# Logstash write to json no comma separator

**URL:** <https://discuss.elastic.co/t/logstash-write-to-json-no-comma-separator/280302>\
**Category:** Logstash\
**Created:** [August 3, 2021, 10:45am UTC](https://discuss.elastic.co/t/logstash-write-to-json-no-comma-separator/280302 "2021-08-03T10:45:54Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Hamza\_El\_Aouane](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/hamza_el_aouane/32/82411_2.png) [@Hamza\_El\_Aouane](https://discuss.elastic.co/u/Hamza_El_Aouane)\
**Post date:** [August 3, 2021, 10:45am UTC](https://discuss.elastic.co/t/logstash-write-to-json-no-comma-separator/280302/1 "2021-08-03T10:45:54Z")

</div>

Hello everyone.  
I am saving my logstash events to a json file as follow:

```auto
 file {
    path => "path\event-%{+yyyy.MM.dd}.json"
    codec => json

```

everything is fine, until today that I realised that the file is not formatted correctly.  
basically what is happening, is just writing line by line the events without wrapping them in `[]` or inserting any comma between the event. this is the output I am having in my json file

```auto
"{"sourceUserName":"value","@timestamp":"2021-08-03T00:37:09.180Z","name":"value","deviceAction":"value","userID":"value"}
{"sourceUserName":"value","@timestamp":"2021-08-03T00:39:13.445Z","name":"value","deviceAction":"value","userID":"value"}
{"

```

Is there any solution of I could have the json parsed correctly please?

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [August 3, 2021, 5:30pm UTC](https://discuss.elastic.co/t/logstash-write-to-json-no-comma-separator/280302/2 "2021-08-03T17:30:57Z")

</div>

An output processes each event independently of the others. A json codec outputs an event as a string of JSON. If you want to append a comma to the string you would have to encode the event into JSON yourself and then use a plain or line codec with a format option. I cannot think of a way to format the output as an array.

---

<div class="post-metadata">

**Author:** ![Hamza\_El\_Aouane](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/hamza_el_aouane/32/82411_2.png) [@Hamza\_El\_Aouane](https://discuss.elastic.co/u/Hamza_El_Aouane)\
**Post date:** [August 3, 2021, 6:56pm UTC](https://discuss.elastic.co/t/logstash-write-to-json-no-comma-separator/280302/3 "2021-08-03T18:56:11Z")

</div>

Thank you very much for your reply one more time.  
I have been looking into logstash documentations, and I cannot find much about this.

The only thing I could find is about this?

```auto
 file {
    codec => line {format => ","}

```

The file output, by default is a json file, which is perfect. and according to the documentation, we can customise the output using the `format`, which is great. Running that configuration, it works but it does not add the comma at the end of each event, but add one for each event at the end of the file.

But that's it, there is nothing regarding this.

You have more experience than me on this, maybe I am missing some documentation about this or how this file codec works?

Thank you so much for any clarification

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [August 3, 2021, 7:18pm UTC](https://discuss.elastic.co/t/logstash-write-to-json-no-comma-separator/280302/4 "2021-08-03T19:18:57Z")

</div>

You could try

```
filter {
    ruby { code => 'event.set("[@metadata][json]", event.to_hash.to_s)' }
}
output { stdout { codec => line { format => "%{[@metadata][json]}," } } }
```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 31, 2021, 7:19pm UTC](https://discuss.elastic.co/t/logstash-write-to-json-no-comma-separator/280302/5 "2021-08-31T19:19:28Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
