# Logstash mutate string to JSON

**URL:** <https://discuss.elastic.co/t/logstash-mutate-string-to-json/163466>\
**Category:** Logstash\
**Created:** [January 9, 2019, 7:48am UTC](https://discuss.elastic.co/t/logstash-mutate-string-to-json/163466 "2019-01-09T07:48:26Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![ale.bollicino](https://avatars.discourse-cdn.com/v4/letter/a/ce7236/32.png) [@ale.bollicino](https://discuss.elastic.co/u/ale.bollicino)\
**Post date:** [January 9, 2019, 7:48am UTC](https://discuss.elastic.co/t/logstash-mutate-string-to-json/163466/1 "2019-01-09T07:48:26Z")

</div>

Hi all,

I have a Logstash installation that read JSON data from a Redis cache and send the events to an Elastic.  
Configuration it's very simple:

> input {  
> redis {  
> host =\> "my-redis"  
> data\_type =\> "list"  
> port =\> "6380"  
> key =\> "my-redis-key"  
> password =\> "my-password"  
> ssl =\> true  
> }  
> }  
> output {  
> elasticsearch {  
> index =\> "my-redis-log-%{+YYYY.MM.dd}"  
> hosts =\> ["elastic-1:9200","elastic-2:9200","elastic-3:9200",]  
> }  
> }

By default Redis input codec is JSON, this is good for me because messages are JSON.  
But the code that generates the JSON message in Redis has a bug, and fix at this time is not simple. 🙄

> {  
> "@timestamp": "2019-01-02T23:18:19.766+00:00",  
> "@version": "1",  
> "message": "Correct JSON",  
> "logger\_name": "com.redis.correct.controller.Message",  
> "thread\_name": "http-nio-8080-exec-12",  
> "version": "7.2.3",  
> "ip": "127.0.0.1",  
> "request\_id": "djqfqtjlz3vcz5k92ve3njdmg",  
> "user": "local-user-id",  
> "step": "input",  
> "payload": {  
> "number": "2",  
> "statusName": "full"  
> },  
> "name": "JSON",  
> "env": "prod"  
> }

The value of payload normally it's a nested JSON. So for our logic this it's correct.  
But in some event payload field it's written as string:

> {  
> "@timestamp": "2019-01-02T22:18:19.766+00:00",  
> "message": "Correct JSON",  
> "logger\_name": "com.redis.correct.controller.Message",  
> "thread\_name": "http-nio-8080-exec-12",  
> "version": "7.2.3",  
> "ip": "127.0.0.1",  
> "request\_id": "my-reuqest-id",  
> "user": "local-user-id",  
> "step": "input",  
> "payload": "{"number":"0","statusName":"null"}",  
> "name": "JSON",  
> "env": "prod"  
> }

This kind of events is rejected by Elastic during the indexing process.  
I have not found a solution at this time to mutate payload value when it's written as a string. Can you give me some hints to solve this problem, and correctly index all documents? (A bug in code side as told, it's not possible...)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 6, 2019, 7:48am UTC](https://discuss.elastic.co/t/logstash-mutate-string-to-json/163466/2 "2019-02-06T07:48:37Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
