# Parsing a json file in logstash?

**URL:** <https://discuss.elastic.co/t/parsing-a-json-file-in-logstash/59597>\
**Category:** Logstash\
**Created:** [September 1, 2016, 8:27pm UTC](https://discuss.elastic.co/t/parsing-a-json-file-in-logstash/59597 "2016-09-01T20:27:32Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![ZillaG](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/zillag/32/10505_2.png) [@ZillaG](https://discuss.elastic.co/u/ZillaG)\
**Post date:** [September 1, 2016, 8:27pm UTC](https://discuss.elastic.co/t/parsing-a-json-file-in-logstash/59597/1 "2016-09-01T20:27:33Z")

</div>

I'm sending log messages from a remote client to my ELK server, and all is well. The logs come in a json format, that looks something like

```
{
        "type" => "trm-system",
        "host" => "susralcent09",
   "timestamp" => "2016-09-01T16:21:54.762437-04:00",
    "@version" => "1",
    "customer" => "cf_cim",
        "role" => "app_server",
  "sourcefile" => "/usr/share/tomcat/dist/logs/trm-system.log",
    .........
}

```

In my logstash configuration files, how do I parse the value of "sourcefile" to ultimately get the filename. e.g. trm-system.log? I then want to use the result (the filename) to create the file locally in some local path.

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [September 1, 2016, 8:29pm UTC](https://discuss.elastic.co/t/parsing-a-json-file-in-logstash/59597/2 "2016-09-01T20:29:30Z")

</div>

Well, that's not a JSON file so it'll take some work to parse. You might be able to use the kv filter. You'll also have to use a multiline codec to join an multiple physical lines into a single logical event.

---

<div class="post-metadata">

**Author:** ![ZillaG](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/zillag/32/10505_2.png) [@ZillaG](https://discuss.elastic.co/u/ZillaG)\
**Post date:** [September 1, 2016, 8:33pm UTC](https://discuss.elastic.co/t/parsing-a-json-file-in-logstash/59597/3 "2016-09-01T20:33:09Z")

</div>

Thanks. Well at least that's the output that's shown in my stdout. I have the following plugin in my output section of my Logstash configuration files.

```
input {
  tcp {
    port => 5514
    codec => json
  }
}

output {
  stdout {
    codec => rubydebug
  }
}
```

---

<div class="post-metadata">

**Author:** ![ZillaG](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/zillag/32/10505_2.png) [@ZillaG](https://discuss.elastic.co/u/ZillaG)\
**Post date:** [September 1, 2016, 8:42pm UTC](https://discuss.elastic.co/t/parsing-a-json-file-in-logstash/59597/4 "2016-09-01T20:42:14Z")

</div>

I changed the codec to json in the stdout plugin, and I get this

`{"type":"trm-system","host":"susralcent09","timestamp":"2016-09-01T16:37:50.221220-04:00","@version":"1","customer":"cf_cim","role":"app_server","sourcefile":"/usr/share/tomcat/dist/logs/trm-system.log", ....}`

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [September 2, 2016, 5:37am UTC](https://discuss.elastic.co/t/parsing-a-json-file-in-logstash/59597/5 "2016-09-02T05:37:57Z")

</div>

Okay, now I get what you're really asking. Your question is completely unrelated to JSON, you just want to extract the filename from a filepath. Use a grok filter that matches against the `sourcefile` field and captures everything after the last slash:

```nohighlight
grok {
  match => {
    "sourcefile" => "/(?<filename>[^/]+)$"
  }
}

```

---

<div class="post-metadata">

**Author:** ![ZillaG](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/zillag/32/10505_2.png) [@ZillaG](https://discuss.elastic.co/u/ZillaG)\
**Post date:** [September 6, 2016, 2:03pm UTC](https://discuss.elastic.co/t/parsing-a-json-file-in-logstash/59597/6 "2016-09-06T14:03:00Z")

</div>

Thanks! it worked.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 4:39am UTC](https://discuss.elastic.co/t/parsing-a-json-file-in-logstash/59597/7 "2017-07-06T04:39:39Z")

</div>


