi/32/79762_2.png) [@Didi\_Sisi](https://discuss.elastic.co/u/Didi_Sisi)\
**Post date:** [November 29, 2020, 9:04am UTC](https://discuss.elastic.co/t/logstash-json-line-by-line/256787/3 "2020-11-29T09:04:02Z")

</div>

Thank you, please, where to add this code in the Filter {}?

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [November 29, 2020, 2:44pm UTC](https://discuss.elastic.co/t/logstash-json-line-by-line/256787/4 "2020-11-29T14:44:45Z")

</div>

Yes, add those lines inside a filter {} section of your logstash configuration.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 27, 2020, 2:44pm UTC](https://discuss.elastic.co/t/logstash-json-line-by-line/256787/5 "2020-12-27T14:44:58Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
