# Parse json in string in json (nested json)

**URL:** <https://discuss.elastic.co/t/parse-json-in-string-in-json-nested-json/264569>\
**Category:** Logstash\
**Created:** [February 17, 2021, 12:37pm UTC](https://discuss.elastic.co/t/parse-json-in-string-in-json-nested-json/264569 "2021-02-17T12:37:15Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Romanian\_Coder](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/romanian_coder/32/84041_2.png) [@Romanian\_Coder](https://discuss.elastic.co/u/Romanian_Coder)\
**Post date:** [February 17, 2021, 12:37pm UTC](https://discuss.elastic.co/t/parse-json-in-string-in-json-nested-json/264569/1 "2021-02-17T12:37:15Z")

</div>

I have next json in input

```auto
 {
  "partitionId": 3,
  "value": {
    "name": "updatedPaymentInfo",
    "value": "{\"reference\":\"Z091702210000015\",\"transactionId\":\"CC11702210000020\",\"amountDTO\":{\"value\":10000,\"currency\":\"RUR\",\"minorUnits\":100},\"status\":\"V\",\"fields\":[{\"type\":\"CHAR\",\"value\":\"CC61401210000183\",\"name\":\"#HUMN\"}]}",
    "workflowKey": 2251799815337822,
    "workflowInstanceKey": 6755399442908649,
    "scopeKey": 6755399442908690
  },
  "sourceRecordPosition": 3744890,
  "valueType": "VARIABLE",
  "position": 3744892,
  "key": 6755399442908692,
  "timestamp": 1613564803494,
  "recordType": "EVENT",
  "intent": "CREATED",
  "rejectionType": "NULL_VAL",
  "rejectionReason": "",
  "brokerVersion": "0.26.0"
}

```

How I can parse nested json as string in top-level? I want in output get

```auto
{
  "partitionId": 3,
  "value": {
    "name": "updatedPaymentInfo",
    "workflowKey": 2251799815337822,
    "workflowInstanceKey": 6755399442908649,
    "scopeKey": 6755399442908690
  },
  "sourceRecordPosition": 3744890,
  "valueType": "VARIABLE",
  "position": 3744892,
  "key": 6755399442908692,
  "timestamp": 1613564803494,
  "recordType": "EVENT",
  "intent": "CREATED",
  "rejectionType": "NULL_VAL",
  "rejectionReason": "",
  "brokerVersion": "0.26.0",
  "variables" : {"reference":"Z091702210000015","transactionId":"CC11702210000020"\"amountDTO":{"value":10000,"currency":"RUR","minorUnits":100},"status":"V","fields":[{"type":"CHAR","value":"CC61401210000183","name":"#HUMN"}]}
}

```

I am trying by this filter, but nothing succeeded

```auto
 filter {
    json {
        source => "message"
    }
    if [valueType] == "JOB_BATCH" {
        drop { }
    }
    if [valueType] == "VARIABLE" {
       mutate{
            replace => ["value", "%{value}"]
            gsub => ['value','\n','']
        }

        if [value] =~ /^{.*}$/ {
            json { source => message }
        }
    }
    mutate {
        remove_field => ["syslog_hostname", "spanExportable", "timestamp"]
    }

}

```

---

<div class="post-metadata">

**Author:** ![val](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/val/32/138203_2.png) [@val](https://discuss.elastic.co/u/val)\
**Post date:** [February 17, 2021, 12:41pm UTC](https://discuss.elastic.co/t/parse-json-in-string-in-json-nested-json/264569/2 "2021-02-17T12:41:36Z")

</div>

Logstash provides a filter called [`json`](https://www.elastic.co/guide/en/logstash/current/plugins-filters-json.html) that you can use to parse the `[value][value]` field:

```
filter {
  json {
    source => "[value][value]"
    target => "variables"
  }
}

```

If you don't specify any target field, the parsed data will be stored at the root level.

In your case, I think you got it right, except that the field name is not correct, it should be `[value][value]` instead of `message`

---

<div class="post-metadata">

**Author:** ![Romanian\_Coder](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/romanian_coder/32/84041_2.png) [@Romanian\_Coder](https://discuss.elastic.co/u/Romanian_Coder)\
**Post date:** [February 17, 2021, 1:03pm UTC](https://discuss.elastic.co/t/parse-json-in-string-in-json-nested-json/264569/3 "2021-02-17T13:03:00Z")

</div>

Thanks! This solved my problem!

---

<div class="post-metadata">

**Author:** ![val](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/val/32/138203_2.png) [@val](https://discuss.elastic.co/u/val)\
**Post date:** [February 17, 2021, 1:03pm UTC](https://discuss.elastic.co/t/parse-json-in-string-in-json-nested-json/264569/4 "2021-02-17T13:03:42Z")

</div>

Cool, happy to help!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 17, 2021, 1:04pm UTC](https://discuss.elastic.co/t/parse-json-in-string-in-json-nested-json/264569/5 "2021-03-17T13:04:27Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
