# Parse elastic response json into CSV

**URL:** <https://discuss.elastic.co/t/parse-elastic-response-json-into-csv/204347>\
**Category:** Logstash\
**Created:** [October 20, 2019, 10:06am UTC](https://discuss.elastic.co/t/parse-elastic-response-json-into-csv/204347 "2019-10-20T10:06:15Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![raviep](https://avatars.discourse-cdn.com/v4/letter/r/5f8ce5/32.png) [@raviep](https://discuss.elastic.co/u/raviep)\
**Post date:** [October 20, 2019, 10:06am UTC](https://discuss.elastic.co/t/parse-elastic-response-json-into-csv/204347/1 "2019-10-20T10:06:15Z")

</div>

Hi,

I need to parse elastic search response JSON to CSV using logstash. Here I need only fields parameters to go into CSV file.

{  
"took" : 11,  
"timed\_out" : false,  
"\_shards" : {  
"total" : 3,  
"successful" : 3,  
"skipped" : 0,  
"failed" : 0  
},  
"hits" : {  
"total" : 2434,  
"max\_score" : null,  
"hits" : [  
{  
"\_index" : "index1",  
"\_type" : "type1",  
"\_id" : "id",  
"\_score" : null,  
"fields" : {  
"field1" : [  
"454"  
],  
"field2" : [  
"777"  
],  
"field3" : [  
"6767"  
]  
}  
}  
{  
"\_index" : "index1",  
"\_type" : "type1",  
"\_id" : "id2",  
"\_score" : null,  
"fields" : {  
"field1" : [  
"242"  
],  
"field2" : [  
"434"  
],  
"field3" : [  
"2323"  
]  
}  
}  
]  
}  
}

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [October 20, 2019, 1:05pm UTC](https://discuss.elastic.co/t/parse-elastic-response-json-into-csv/204347/2 "2019-10-20T13:05:00Z")

</div>

Your JSON is not valid, since the entries in the array are not separated by a comma. If you fix that you can parse it using a json filter, then split it

```
split { field => "[hits][hits]" }

```

and then use a csv output with

```
 fields => ["[hits][hits][fields][field1][0]", "[hits][hits][fields][field2][0]", "[hits][hits][fields][field3][0]" ]
```

---

<div class="post-metadata">

**Author:** ![raviep](https://avatars.discourse-cdn.com/v4/letter/r/5f8ce5/32.png) [@raviep](https://discuss.elastic.co/u/raviep)\
**Post date:** [October 21, 2019, 5:59am UTC](https://discuss.elastic.co/t/parse-elastic-response-json-into-csv/204347/3 "2019-10-21T05:59:29Z")

</div>

Thanks for your quick reply, it works fine and I got expected result.😀

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 18, 2019, 5:59am UTC](https://discuss.elastic.co/t/parse-elastic-response-json-into-csv/204347/4 "2019-11-18T05:59:33Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
