# Parsing json from http\_poller and CiscoAMP API

**URL:** <https://discuss.elastic.co/t/parsing-json-from-http-poller-and-ciscoamp-api/78390>\
**Category:** Logstash\
**Created:** [March 13, 2017, 5:32pm UTC](https://discuss.elastic.co/t/parsing-json-from-http-poller-and-ciscoamp-api/78390 "2017-03-13T17:32:27Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Karn\_Griffen](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/karn_griffen/32/16337_2.png) [@Karn\_Griffen](https://discuss.elastic.co/u/Karn_Griffen)\
**Post date:** [March 13, 2017, 5:32pm UTC](https://discuss.elastic.co/t/parsing-json-from-http-poller-and-ciscoamp-api/78390/1 "2017-03-13T17:32:27Z")

</div>

I am attempting to pull data from CiscoAMP, I am able to connect and grab the data with http\_poller, but I am having a hard time understanding how to break out the subfields.

Products:  
Logstash (5.2.0)  
Elastic Cloud

All the data I want gets put into a single field called 'data'. I would like to break this field out further into other fields. The raw json looks like this:

{  
"version": "v1.1.0",  
"metadata": {  
"links": {  
"self": "[https://api.amp.cisco.com/v1/events?limit=2](https://api.amp.cisco.com/v1/events?limit=2)",  
"next": "[https://api.amp.cisco.com/v1/events?limit=2\u0026offset=2](https://api.amp.cisco.com/v1/events?limit=2%5Cu0026offset=2)"  
},  
"results": {  
"total": 19127,  
"current\_item\_count": 2,  
"index": 0,  
"items\_per\_page": 2  
}  
},  
"data": [  
{  
"id": 1489425771450000746,  
"timestamp": 1489425771,  
"timestamp\_nanoseconds": 450000000,  
"date": "2017-03-13T17:22:51+00:00",  
"event\_type": "Vulnerable Application Detected",  
"event\_type\_id": 1107296279,  
"group\_guids": [  
"5caccfca-ac7f-42dc-b39c-9d1f3f717676"  
],  
"computer": {  
"connector\_guid": "35d760f2-0dca-4cee-811f-5fafd7ac1b94",  
"hostname": "[GSG-01636.gsg.grantstreet.com](http://GSG-01636.gsg.grantstreet.com)",  
"active": true,  
"links": {  
"computer": "[https://api.amp.cisco.com/v1/computers/35d760f2-0dca-4cee-811f-5fafd7ac1b94](https://api.amp.cisco.com/v1/computers/35d760f2-0dca-4cee-811f-5fafd7ac1b94)",  
"trajectory": "[https://api.amp.cisco.com/v1/computers/35d760f2-0dca-4cee-811f-5fafd7ac1b94/trajectory](https://api.amp.cisco.com/v1/computers/35d760f2-0dca-4cee-811f-5fafd7ac1b94/trajectory)",  
"group": "[https://api.amp.cisco.com/v1/groups/5caccfca-ac7f-42dc-b39c-9d1f3f717676](https://api.amp.cisco.com/v1/groups/5caccfca-ac7f-42dc-b39c-9d1f3f717676)"  
}  
},  
"file": {  
"disposition": "Clean",  
"identity": {  
"sha256": "c8bf1abdc9ede0264ed7a818f61bb84ba2d42f160fdea45de6ed6ef816a6425e"  
},  
"file\_name": "chrome.exe"  
},  
"vulnerabilities": [  
{  
"name": "Google Chrome",  
"version": "55.0.2883.87",  
"cve": "CVE-2017-5019",  
"score": 6.8,  
"url": "[https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2017-5019](https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2017-5019)"  
},  
{  
"cve": "CVE-2017-5012",  
"score": 6.8,  
"url": "[https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2017-5012](https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2017-5012)"  
},  
{  
"cve": "CVE-2017-5014",  
"score": 6.8,  
"url": "[https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2017-5014](https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2017-5014)"  
},  
{  
"cve": "CVE-2017-5009",  
"score": 6.8,  
"url": "[https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2017-5009](https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2017-5009)"  
}  
]  
},  
{  
"id": 6396978716487974919,  
"timestamp": 1489412608,  
"timestamp\_nanoseconds": 325273163,  
"date": "2017-03-13T13:43:28+00:00",  
"event\_type": "Policy Update Failure",  
"event\_type\_id": 2164260866,  
"group\_guids": [  
"5caccfca-ac7f-42dc-b39c-9d1f3f717676"  
],  
"error": {  
"error\_code": 3238330375,  
"description": "Cannot connect to server"  
},  
"computer": {  
"connector\_guid": "b7acf51a-282d-4e20-848c-d2d2a9d216aa",  
"hostname": "soemthing.hostname",  
"active": true,  
"links": {  
"computer": "[https://api.amp.cisco.com/v1/computers/b7acf51a-28](https://api.amp.cisco.com/v1/computers/b7acf51a-28)",  
"trajectory": "[https://api.amp.cisco.com/v1/computers/b7acf51a-28/trajectory](https://api.amp.cisco.com/v1/computers/b7acf51a-28/trajectory)",  
"group": "[https://api.amp.cisco.com/v1/groups/5caccfca-a](https://api.amp.cisco.com/v1/groups/5caccfca-a)"  
}  
}  
}  
]  
}

* * *

Input and Filter:

input {  
http\_poller {  
type =\> ciscoamp  
urls =\> {  
ciscoampurl =\> {  
method =\> get  
url =\> "[https://api.amp.cisco.com/v1/events?limit=1](https://api.amp.cisco.com/v1/events?limit=1)"  
headers =\> {  
Accept =\> "application/json"  
Authorization =\> "Basic [redacted]"  
}  
}  
}  
request\_timeout =\> 60  
schedule =\> { cron =\> "\* \* \* \* \* UTC"}  
codec =\> "json" #tried both with and without this  
metadata\_target =\> "http\_poller\_metadata"  
}  
}

filter {  
if [type] == "ciscoamp" {  
json {  
source =\> "message"  
}  
geoip { source =\> "dst\_ip" }  
geoip { source =\> "src\_ip" }  
}  
}

---

<div class="post-metadata">

**Author:** ![Karn\_Griffen](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/karn_griffen/32/16337_2.png) [@Karn\_Griffen](https://discuss.elastic.co/u/Karn_Griffen)\
**Post date:** [March 15, 2017, 4:52pm UTC](https://discuss.elastic.co/t/parsing-json-from-http-poller-and-ciscoamp-api/78390/2 "2017-03-15T16:52:58Z")

</div>

Nothing? Anyone have a good resource on dealing with nested JSON, objects in arrays?

---

<div class="post-metadata">

**Author:** ![guyboertje](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/guyboertje/32/31592_2.png) [@guyboertje](https://discuss.elastic.co/u/guyboertje)\
**Post date:** [March 16, 2017, 12:16pm UTC](https://discuss.elastic.co/t/parsing-json-from-http-poller-and-ciscoamp-api/78390/3 "2017-03-16T12:16:33Z")

</div>

You can use the split filter after the json codec.

This will create clones of the original event (which will be cancelled), each having a successive element of the `data` field in a new field or overwrite the `data` field.

---

<div class="post-metadata">

**Author:** ![Karn\_Griffen](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/karn_griffen/32/16337_2.png) [@Karn\_Griffen](https://discuss.elastic.co/u/Karn_Griffen)\
**Post date:** [March 17, 2017, 11:14pm UTC](https://discuss.elastic.co/t/parsing-json-from-http-poller-and-ciscoamp-api/78390/4 "2017-03-17T23:14:07Z")

</div>

Thank you, I will look for some examples and give it a try.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 14, 2017, 11:14pm UTC](https://discuss.elastic.co/t/parsing-json-from-http-poller-and-ciscoamp-api/78390/5 "2017-04-14T23:14:12Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
