# Parse Json

**URL:** <https://discuss.elastic.co/t/parse-json/357405>\
**Category:** Logstash\
**Tags:** elastic-stack-monitoring\
**Created:** [April 15, 2024, 10:11am UTC](https://discuss.elastic.co/t/parse-json/357405 "2024-04-15T10:11:48Z")\
**Posts on this page:** 1\
**Showing post:** 3

<div class="post-metadata">

**Author:** ![Rios](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rios/32/95745_2.png) [@Rios](https://discuss.elastic.co/u/Rios)\
**Post date:** [April 15, 2024, 6:46pm UTC](https://discuss.elastic.co/t/parse-json/357405/3 "2024-04-15T18:46:29Z")

</div>

The same result, with "@timestamp" and "@version" which can be removed in the mutate remove\_field list :

```auto
filter {
  grok { match => { "message" => [",\"uri\":\"%{DATA:method} %{DATA}\",\"http_status\":"]} }
	 
  mutate { remove_field => ["event", "host", "message"] } 
}

```

The first version json/prune is better in case you decide to have all fields or change white\_list.  
The grok is simpler in case of you need only one field.

---

_[View the full topic](https://discuss.elastic.co/t/parse-json/357405)._
