# Parsing dictionary into json file

**URL:** <https://discuss.elastic.co/t/parsing-dictionary-into-json-file/191386>\
**Category:** Logstash\
**Created:** [July 19, 2019, 11:49am UTC](https://discuss.elastic.co/t/parsing-dictionary-into-json-file/191386 "2019-07-19T11:49:32Z")\
**Posts on this page:** 10\
**Page:** 1

<div class="post-metadata">

**Author:** ![saisimo02](https://avatars.discourse-cdn.com/v4/letter/s/edb3f5/32.png) [@saisimo02](https://discuss.elastic.co/u/saisimo02)\
**Post date:** [July 19, 2019, 11:49am UTC](https://discuss.elastic.co/t/parsing-dictionary-into-json-file/191386/1 "2019-07-19T11:49:32Z")

</div>

Hello,

I would like to parse a json file, my file looks like that:

```
file={"id":" *******","name":"test","alarm":{"error":2,"warning":3}}

```

using this filter:

```
json {
            source => "message"

    }

```

I get only these fields: **"alarm.error"** and **"alaram.warning"**

I would like to get this field: **alarm** , then in kibana I can select which level of alarm ("error","warning"...) and show the value of each level.

I tried to use **split** but I don't think we can split a dictionary.

Thank your for your help

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [July 19, 2019, 12:39pm UTC](https://discuss.elastic.co/t/parsing-dictionary-into-json-file/191386/2 "2019-07-19T12:39:57Z")

</div>

What you have is an alarm object that contains warning and error fields. In kibana that will show up as alarm.error and alarm.warning

```
      "name" => "test",
     "alarm" => {
    "warning" => 3,
      "error" => 2
},
        "id" => " *******",
```

---

<div class="post-metadata">

**Author:** ![saisimo02](https://avatars.discourse-cdn.com/v4/letter/s/edb3f5/32.png) [@saisimo02](https://discuss.elastic.co/u/saisimo02)\
**Post date:** [July 19, 2019, 1:07pm UTC](https://discuss.elastic.co/t/parsing-dictionary-into-json-file/191386/3 "2019-07-19T13:07:21Z")

</div>

Yes, but what I would like to have is a new filter named for example **alarmLevel** and inside there is the level : warning, error, info...  
the desired output is

```
 {"name" => "test",
 "alarmlevel" => "warning",
 "alarmValue"=>3,
 "id" => " *******"},
{"name" => "test",
     "alarmlevel" => "error",
     "alarmValue"=>2,
     "id" => " *******"}
```

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [July 19, 2019, 1:18pm UTC](https://discuss.elastic.co/t/parsing-dictionary-into-json-file/191386/4 "2019-07-19T13:18:06Z")

</div>

> [@saisimo02](#):
>
> {"id":"\*\*\*\*\*\*\*","name":"test","alarm":{"error":2,"warning":3}}

You could try this

```
    ruby {
        code => '
            a = []
            event.get("alarm").each { |k, v|
                h = Hash.new
                h["alarmLevel"] = k
                h["alarmValue"] = v
                a << h
            }
            event.remove("alarm")
            event.set("alarm", a)
        '
    }
    split { field => "alarm" }

```

If you need to then move the contents of alarm to the root level look at [this](https://discuss.elastic.co/t/how-to-dynamically-move-nested-key-value-to-root-level/180006/2).

---

<div class="post-metadata">

**Author:** ![luc1](https://avatars.discourse-cdn.com/v4/letter/l/e79b87/32.png) [@luc1](https://discuss.elastic.co/u/luc1)\
**Post date:** [July 22, 2019, 7:52am UTC](https://discuss.elastic.co/t/parsing-dictionary-into-json-file/191386/5 "2019-07-22T07:52:40Z")

</div>

Hello Badger,

This gives me the following Error:  
Ruby exception occured : undefined method 'each' for NilClass.

Which means the class 'alarm' doesn't exist right ?

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [July 22, 2019, 11:58am UTC](https://discuss.elastic.co/t/parsing-dictionary-into-json-file/191386/6 "2019-07-22T11:58:02Z")

</div>

> [@luc1](#):
>
> Which means the class 'alarm' doesn't exist right ?

Correct.

---

<div class="post-metadata">

**Author:** ![luc1](https://avatars.discourse-cdn.com/v4/letter/l/e79b87/32.png) [@luc1](https://discuss.elastic.co/u/luc1)\
**Post date:** [July 22, 2019, 12:05pm UTC](https://discuss.elastic.co/t/parsing-dictionary-into-json-file/191386/7 "2019-07-22T12:05:16Z")

</div>

"alarmMetadata":{"criticalAlarmCount":29,"majorAlarmCount":0,"minorAlarmCount":6,"warningAlarmCount":0}

If we added "[]" at the beginning and the end of the value of alarmMetadata with logstash, would it create the field "alarmMetadata" ? So the dictionary turns into a list..

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [July 22, 2019, 12:10pm UTC](https://discuss.elastic.co/t/parsing-dictionary-into-json-file/191386/8 "2019-07-22T12:10:37Z")

</div>

That would be {}, not

```
    mutate { gsub => ["message", "^", "{", "message", "$", "}"] }
    json { source => "message" }

```

will result in

```
"alarmMetadata" => {
    "criticalAlarmCount" => 29,
       "minorAlarmCount" => 6,
     "warningAlarmCount" => 0,
       "majorAlarmCount" => 0
},
```

---

<div class="post-metadata">

**Author:** ![luc1](https://avatars.discourse-cdn.com/v4/letter/l/e79b87/32.png) [@luc1](https://discuss.elastic.co/u/luc1)\
**Post date:** [July 22, 2019, 12:35pm UTC](https://discuss.elastic.co/t/parsing-dictionary-into-json-file/191386/9 "2019-07-22T12:35:08Z")

</div>

Thanks a lot

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 19, 2019, 12:35pm UTC](https://discuss.elastic.co/t/parsing-dictionary-into-json-file/191386/10 "2019-08-19T12:35:11Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
