# Parse Json data wrapped in "message" into event fields

**URL:** <https://discuss.elastic.co/t/parse-json-data-wrapped-in-message-into-event-fields/40072>\
**Category:** Logstash\
**Created:** [January 26, 2016, 12:20am UTC](https://discuss.elastic.co/t/parse-json-data-wrapped-in-message-into-event-fields/40072 "2016-01-26T00:20:53Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![sara](https://avatars.discourse-cdn.com/v4/letter/s/a5b964/32.png) [@sara](https://discuss.elastic.co/u/sara)\
**Post date:** [January 26, 2016, 12:20am UTC](https://discuss.elastic.co/t/parse-json-data-wrapped-in-message-into-event-fields/40072/1 "2016-01-26T00:20:53Z")

</div>

the issue is that the log in json format, sent from filebeat to logstash, the json data got wrapped in the message field and cannot be parsed into event fields.  
I have read a lot of posts on the similar issue over this weekend, and I followed the online document on the configuration of logstash:  
the following is my configuration:  
input {  
beats {  
port =\> 5044  
type =\> "mylog"  
}  
}

filter {  
if [type] == "mylog" {  
json {  
source =\> "message"  
}  
}  
}

output {  
stdout { codec =\> rubydebug }  
}

but I found that the log data is still the value of "message", and did not get parsed.  
I would be appreciated it very much if anyone could shed some light.  
thank you!

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [January 26, 2016, 7:02am UTC](https://discuss.elastic.co/t/parse-json-data-wrapped-in-message-into-event-fields/40072/2 "2016-01-26T07:02:01Z")

</div>

This is the correct way of doing it (you could also set `codec => json` in the beats input). What do you get when you try this?

---

<div class="post-metadata">

**Author:** ![sara](https://avatars.discourse-cdn.com/v4/letter/s/a5b964/32.png) [@sara](https://discuss.elastic.co/u/sara)\
**Post date:** [January 26, 2016, 4:37pm UTC](https://discuss.elastic.co/t/parse-json-data-wrapped-in-message-into-event-fields/40072/3 "2016-01-26T16:37:52Z")

</div>

from Kibana, I can see the json data in "message", but I cannot find keys/values from the json data in the list of the fields.  
I validated the json data via /logstash -f mytest.conf manually. The json data got parsed correctly. Is there a way that the json data gets parsed without manual way? I have read many posts but I cannot figure a solution for the specific issue. I believe I must have missed something, and I need help to know what I missed.

thank you.

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [January 27, 2016, 7:21am UTC](https://discuss.elastic.co/t/parse-json-data-wrapped-in-message-into-event-fields/40072/4 "2016-01-27T07:21:14Z")

</div>

Please give an example of the `stdout { codec => rubydebug }` output so that we can see _exactly_ what the resulting events look like.

---

<div class="post-metadata">

**Author:** ![sara](https://avatars.discourse-cdn.com/v4/letter/s/a5b964/32.png) [@sara](https://discuss.elastic.co/u/sara)\
**Post date:** [February 3, 2016, 5:21am UTC](https://discuss.elastic.co/t/parse-json-data-wrapped-in-message-into-event-fields/40072/5 "2016-02-03T05:21:00Z")

</div>

Logstash startup completed  
{  
"message" =\> "{"test1":"testvalue1","mymessage":{"mtest1":"test"}}",  
"@version" =\> "1",  
"@timestamp" =\> "2016-02-03T04:42:08.507Z",  
"host" =\> "...",  
"path" =\> "/mytest1.log",  
"test1" =\> "testvalue1",  
"mymessage" =\> {  
"mtest1" =\> "test"  
}  
}

elasticsearch result processed directly from logstash:  
"\_source":{"message":"{"test1":"testvalue1","mymessage":{"mtest1":"test"}}","@version":"1","@timestamp":"2016-02-03T04:42:08.507Z","host”:”…”,”test1":"testvalue1","mymessage":{"mtest1":"test"}}

\*\* the json data got parsed.

* * *

the result from elasticsearch shipped from filebeat to logstash:  
"\_source":{"@metadata":{"beat":"filebeat","type”:”my-log"},"@timestamp":"2016-02-03T04:46:30.234Z","beat":{"hostname”:”…”,”name”:”…”},”count":1,"message":"{"test1":"testvalue1","mymessage":{"mtest1":"test"}}","offset":0,"type”:”my-log"}

\*\* the json data did not get parsed.  
I guess my question is, why does the json data not get parsed by the logstash if the json data is sent by filebeat to the logstash?

thank you!

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [February 3, 2016, 7:03am UTC](https://discuss.elastic.co/t/parse-json-data-wrapped-in-message-into-event-fields/40072/6 "2016-02-03T07:03:01Z")

</div>

> elasticsearch result processed directly from logstash:

What do you mean? If you use a file input in Logstash instead of Filebeat?

I don't think the evidence is consistent. How come there's a `type` field here:

> "\_source":{"@metadata":{"beat":"filebeat","type”:”my-log"},"@timestamp":"2016-02-03T04:46:30.234Z","beat":{"hostname”:”…”,”name”:”…”},”count":1,"message":"{"test1":"testvalue1","mymessage":{"mtest1":"test"}}","offset":0,"type”:”my-log"}

But not here:

> {  
> "message" =\> "{"test1":"testvalue1","mymessage":{"mtest1":"test"}}",  
> "@version" =\> "1",  
> "@timestamp" =\> "2016-02-03T04:42:08.507Z",  
> "host" =\> "...",  
> "path" =\> "/mytest1.log",  
> "test1" =\> "testvalue1",  
> "mymessage" =\> {  
> "mtest1" =\> "test"  
> }  
> }

Also, the JSON payload is parsed in the second example but not in the first.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 5:13am UTC](https://discuss.elastic.co/t/parse-json-data-wrapped-in-message-into-event-fields/40072/7 "2017-07-06T05:13:18Z")

</div>


