# Parse string escaped JSON inside message

**URL:** <https://discuss.elastic.co/t/parse-string-escaped-json-inside-message/178212>\
**Category:** Logstash\
**Created:** [April 24, 2019, 9:40am UTC](https://discuss.elastic.co/t/parse-string-escaped-json-inside-message/178212 "2019-04-24T09:40:54Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![jfreeman](https://avatars.discourse-cdn.com/v4/letter/j/3e96dc/32.png) [@jfreeman](https://discuss.elastic.co/u/jfreeman)\
**Post date:** [April 24, 2019, 9:40am UTC](https://discuss.elastic.co/t/parse-string-escaped-json-inside-message/178212/1 "2019-04-24T09:40:54Z")

</div>

In logstash the event I receive from http input is

```
{  
   "event" => {  
      "@timestamp" =>2019-04-24T09:17:29.940 Z,
      "headers" => {  
         "http_host" =>"localhost:5055 ", " http_version"=>"HTTP/1.1",
         "connection" =>"close",
         "http_accept" =>nil,
         "request_path" =>"/",
         "http_user_agent" =>"httpget",
         "request_method" =>"POST",
         "content_length" =>"296",
         "accept_language" =>"application/json",
         "content_type" =>"application/x-www-form-urlencoded",
         "accept_encoding" =>"identity"
      },
      "message" =>" [  
         {  
            \"job_result\":{  
               \"job_template_name\":\"Test Job\",
               \"frequency\":\"daily\",
               \"job_id\":\"21751\",
               \"api_version\":\"v1\",
               \"template_id\":\"312\"
            }
         }
      ] ", " @version"=>"1",
      "host" =>"10.10.112.16"
   }
}

```

I want the content inside the message as parsed JSON like

```
{  
   "job_result":{  
      "job_template_name":"Test Job",
      "frequency":"daily",
      "job_id":"21751",
      "api_version":"v1",
      "template_id":"312"
   }
}

```

I used the below filter

```
json {
        source => "message"
        remove_field => ["headers"]
      }

```

but I see the output comes as

```
{  
   "@timestamp":"2019-04-24T09:17:21.959Z",
   "headers":{  
      "http_host":"localhost:5055",
      "http_version":"HTTP/1.1",
      "connection":"close",
      "http_accept":null,
      "request_path":"/",
      "http_user_agent":"httpget",
      "request_method":"POST",
      "content_length":"296",
      "accept_language":"application/json",
      "content_type":"application/x-www-form-urlencoded",
      "accept_encoding":"identity"
   },
   "message":"[{\"job\": {\"job_template_name\": \"Test Job\", \"frequency\": \"daily\", \"job_id\": \"21751\", \"api_version\": \"v1\", \"template_id\": \"312\"}}]",
   "@version":"1",
   "host":"10.51.222.16"
}

```

how do I get the content inside message as parsed JSON?

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [April 24, 2019, 1:24pm UTC](https://discuss.elastic.co/t/parse-string-escaped-json-inside-message/178212/2 "2019-04-24T13:24:11Z")

</div>

If the JSON is an array then target is not optional, since otherwise the json filter does not know what field to put the output in.

---

<div class="post-metadata">

**Author:** ![jfreeman](https://avatars.discourse-cdn.com/v4/letter/j/3e96dc/32.png) [@jfreeman](https://discuss.elastic.co/u/jfreeman)\
**Post date:** [April 24, 2019, 6:38pm UTC](https://discuss.elastic.co/t/parse-string-escaped-json-inside-message/178212/3 "2019-04-24T18:38:21Z")

</div>

Thanks. It worked!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 22, 2019, 6:38pm UTC](https://discuss.elastic.co/t/parse-string-escaped-json-inside-message/178212/4 "2019-05-22T18:38:27Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
