# Parse json message events using split filter

**URL:** <https://discuss.elastic.co/t/parse-json-message-events-using-split-filter/169673>\
**Category:** Logstash\
**Created:** [February 23, 2019, 4:29pm UTC](https://discuss.elastic.co/t/parse-json-message-events-using-split-filter/169673 "2019-02-23T16:29:35Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![saroja](https://avatars.discourse-cdn.com/v4/letter/s/eada6e/32.png) [@saroja](https://discuss.elastic.co/u/saroja)\
**Post date:** [February 23, 2019, 4:29pm UTC](https://discuss.elastic.co/t/parse-json-message-events-using-split-filter/169673/1 "2019-02-23T16:29:35Z")

</div>

Continuing the discussion from [Split nested json array](https://discuss.elastic.co/t/split-nested-json-array/147969):

How to parse a json message events :-

1. If any json key value, passed as null, It would not be parsed by the split filter and wouldn't be render.See the below json line and check the element name : FilterValue.  
json file name : testdata-1.1.json  
============================  
{"VectorList": [{"LocalizationId": 60,"ServiceId": 2,"Date": "2018-09-11T00:00:00","IsAvailable": true,"FreeTermCount": 86,"SegmentFreeTermCount": 87, "FilterValue": null}]}

Index output:-  
{  
"\_index": "logstash-2019.02.23",  
"_type": "doc",  
"id": "aisEG2kBN4-7njBKFM_",  
"\_score": 1,  
"\_source": {  
"ServiceId": "2",  
"IsAvailable": "true",  
"Date": "2018-09-11T00:00:00",  
"@timestamp": "2019-02-23T15:40:43.820Z",  
"@version": "1",  
"path": "C:/Users/n487610/LogStash/logstash-6.2.3/input\_json\_files/testdata-1.1.json",  
"type": "MyLog",  
"FreeTermCount": "86",  
"host": "Z507B-9D70-B00E",  
"FilterValue": "%{[VectorList][FilterValue]}", # willn't processed the value  
"SegmentFreeTermCount": "87",  
"VectorList": {  
"ServiceId": 2,  
"IsAvailable": true,  
"Date": "2018-09-11T00:00:00",  
"FreeTermCount": 86,  
"FilterValue": null,  
"SegmentFreeTermCount": 87,  
"LocalizationId": 60  
},  
"LocalizationId": "60"  
}  
}

2.If any json key value, passed as "null" (with double quotes), It would be parsed successfully and render "null" value .See the below json line and check the element name : FilterValue.  
json file name : testdata-1.2.json :-

{"VectorList": [{"LocalizationId": 60,"ServiceId": 2,"Date": "2018-09-11T00:00:00","IsAvailable": true,"FreeTermCount": 86,"SegmentFreeTermCount": 87, "FilterValue": "null"}]}

Index output:-  
{  
"\_index": "logstash-2019.02.23",  
"\_type": "doc",  
"\_id": "aysHG2kBN4-7njBKus\_a",  
"\_score": 1,  
"\_source": {  
"ServiceId": "2",  
"IsAvailable": "true",  
"Date": "2018-09-11T00:00:00",  
"@timestamp": "2019-02-23T15:44:45.019Z",  
"@version": "1",  
"path": "C:/Users/n487610/LogStash/logstash-6.2.3/input\_json\_files/testdata-1.2.json",  
"type": "MyLog",  
"FreeTermCount": "86",  
"host": "Z507B-9D70-B00E",  
"FilterValue": "null", # parse the value successfully  
"SegmentFreeTermCount": "87",  
"VectorList": {  
"ServiceId": 2,  
"IsAvailable": true,  
"Date": "2018-09-11T00:00:00",  
"FreeTermCount": 86,  
"FilterValue": "null",  
"SegmentFreeTermCount": 87,  
"LocalizationId": 60  
},  
"LocalizationId": "60"  
}  
}

1. Use the below filebeat config to create index in elastic search.   
config details:-

input {  
file {  
type =\> "MyLog"  
path =\> ["C:/Users/n487610/LogStash/logstash-6.2.3/input\_json\_files/\*.json"]  
start\_position =\> "beginning"  
codec =\> "json"  
}  
}

filter {  
json {  
source =\> "message"  
}   
split {  
field =\> "[VectorList]"  
terminator=\> ","  
}

mutate {  
add\_field =\> {  
"LocalizationId" =\> "%{[VectorList][LocalizationId]}"  
"ServiceId" =\> "%{[VectorList][ServiceId]}"  
"Date" =\> "%{[VectorList][Date]}"  
"IsAvailable" =\> "%{[VectorList][IsAvailable]}"  
"FreeTermCount" =\> "%{[VectorList][FreeTermCount]}"  
"SegmentFreeTermCount" =\> "%{[VectorList][SegmentFreeTermCount]}"  
"FilterValue" =\> "%{[VectorList][FilterValue]}"  
}  
remove\_field =\> ["[message]" ]  
}  
}

output {  
elasticsearch {  
index =\> "logstash-%{+yyyy.MM.dd}"  
hosts =\> ["localhost:9200"]  
}   
file {  
path =\> "C:\Users\n487610\LogstashOutput\testing-out-%{+YYYY.MM.dd}"  
}  
stdout {  
codec =\> "rubydebug"  
}  
}

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [February 23, 2019, 4:32pm UTC](https://discuss.elastic.co/t/parse-json-message-events-using-split-filter/169673/2 "2019-02-23T16:32:54Z")

</div>

What is your question?

BTW, you should either have a json codec or a json filter. It would be very unusual to need both.

---

<div class="post-metadata">

**Author:** ![saroja](https://avatars.discourse-cdn.com/v4/letter/s/eada6e/32.png) [@saroja](https://discuss.elastic.co/u/saroja)\
**Post date:** [February 23, 2019, 4:46pm UTC](https://discuss.elastic.co/t/parse-json-message-events-using-split-filter/169673/3 "2019-02-23T16:46:18Z")

</div>

> [@Badger](#):
>
> uld be very unusual to need both.

I don't want to process complete json event message into Elasticsearch.  
Need to parse and filter the json message after getting the message through http\_input plugin.  
do i use both json codec and json filter plugin ??

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [February 23, 2019, 6:33pm UTC](https://discuss.elastic.co/t/parse-json-message-events-using-split-filter/169673/4 "2019-02-23T18:33:07Z")

</div>

You would only need both if your JSON contains a field called message, which itself is JSON. Like this:

{"message":"{ \"foo\" : 1}"}

Otherwise use one or the other.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 23, 2019, 6:33pm UTC](https://discuss.elastic.co/t/parse-json-message-events-using-split-filter/169673/5 "2019-03-23T18:33:10Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
