# Problem with parsing json in syslog format

**URL:** <https://discuss.elastic.co/t/problem-with-parsing-json-in-syslog-format/252042>\
**Category:** Logstash\
**Created:** [October 14, 2020, 12:30pm UTC](https://discuss.elastic.co/t/problem-with-parsing-json-in-syslog-format/252042 "2020-10-14T12:30:57Z")\
**Posts on this page:** 1\
**Showing post:** 2

<div class="post-metadata">

**Author:** ![rugenl](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rugenl/32/12887_2.png) [@rugenl](https://discuss.elastic.co/u/rugenl)\
**Post date:** [October 14, 2020, 2:20pm UTC](https://discuss.elastic.co/t/problem-with-parsing-json-in-syslog-format/252042/2 "2020-10-14T14:20:34Z")

</div>

Here is an example [Parse JSON string contained in a Syslog message](https://discuss.elastic.co/t/parse-json-string-contained-in-a-syslog-message/54951)

This uses grok to parse off the syslog headers before using the json filter

```
    if [type] == "syslog" {
            grok {
                    match => { "message" => "%{SYSLOGBASE} %{GREEDYDATA:syslog_message}" }
            }

            json {
                    source => { source => "syslog_message" }
            }
    }
```

---

_[View the full topic](https://discuss.elastic.co/t/problem-with-parsing-json-in-syslog-format/252042)._
