# Parsed Multi Object in Json

**URL:** <https://discuss.elastic.co/t/parsed-multi-object-in-json/317705>\
**Category:** Logstash\
**Created:** [October 28, 2022, 6:20pm UTC](https://discuss.elastic.co/t/parsed-multi-object-in-json/317705 "2022-10-28T18:20:44Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![yuswanul](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yuswanul/32/101662_2.png) [@yuswanul](https://discuss.elastic.co/u/yuswanul)\
**Post date:** [October 28, 2022, 6:20pm UTC](https://discuss.elastic.co/t/parsed-multi-object-in-json/317705/1 "2022-10-28T18:20:44Z")

</div>

Hi there,

so i have a log look like this:

> 2022-10-27 08:39:02 [https-jsse-nio-9078-exec-7] INFO i.c.p.va.security.LoggerFilter - Response Body : {"responseCode":"00","responseDesc":"Approved","data":"{"vaNumber":"11122233344","accountName":"NAME","balance":"205569"}"}

i already apply grok filter like this

> match =\> { "message" =\> "%{TIMESTAMP\_ISO8601:timestamp} [%{NOTSPACE:program}] %{LOGLEVEL:logLevel}%{SPACE}%{NOTSPACE:serviceName} - Response Body : %{GREEDYDATA:responseBody}" }

and then i applied json plugin like this:

> json{  
> source =\> "responseBody"  
> target =\> "responseBody"  
> skip\_on\_invalid\_json =\> true  
> }

and the result is the "data" object from Response Body didn't parsed. i just got responseBody.responseCode & Desc. if i try to change the json filter to become like this:

> json{  
> source =\> "[responseBody][data]"  
> target =\> "responseBodydata"  
> skip\_on\_invalid\_json =\> true  
> }

it just produces the opposite of the previous result. can anyone help me? Thank you

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [October 28, 2022, 9:35pm UTC](https://discuss.elastic.co/t/parsed-multi-object-in-json/317705/2 "2022-10-28T21:35:55Z")

</div>

You JSON is not valid, and you have set the skip\_on\_invalid\_json option on the json filter, so it is skipping it.

```
{"responseCode":"00","responseDesc":"Approved","data":"{"vaNumber":"11122233344","accountName":"NAME","balance":"205569"}"}

```

If [data] is meant to be an encoded string it should be

```
{"responseCode":"00","responseDesc":"Approved","data":"{\"vaNumber\":\"11122233344\",\"accountName\":\"NAME\",\"balance\":\"205569\"}"}

```

and if [data] is meant to be a hash then

```
{"responseCode":"00","responseDesc":"Approved","data":{"vaNumber":"11122233344","accountName":"NAME","balance":"205569"}}

```

---

<div class="post-metadata">

**Author:** ![yuswanul](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yuswanul/32/101662_2.png) [@yuswanul](https://discuss.elastic.co/u/yuswanul)\
**Post date:** [October 28, 2022, 10:46pm UTC](https://discuss.elastic.co/t/parsed-multi-object-in-json/317705/3 "2022-10-28T22:46:36Z")

</div>

Ok, if my json is valid. How to do that?

> [@Badger](#):
>
> `{"responseCode":"00","responseDesc":"Approved","data":"{\"vaNumber\":\"11122233344\",\"accountName\":\"NAME\",\"balance\":\"205569\"}"}`

This is my log look like actually. i don't know why the \ character is dissapear in my post before. then, if my log look like this. was there any way to parse it? Thank you

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [October 28, 2022, 11:07pm UTC](https://discuss.elastic.co/t/parsed-multi-object-in-json/317705/4 "2022-10-28T23:07:00Z")

</div>

> [@yuswanul](#):
>
> Ok, if my json is valid. How to do that?

Well, for me

```
    json{ source => "responseBody" target => "responseBody" skip_on_invalid_json => true }
    json{ source => "[responseBody][data]" target => "[responseBody][data]" skip_on_invalid_json => true }

```

produces

```
"responseBody" => {
    "responseDesc" => "Approved",
            "data" => {
           "vaNumber" => "11122233344",
            "balance" => "205569",
        "accountName" => "NAME"
    },
    "responseCode" => "00"
},

```

---

<div class="post-metadata">

**Author:** ![yuswanul](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yuswanul/32/101662_2.png) [@yuswanul](https://discuss.elastic.co/u/yuswanul)\
**Post date:** [October 29, 2022, 12:26am UTC](https://discuss.elastic.co/t/parsed-multi-object-in-json/317705/5 "2022-10-29T00:26:43Z")

</div>

I think I've used that. it's just, I don't put it close like that. there is other source between them. does it have any effect?

Pada tanggal Sab, 29 Okt 2022 06.17, Badger via Discuss the Elastic Stack \<[notifications@elastic.discoursemail.com](mailto:notifications@elastic.discoursemail.com)\> menulis:

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [October 29, 2022, 12:32am UTC](https://discuss.elastic.co/t/parsed-multi-object-in-json/317705/6 "2022-10-29T00:32:56Z")

</div>

> [@yuswanul](#):
>
> does it have any effect?

Not unless they modify [responseBody].

---

<div class="post-metadata">

**Author:** ![yuswanul](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yuswanul/32/101662_2.png) [@yuswanul](https://discuss.elastic.co/u/yuswanul)\
**Post date:** [October 31, 2022, 3:15am UTC](https://discuss.elastic.co/t/parsed-multi-object-in-json/317705/7 "2022-10-31T03:15:50Z")

</div>

> [@Badger](#):
>
> ```auto
> json{ source => "responseBody" target => "responseBody" skip_on_invalid_json => true }
> json{ source => "[responseBody][data]" target => "[responseBody][data]" skip_on_invalid_json => true }
> 
> ```

i followed this, and i got this error:

> "error"=\>{"type"=\>"mapper\_parsing\_exception", "reason"=\>"failed to parse field [responseBody.data] of type [text] in document with id '6WQFLIQBueWIjhGITXWO'

`> "caused_by"=>{"type"=>"illegal_state_exception", "reason"=>"Can't get text on a START_OBJECT at 1:59"}}}}}`

I don't know why [responseBody][data] read as text. maybe it because the previous filter?

> [@Badger](#):
>
> `json{ source => "responseBody" target => "responseBody" skip_on_invalid_json => true }`

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [October 31, 2022, 4:42pm UTC](https://discuss.elastic.co/t/parsed-multi-object-in-json/317705/8 "2022-10-31T16:42:38Z")

</div>

See [this](https://discuss.elastic.co/t/getting-illegal-state-exception-error-while-pushing-logs-to-elasticsearch/290029/2) thread.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 28, 2022, 4:42pm UTC](https://discuss.elastic.co/t/parsed-multi-object-in-json/317705/9 "2022-11-28T16:42:56Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
