# Logstash ruby json parsing Issue

**URL:** <https://discuss.elastic.co/t/logstash-ruby-json-parsing-issue/188603>\
**Category:** Logstash\
**Created:** [July 3, 2019, 4:27am UTC](https://discuss.elastic.co/t/logstash-ruby-json-parsing-issue/188603 "2019-07-03T04:27:02Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![sukku77](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sukku77/32/52068_2.png) [@sukku77](https://discuss.elastic.co/u/sukku77)\
**Post date:** [July 3, 2019, 4:27am UTC](https://discuss.elastic.co/t/logstash-ruby-json-parsing-issue/188603/1 "2019-07-03T04:27:02Z")

</div>

Hi ,  
I need to poll http endpoint from logstash using http\_poller plugin and parse the json response to fetch the values and derive custom fields based on that.  
Below is my response sample json output that need to parsed and derive some fields based on that.

```
{ "response" : {
      "root": {
          "mode": "master",
          "node-id": "master.host.com"
          "connected-slave": ["slave.host1.corp.com","slave.host2.corp.com"] 
      }
   }
}

```

Below is my logstash (version 6.6.0) code in ruby:

```
if ([response]) {
  ruby {
    code => "
        require 'json'
        jsondata = event.get('response')
        parsed = JSON.parse(jsondata)
        parsed['root'].each { |hash|
         if #{hash['mode']} == 'master'
           event.set('df_mode', 'master')
         end
        }
    "
  }
}

```

While running this configuration, I am running into "Hash cannot convert to String ruby exception". And I tried other ways also but not helped though. Please provide some light or with sample code, how i could get the values of each key which i need to set as custom fields values.

Thanks  
Sukumar C

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [July 3, 2019, 1:50pm UTC](https://discuss.elastic.co/t/logstash-ruby-json-parsing-issue/188603/2 "2019-07-03T13:50:46Z")

</div>

Why use ruby? If you have valid JSON in a field called response (your JSON is not valid, it is missing a comma after the value of "node-id") you can parse it using a json filter then reference the fields directly

```
filter {
    json { source => "message" remove_field => ["message"] } }

    if [response][root][mode] == "master" {
        mutate { copy => { "[response][root][mode]" => "df_mode" } }
    }
}
```

---

<div class="post-metadata">

**Author:** ![sukku77](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sukku77/32/52068_2.png) [@sukku77](https://discuss.elastic.co/u/sukku77)\
**Post date:** [July 4, 2019, 8:26am UTC](https://discuss.elastic.co/t/logstash-ruby-json-parsing-issue/188603/3 "2019-07-04T08:26:09Z")

</div>

Reason for using ruby is i need to loop the response array with expected array for one of the json array field. If it is just copying the fields then i could have think of logstash code. I feel it is easy to do in ruby. Please advise.  
But I am able to achieve it using ruby now. Thanks

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 1, 2019, 8:26am UTC](https://discuss.elastic.co/t/logstash-ruby-json-parsing-issue/188603/4 "2019-08-01T08:26:11Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
