# Parsing JSON Formatted messages to add fields and later use them for visualization

**URL:** <https://discuss.elastic.co/t/parsing-json-formatted-messages-to-add-fields-and-later-use-them-for-visualization/189398>\
**Category:** Kibana\
**Created:** [July 8, 2019, 5:48pm UTC](https://discuss.elastic.co/t/parsing-json-formatted-messages-to-add-fields-and-later-use-them-for-visualization/189398 "2019-07-08T17:48:48Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![Karthik2411](https://avatars.discourse-cdn.com/v4/letter/k/ed8c4c/32.png) [@Karthik2411](https://discuss.elastic.co/u/Karthik2411)\
**Post date:** [July 8, 2019, 5:48pm UTC](https://discuss.elastic.co/t/parsing-json-formatted-messages-to-add-fields-and-later-use-them-for-visualization/189398/1 "2019-07-08T17:48:48Z")

</div>

Hello ,

I am looking at an unindexed field in my kibana. It has all the info wrapped up in a message and that message is not searchable. Is there any way I can parse that JSON formatted message and add fields into that particular log and visualize that log as per my requirement??

Here's the message :

{"number\_of\_backups": 1, "app\_name": "premium\_webex\_v1\_\_422996", "region": "PAM DOCTOR TO ADD THIS", "data\_center": "DFW", "problem\_type": "PAM\_DOCTOR\_MISSING\_APP\_FROM\_appNameToHostNameMappingTable", "id": "premium\_webex\_v1\_\_422996"}

---

<div class="post-metadata">

**Author:** ![joshdover](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/joshdover/32/42020_2.png) [@joshdover](https://discuss.elastic.co/u/joshdover)\
**Post date:** [July 8, 2019, 6:50pm UTC](https://discuss.elastic.co/t/parsing-json-formatted-messages-to-add-fields-and-later-use-them-for-visualization/189398/2 "2019-07-08T18:50:46Z")

</div>

Hi there!

In order to visualize this data, you'll need to reindex this JSON data as nested fields in your index. You may be able to get some useful visualizations by adding [scripted fields](https://www.elastic.co/guide/en/kibana/current/scripted-fields.html) but the performance will be bad if this data is of any significant size and you will be limited in what you can do with it.

---

<div class="post-metadata">

**Author:** ![Karthik2411](https://avatars.discourse-cdn.com/v4/letter/k/ed8c4c/32.png) [@Karthik2411](https://discuss.elastic.co/u/Karthik2411)\
**Post date:** [July 8, 2019, 7:29pm UTC](https://discuss.elastic.co/t/parsing-json-formatted-messages-to-add-fields-and-later-use-them-for-visualization/189398/3 "2019-07-08T19:29:07Z")

</div>

What exactly do you mean when you talk about the performance being bad?? Is it like the loadtime will be greater or something else??

---

<div class="post-metadata">

**Author:** ![joshdover](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/joshdover/32/42020_2.png) [@joshdover](https://discuss.elastic.co/u/joshdover)\
**Post date:** [July 8, 2019, 7:41pm UTC](https://discuss.elastic.co/t/parsing-json-formatted-messages-to-add-fields-and-later-use-them-for-visualization/189398/4 "2019-07-08T19:41:09Z")

</div>

Rather than using the built index to retrieve data, a scripted field will have to run the script for every document in the index on the fly. If you have many thousands of documents this will be much slower than actually indexing the data up front.

---

<div class="post-metadata">

**Author:** ![Karthik2411](https://avatars.discourse-cdn.com/v4/letter/k/ed8c4c/32.png) [@Karthik2411](https://discuss.elastic.co/u/Karthik2411)\
**Post date:** [July 8, 2019, 8:11pm UTC](https://discuss.elastic.co/t/parsing-json-formatted-messages-to-add-fields-and-later-use-them-for-visualization/189398/5 "2019-07-08T20:11:35Z")

</div>

Thank you for the reply.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 5, 2019, 8:11pm UTC](https://discuss.elastic.co/t/parsing-json-formatted-messages-to-add-fields-and-later-use-them-for-visualization/189398/6 "2019-08-05T20:11:46Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
