# Logstash Unable to parse dot inside a json

**URL:** <https://discuss.elastic.co/t/logstash-unable-to-parse-dot-inside-a-json/63294>\
**Category:** Logstash\
**Created:** [October 18, 2016, 12:25pm UTC](https://discuss.elastic.co/t/logstash-unable-to-parse-dot-inside-a-json/63294 "2016-10-18T12:25:27Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![javatechy](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/javatechy/32/8763_2.png) [@javatechy](https://discuss.elastic.co/u/javatechy)\
**Post date:** [October 18, 2016, 12:25pm UTC](https://discuss.elastic.co/t/logstash-unable-to-parse-dot-inside-a-json/63294/1 "2016-10-18T12:25:27Z")

</div>

I am trying to parse my CSV fomatted logs using logstash. I am facing problem in parsing a json which contains dot(.) in the key of json.

I took reference from this link [ref](https://discuss.elastic.co/t/field-name-cannot-contain/33251/25) but didn't work for me

My sample input is

> 2016-10-17 10:44:37,733|null|{"k1.k2.k3.k4":"val"}|{"requestId":"9s,ss4"}|{"status":"PG601"}|1732|{"testKey": "\<?xml version="}

My filter code is :

> filter {  
> ruby {  
> code =\> "  
> event.to\_hash.keys.each { |k| event[k.sub('.','\_')] = event.remove(k) if k.include?'.' }  
> "  
> }

> ```
> mutate { gsub => ["message","\"","'"] }
> csv {
> columns => ["TIMESTAMP","URI","HEADERS","REQUEST","RESPONSE","RESPONSE_TIME","INTER_RESPONSE"]
> separator => "|"
> }
> mutate {
> add_field => { "INDEX_NAME" => "pg_request_response" }
> }
> mutate { gsub => ["REQUEST", "'", '"']}
> json { source => "REQUEST" target => "request" }
> 
> ```

> ```
> mutate { gsub => ["RESPONSE", "'", '"']}
> json { source => "RESPONSE" target => "response" }
> 
> ```

> ```
> mutate { gsub => ["HEADERS", "'", '"']}
> json { source => "HEADERS" target => "headers" }
> mutate { gsub => ["INTER_RESPONSE", "'", '"'] }
> json { source => "INTER_RESPONSE" }
> #date { match => ["TIMESTAMP", "YYYY-MM-dd HH:mm:ss,SSS"] }
> 
> ```
> 
> }

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [October 20, 2016, 7:48pm UTC](https://discuss.elastic.co/t/logstash-unable-to-parse-dot-inside-a-json/63294/2 "2016-10-20T19:48:09Z")

</div>

> I took reference from this link ref but didn't work for me

Please be more specific. And what's wrong with the de\_dot filter?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 4:33am UTC](https://discuss.elastic.co/t/logstash-unable-to-parse-dot-inside-a-json/63294/3 "2017-07-06T04:33:22Z")

</div>


