# Parse json format logagregator logs in logstash

**URL:** <https://discuss.elastic.co/t/parse-json-format-logagregator-logs-in-logstash/182952>\
**Category:** Logstash\
**Created:** [May 27, 2019, 6:07pm UTC](https://discuss.elastic.co/t/parse-json-format-logagregator-logs-in-logstash/182952 "2019-05-27T18:07:41Z")\
**Posts on this page:** 1\
**Showing post:** 4

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [May 27, 2019, 7:46pm UTC](https://discuss.elastic.co/t/parse-json-format-logagregator-logs-in-logstash/182952/4 "2019-05-27T19:46:02Z")

</div>

I would break the line up using dissect, then use a json filter.

```
dissect { mapping => { "message" => "<%{pri}>%{f1} %{ts} [%{f2}] %{f3} ,%{[@metadata][json]}" } }
json { source => "[@metadata][json]" }
```

---

_[View the full topic](https://discuss.elastic.co/t/parse-json-format-logagregator-logs-in-logstash/182952)._
