# Parse specific field when JSON filter failed

**URL:** <https://discuss.elastic.co/t/parse-specific-field-when-json-filter-failed/305439>\
**Category:** Logstash\
**Created:** [May 24, 2022, 2:29am UTC](https://discuss.elastic.co/t/parse-specific-field-when-json-filter-failed/305439 "2022-05-24T02:29:03Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![austin0918](https://avatars.discourse-cdn.com/v4/letter/a/c68b51/32.png) [@austin0918](https://discuss.elastic.co/u/austin0918)\
**Post date:** [May 24, 2022, 2:29am UTC](https://discuss.elastic.co/t/parse-specific-field-when-json-filter-failed/305439/1 "2022-05-24T02:29:03Z")

</div>

I have some logs in JSON format with some offending key-value pairs that cause \_jsonparsefailure. I wanted to leave the log as is and just parse the timestamp. I tried the below config but failed to parse the timestamp field. I don't even see the ts1 field in results. Please advise.

```auto
filter {
	json {
		source => "message"
	}	
	date {
		match => ["ts","YYYY-MM-dd'T'HH:mm:ss.SSSZ","ISO8601"]
		target => "@timestamp"
	}

	if "_jsonparsefailure" in [tags] { 
		mutate {
			add_field => { "ts1" => "" }
        }
		ruby {
			code => '
				t = event.get("[ts]")
				event.set("[ts1]", t)
			'
		}
		date {
			match => ["ts1","YYYY-MM-dd'T'HH:mm:ss.SSSZ","ISO8601"]
			target => "@timestamp"
		}
	
	}
}

```

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [May 24, 2022, 2:53am UTC](https://discuss.elastic.co/t/parse-specific-field-when-json-filter-failed/305439/2 "2022-05-24T02:53:53Z")

</div>

> [@austin0918](#):
>
> I have some logs in JSON format with some offending key-value pairs that cause \_jsonparsefailure.

JSON parsing is all-or-nothing. If it gets an error then a json filter will not add any fields to the event. You might be able to do something like

```
grok { match => { "message" => '"ts"\s*:\s*"%{TIMESTAMP_ISO8601:ts}"' } }

```

to extract the ts field.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 21, 2022, 2:54am UTC](https://discuss.elastic.co/t/parse-specific-field-when-json-filter-failed/305439/3 "2022-06-21T02:54:07Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
