# Parsing array of json objects with logstash and injesting to elastic

**URL:** <https://discuss.elastic.co/t/parsing-array-of-json-objects-with-logstash-and-injesting-to-elastic/203197>\
**Category:** Logstash\
**Created:** [October 11, 2019, 9:16am UTC](https://discuss.elastic.co/t/parsing-array-of-json-objects-with-logstash-and-injesting-to-elastic/203197 "2019-10-11T09:16:31Z")\
**Posts on this page:** 1\
**Showing post:** 2

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [October 11, 2019, 4:03pm UTC](https://discuss.elastic.co/t/parsing-array-of-json-objects-with-logstash-and-injesting-to-elastic/203197/2 "2019-10-11T16:03:37Z")

</div>

None of the individual lines are valid JSON. The entire array is almost valid JSON (you need to remove the , that precedes the ]). You can read the entire file as a single event using a multiline codec with a pattern that never matches

```
codec => multiline { pattern => "^Spalanzani" negate => true what => previous auto_flush_interval => 1 multiline_tag => "" }

```

Then split the array

```
    split { field => "someField" }
    date { match => ["[someField][date]", "YYYY-MM-dd'T'HH:mm:ssZZ" ] }

```

If you need to move the contents of [someField] to the top level you can do it in a ruby filter similar to [this](https://discuss.elastic.co/t/move-subarrays-to-document-root/143876/2).

---

_[View the full topic](https://discuss.elastic.co/t/parsing-array-of-json-objects-with-logstash-and-injesting-to-elastic/203197)._
