# Nested json as a string field

**URL:** <https://discuss.elastic.co/t/nested-json-as-a-string-field/164257>\
**Category:** Logstash\
**Created:** [January 15, 2019, 7:57am UTC](https://discuss.elastic.co/t/nested-json-as-a-string-field/164257 "2019-01-15T07:57:05Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![shwesinhan](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/shwesinhan/32/78663_2.png) [@shwesinhan](https://discuss.elastic.co/u/shwesinhan)\
**Post date:** [January 15, 2019, 7:57am UTC](https://discuss.elastic.co/t/nested-json-as-a-string-field/164257/1 "2019-01-15T07:57:05Z")

</div>

hi

i use json filter plugin in my logstash config.  
here if i face nested json, i got \_jsonparsefailure tag.  
my target is that i just want nested json as string. not another json.  
eg:

> { "agent": "Mozilla/5.0 (compatible; MSIE 9.0)", "ip": "192.168.24.44", request": "/index.html", "message": "{ "status": 200, "bytes": 52353 }"}

above log, i expect

> agent : Mozilla/5.0 (compatible; MSIE 9.0)  
> ip : 192.168.24.44"  
> request : /index.html  
> message : { "status": 200, "bytes": 52353 }

is that possible?

could anyone help me to point out this?

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [January 15, 2019, 3:11pm UTC](https://discuss.elastic.co/t/nested-json-as-a-string-field/164257/2 "2019-01-15T15:11:24Z")

</div>

> [@shwesinhan](#):
>
> { "agent": "Mozilla/5.0 (compatible; MSIE 9.0)", "ip": "192.168.24.44", request": "/index.html", "message": "{ "status": 200, "bytes": 52353 }"}

request needs a leading "

Even then, it does not appear to be valid JSON. No matter, we can fix things. We can modify that input so that the double quotes within the message field are escaped. That is, we need to transform it into

```
{ "agent": "Mozilla/5.0 (compatible; MSIE 9.0)", "ip": "192.168.24.44", request": "/index.html", "message": "{ \"status\": 200, \"bytes\": 52353 }"}

```

This is expensive (because it uses GREEDYDATA at the start of a pattern), fragile, and ugly. But for that exact input it works.

```
filter {
    grok { match => { "message" => ["%{GREEDYDATA:beginning}\"message\": \"(?<middle>[^}]+)}%{GREEDYDATA:end}" ] } }
    mutate { gsub => ["middle", '"', '\"'] }
    mutate { add_field => { "quotedmessage" => '%{beginning}"message": "%{middle}}%{end}' } }
    filter { json { source => "quotedmessage" } }
}

```

Alternatively, we can strip off the quotes around the message field, let the json filter parse it, then convert it back to a string.

```
filter {
    mutate { gsub => ["message", '"message": "', '"message": ', "message", '"([^"]+)$', '\1' ] }
    json { source => "message" }
    mutate { replace => { "message" => "%{message}" } }
}

```

---

<div class="post-metadata">

**Author:** ![shwesinhan](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/shwesinhan/32/78663_2.png) [@shwesinhan](https://discuss.elastic.co/u/shwesinhan)\
**Post date:** [January 16, 2019, 7:01am UTC](https://discuss.elastic.co/t/nested-json-as-a-string-field/164257/3 "2019-01-16T07:01:59Z")

</div>

thank you @Badger

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 13, 2019, 7:01am UTC](https://discuss.elastic.co/t/nested-json-as-a-string-field/164257/4 "2019-02-13T07:01:59Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
