# Parsing incoming Json Data

**URL:** <https://discuss.elastic.co/t/parsing-incoming-json-data/166952>\
**Category:** Logstash\
**Created:** [February 4, 2019, 12:04pm UTC](https://discuss.elastic.co/t/parsing-incoming-json-data/166952 "2019-02-04T12:04:06Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![aseemmittal](https://avatars.discourse-cdn.com/v4/letter/a/c4cdca/32.png) [@aseemmittal](https://discuss.elastic.co/u/aseemmittal)\
**Post date:** [February 4, 2019, 12:04pm UTC](https://discuss.elastic.co/t/parsing-incoming-json-data/166952/1 "2019-02-04T12:04:06Z")

</div>

Hi,

I have following incoming data  
{"event":[{"duration":"3","time":"2019-02-04 17:49:27","event":"achievementUnlock","message":"Achievement unlocked"},{"duration":"5","time":"2019-02-04 17:49:27","event":"achievementUnlock","message":"Achievement unlocked"},{"duration":"6","time":"2019-02-04 17:49:27","event":"achievementUnlock","message":"Achievement unlocked"}]}

Need to push each element of event array as a separate entry to elastic  
one document will look like this  
hits:[  
"\_source": {  
"@timestamp": "2019-02-04T09:44:20.379Z",  
"duration":"3"  
"time":2019-02-04  
"event": achievementUnlock  
"message":Achievement unlocked,  
"@version": "1"  
},  
{  
"\_source": {  
"@timestamp": "2019-02-04T09:44:20.379Z",  
"duration":"5"  
"time":2019-02-04  
"event": achievementUnlock  
"message":Achievement unlocked,  
"@version": "1"  
}  
}  
]

instead I am getting it in below format

"hits": [  
{

"\_source": {  
"event": {  
"time": "2019-02-04 17:43:29",  
"event": "achievementUnlock",  
"duration": "3",  
"message": "Achievement unlocked"  
},  
"@version": "1",  
"@timestamp": "2019-02-04T12:13:29.957Z"  
}  
},  
{

"\_source": {  
"event": {  
"time": "2019-02-04 17:43:29",  
"event": "achievementUnlock",  
"duration": "5",  
"message": "Achievement unlocked"  
},  
"@version": "1",  
"@timestamp": "2019-02-04T12:13:29.957Z"  
}  
}

logstash conf I am using is below

input{  
rabbitmq {  
host =\> "localhost"  
queue =\> "logger\_queues"  
durable =\>false  
codec=\>json

}

}  
filter{  
split {  
field =\> "event"  
}

```
date {
		match => ["time", "YYYY-MM-dd HH:mm:ss"]
		target => "@timestamp"
       
       
	}

```

}  
output{  
elasticsearch{  
hosts =\> "localhost"  
index =\> "test"  
document\_type =\> "test"  
}  
}

---

<div class="post-metadata">

**Author:** ![guyboertje](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/guyboertje/32/31592_2.png) [@guyboertje](https://discuss.elastic.co/u/guyboertje)\
**Post date:** [February 4, 2019, 12:31pm UTC](https://discuss.elastic.co/t/parsing-incoming-json-data/166952/2 "2019-02-04T12:31:18Z")

</div>

This is what the split filter does. The extracted fields will not be in the root of the doc, they will be in the event field.  
To move them into the root, add this to your `split` filter setting section:

```auto
  add_field => {
    "duration" => "%{[event][duration]}"
    "event" => "%{[event][event]}"
    # add all other fields similarly
  }
  remove_field => ["event"]

```

---

<div class="post-metadata">

**Author:** ![aseemmittal](https://avatars.discourse-cdn.com/v4/letter/a/c4cdca/32.png) [@aseemmittal](https://discuss.elastic.co/u/aseemmittal)\
**Post date:** [February 5, 2019, 4:30am UTC](https://discuss.elastic.co/t/parsing-incoming-json-data/166952/3 "2019-02-05T04:30:48Z")

</div>

Thanks... I got it working by below tweak to my incoming json.  
I made it as only a list of Json objects and used codec =\> json.  
And that did the trick

---

<div class="post-metadata">

**Author:** ![guyboertje](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/guyboertje/32/31592_2.png) [@guyboertje](https://discuss.elastic.co/u/guyboertje)\
**Post date:** [February 5, 2019, 10:38am UTC](https://discuss.elastic.co/t/parsing-incoming-json-data/166952/4 "2019-02-05T10:38:15Z")

</div>

Nice to know.

Yes, the JSON codec will break up an array of JSON objects into individual docs (events).

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 5, 2019, 10:38am UTC](https://discuss.elastic.co/t/parsing-incoming-json-data/166952/5 "2019-03-05T10:38:16Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
