# Nested Json Parsing

**URL:** <https://discuss.elastic.co/t/nested-json-parsing/161997>\
**Category:** Logstash\
**Created:** [December 24, 2018, 10:33am UTC](https://discuss.elastic.co/t/nested-json-parsing/161997 "2018-12-24T10:33:59Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Veena\_Kulkarni](https://avatars.discourse-cdn.com/v4/letter/v/edb3f5/32.png) [@Veena\_Kulkarni](https://discuss.elastic.co/u/Veena_Kulkarni)\
**Post date:** [December 24, 2018, 10:33am UTC](https://discuss.elastic.co/t/nested-json-parsing/161997/1 "2018-12-24T10:33:59Z")

</div>

Need help in parsing nested json .  
Below is sample json : {"debug\_level":"ERROR","debug\_timestamp":"2018-12-21 05:15:57,559","debug\_thread":"ScalaTest","debug\_file":"Audit1.scala", "debug\_line":"27","debug\_message":{"JobEndTime":"2018-12-22"}}  
{"debug\_level":"ERROR","debug\_timestamp":"2018-12-21 05:50:57,559","debug\_thread":"ScalaTest","debug\_file":"Audit1.scala", "debug\_line":"27","debug\_message":{"JobStartTime":"2018-12-21"}}

Logstash conf:  
input  
{  
azureblob  
{  
storage\_account\_name =\> "XXXX"  
storage\_access\_key =\> "XXX"  
container =\> "cleanloggingtest"  
codec =\> "line"

```
     type => azureblob
}

```

}  
filter {  
json {  
source =\> "message"  
target =\> "message"  
}  
json {  
source =\> "[message][debug\_message]"  
target =\> "[message][debug\_message]"  
}  
}  
output  
{  
stdout { }  
elasticsearch {  
hosts =\> "localhost:9200"  
index =\> "audittest-logs"  
}

}

Error:  
[2018-12-24T10:13:54,469][WARN][logstash.filters.json] Error parsing json {:source=\>"[message][debug\_message]", :raw=\>{"JobEndTime"=\>"2018-12-22"}, :exception=\>java.lang.ClassCastException: org.jruby.RubyHash cannot be cast to org.jruby.RubyIO}  
[2018-12-24T10:13:54,469][WARN][logstash.filters.json] Error parsing json {:source=\>"[message][debug\_message]", :raw=\>{"User"=\>"admin"}, :exception=\>java.lang.ClassCastException: org.jruby.RubyHash cannot be cast to org.jruby.RubyIO}  
[2018-12-24T10:13:54,469][WARN][logstash.filters.json] Error parsing json {:source=\>"[message][debug\_message]", :raw=\>{"JobStartTime"=\>"2018-12-21"}, :exception=\>java.lang.ClassCastException: org.jruby.RubyHash cannot be cast to org.jruby.RubyIO}  
[2018-12-24T10:13:56,013][WARN][logstash.outputs.elasticsearch] Could not index event to Elasticsearch. {:status=\>400, :action=\>["index", {:\_id=\>nil, :\_index=\>"audittest-logs", :\_type=\>"doc", :\_routing=\>nil}, #LogStash::Event:0x104e5fd3], :response=\>{"index"=\>{"\_index"=\>"audittest-logs", "\_type"=\>"doc", "\_id"=\>"6F6032cBrpO0OARc7kiA", "status"=\>400, "error"=\>{"type"=\>"mapper\_parsing\_exception", "reason"=\>"failed to parse [message]", "caused\_by"=\>{"type"=\>"illegal\_state\_exception", "reason"=\>"Can't get text on a START\_OBJECT at 1:115"}}}}}  
[2018-12-24T10:13:56,023][WARN][logstash.outputs.elasticsearch] Could not index event to Elasticsearch. {:status=\>400, :action=\>["index", {:\_id=\>nil, :\_index=\>"audittest-logs", :\_type=\>"doc", :\_routing=\>nil}, #LogStash::Event:0x6217eab3], :response=\>{"index"=\>{"\_index"=\>"audittest-logs", "\_type"=\>"doc", "\_id"=\>"516032cBrpO0OARc7kh-", "status"=\>400, "error"=\>{"type"=\>"mapper\_parsing\_exception", "reason"=\>"failed to parse [message]", "caused\_by"=\>{"type"=\>"illegal\_state\_exception", "reason"=\>"Can't get text on a START\_OBJECT at 1:115"}}}}}  
[2018-12-24T10:13:56,026][WARN][logstash.outputs.elasticsearch] Could not index event to Elasticsearch. {:status=\>400, :action=\>["index", {:\_id=\>nil, :\_index=\>"audittest-logs", :\_type=\>"doc", :\_routing=\>nil}, #LogStash::Event:0x78109d6a], :response=\>{"index"=\>{"\_index"=\>"audittest-logs", "\_type"=\>"doc", "\_id"=\>"6V6032cBrpO0OARc7kiB", "status"=\>400, "error"=\>{"type"=\>"mapper\_parsing\_exception", "reason"=\>"failed to parse [message]", "caused\_by"=\>{"type"=\>"illegal\_state\_exception", "reason"=\>"Can't get text on a START\_OBJECT at 1:115"}}}}}

---

<div class="post-metadata">

**Author:** ![Chris\_Lyons](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/chris_lyons/32/48107_2.png) [@Chris\_Lyons](https://discuss.elastic.co/u/Chris_Lyons)\
**Post date:** [December 24, 2018, 5:41pm UTC](https://discuss.elastic.co/t/nested-json-parsing/161997/2 "2018-12-24T17:41:34Z")

</div>

When using the JSON filter either move the parsed JSON to root or define a new root level field, seems to create issues when you attempt to overwrite the source field. This should solve your "Can't get text on a START\_OBJECT at 1:115" issue. To resolve your Cast exception only execute the filter once on the field.

> /usr/share/logstash/bin/logstash -e 'input {stdin{}} filter{json {source =\> "message" }} output{stdout {codec =\> rubydebug}}'

```
{
           "@version" => "1",
       "debug_thread" => "ScalaTest",
         "debug_file" => "Audit1.scala",
         "debug_line" => "27",
               "host" => "cernccwes15.cernerasp.com",
    "debug_timestamp" => "2018-12-21 05:15:57,559",
        "debug_level" => "ERROR",
      "debug_message" => {
        "JobStartTime" => "2018-12-22",
          "JobEndTime" => "2018-12-22"
    },
            "message" => "{\"debug_level\":\"ERROR\",\"debug_timestamp\":\"2018-12-21 05:15:57,559\",\"debug_thread\":\"ScalaTest\",\"debug_file\":\"Audit1.scala\", \"debug_line\":\"27\",\"debug_message\":{\"JobEndTime\":\"2018-12-22\",\"JobStartTime\":\"2018-12-22\"}}",
         "@timestamp" => 2018-12-24T17:34:13.803Z
}

```

The View in Kibana:

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/0/e/0e2fb915cc1ba12d671a19459823c3a701739106.png)

---

<div class="post-metadata">

**Author:** ![Veena\_Kulkarni](https://avatars.discourse-cdn.com/v4/letter/v/edb3f5/32.png) [@Veena\_Kulkarni](https://discuss.elastic.co/u/Veena_Kulkarni)\
**Post date:** [December 25, 2018, 7:22am UTC](https://discuss.elastic.co/t/nested-json-parsing/161997/3 "2018-12-25T07:22:23Z")

</div>

Thanks ..This solved my issue

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 22, 2019, 7:22am UTC](https://discuss.elastic.co/t/nested-json-parsing/161997/4 "2019-01-22T07:22:28Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
