# Nested json imposible to parse

**URL:** <https://discuss.elastic.co/t/nested-json-imposible-to-parse/88669>\
**Category:** Logstash\
**Created:** [June 8, 2017, 7:17am UTC](https://discuss.elastic.co/t/nested-json-imposible-to-parse/88669 "2017-06-08T07:17:11Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![fernando\_martinez](https://avatars.discourse-cdn.com/v4/letter/f/f07891/32.png) [@fernando\_martinez](https://discuss.elastic.co/u/fernando_martinez)\
**Post date:** [June 8, 2017, 7:17am UTC](https://discuss.elastic.co/t/nested-json-imposible-to-parse/88669/1 "2017-06-08T07:17:11Z")

</div>

Hi,

I have a nested json in a field like this:  
{  
....  
"host" =\> "[repo1.server.io](http://repo1.server.io)",  
"source" =\> "/mnt/centralizedlogs/logstash/netsec/48851f14d3e9/2017-06-08.txt",  
"message" =\> "{"@timestamp"=\>"2017-06-08T07:06:13.427Z", "@version"=\>"1", "beat"=\>{"hostname"=\>"48851f14d3e9", "name"=\>"48851f14d3e9", "version"=\>"5.4.1"}, "group"=\>"netsec", "host"=\>"48851f14d3e9", "identifier"=\>"asalog", "input\_type"=\>"log", "message"=\>"Jun 8 02:06:12 172.16.124.1 %ASA-4-106023: Deny tcp src OUTSIDE:104.168.182.194/59523 dst ProdWeb:10.246.165.119/3555 by access-group \"101\" [0x0, 0x0]", "offset"=\>44112925, "source"=\>"/var/log/asa/asa.log", "tags"=\>\<Java::JavaUtil::ArrayList:-1276964729 ["beats\_input\_codec\_plain\_applied"]\>, "type"=\>"log"}",  
....  
}  
I tried to do:

json  
{  
source =\> "message"  
target =\> "parsed"  
}  
also tried to add\_field with:

"%{[message][identifier]}"  
"%{[message][0][identifier]}"  
[message][identifier]

not working ☹

Also in the input i tried:

codec =\> "json"

Always I get a : [0] "\_jsonparsefailure",

any ideas? what I'm doing wrong?

Thank you very much!

---

<div class="post-metadata">

**Author:** ![fernando\_martinez](https://avatars.discourse-cdn.com/v4/letter/f/f07891/32.png) [@fernando\_martinez](https://discuss.elastic.co/u/fernando_martinez)\
**Post date:** [June 8, 2017, 7:33am UTC](https://discuss.elastic.co/t/nested-json-imposible-to-parse/88669/2 "2017-06-08T07:33:32Z")

</div>

I get: \<LogStash::Json::ParserError: Unexpected character ('=' (code 61)): was expecting a colon to separate field name and value

I guess I have to replace "=" for ":"...

thanks

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [June 8, 2017, 7:37am UTC](https://discuss.elastic.co/t/nested-json-imposible-to-parse/88669/3 "2017-06-08T07:37:28Z")

</div>

What you've shown us isn't JSON. It looks like something produced by Logstash's rubydebug codec. If so, why are you trying to parse it?

---

<div class="post-metadata">

**Author:** ![fernando\_martinez](https://avatars.discourse-cdn.com/v4/letter/f/f07891/32.png) [@fernando\_martinez](https://discuss.elastic.co/u/fernando_martinez)\
**Post date:** [June 8, 2017, 11:43am UTC](https://discuss.elastic.co/t/nested-json-imposible-to-parse/88669/4 "2017-06-08T11:43:37Z")

</div>

Hi

this is what i receive from filebeat which i'm not the owner...

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [June 8, 2017, 12:05pm UTC](https://discuss.elastic.co/t/nested-json-imposible-to-parse/88669/5 "2017-06-08T12:05:43Z")

</div>

Even though that is not valid JSON, it is quite close, so you may be able to convert it to valid JSON using a mutate filter. Something like this may work:

```auto
mutate {
    gsub => [
      "message", '=>', ':',
      "message", ':,', ':[],'
    ]
}

```

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [June 8, 2017, 12:06pm UTC](https://discuss.elastic.co/t/nested-json-imposible-to-parse/88669/6 "2017-06-08T12:06:19Z")

</div>

Well, Filebeat doesn't produce data that looks like that. Where does Filebeat get its data from?

---

<div class="post-metadata">

**Author:** ![fernando\_martinez](https://avatars.discourse-cdn.com/v4/letter/f/f07891/32.png) [@fernando\_martinez](https://discuss.elastic.co/u/fernando_martinez)\
**Post date:** [June 8, 2017, 12:08pm UTC](https://discuss.elastic.co/t/nested-json-imposible-to-parse/88669/7 "2017-06-08T12:08:08Z")

</div>

> [@magnusbaeck](#):
>
> oes Filebeat get its da

Hi

maybe the problem comes from the origin, I don't know.., But I will use the Christian solution, to get a valid JSON

Thanks

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 12:08pm UTC](https://discuss.elastic.co/t/nested-json-imposible-to-parse/88669/8 "2017-07-06T12:08:56Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
