# Selective indexing of fields

**URL:** <https://discuss.elastic.co/t/selective-indexing-of-fields/28609>\
**Category:** Logstash\
**Created:** [September 3, 2015, 12:29pm UTC](https://discuss.elastic.co/t/selective-indexing-of-fields/28609 "2015-09-03T12:29:46Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![astro](https://avatars.discourse-cdn.com/v4/letter/a/9dc877/32.png) [@astro](https://discuss.elastic.co/u/astro)\
**Post date:** [September 3, 2015, 12:29pm UTC](https://discuss.elastic.co/t/selective-indexing-of-fields/28609/1 "2015-09-03T12:29:47Z")

</div>

Hi All ,

I have a specific problem related to json parsing and extracting particular field for indexing

My sample json message is

{"log\_time":"1/Sep/2015:12:35:50 +05:30","level":"INFO","log\_message":"test message","description":"{"field1":"some data","field2":"some data "}","url":"some url","module":"some module","log\_host":"localhost"}

description field is a string which itself is json  
I want to extract only first 2 fields from description and add them as separate field in the even .

So my final output should be like

{  
"message" =\> "{"log\_time":"1/Sep/2015:12:35:50 +05:30","level":"INFO","log\_message":"test message","description":"{"field2":"some data","field2":"some data "}","url":"some url","module":"some module","log\_host":"localhost"}",  
"@version" =\> "1",  
"@timestamp" =\> "2015-09-03T11:20:43.881Z",  
"host" =\> "localhost",  
"log\_time" =\> "1/Sep/2015:12:35:50 +05:30",  
"level" =\> "INFO",  
"log\_message" =\> "test message",  
"description" =\> ""description":"{"field2":"some data","field2":"some data"}"",  
"url" =\> "some url",  
"module" =\> "some module",  
"log\_host" =\> "localhost",  
"field1" =\> "some data",  
"field2" =\> "some data"  
}

Note : description is having dynamic number of fields , it can be 2 or more .

Thanks & Regards  
Arvind  
Software Engg.  
[Shopclues.com](http://Shopclues.com)

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [September 3, 2015, 1:51pm UTC](https://discuss.elastic.co/t/selective-indexing-of-fields/28609/2 "2015-09-03T13:51:01Z")

</div>

Use the json filter to parse the `description` field into a subfield, move (rename) the fields you're interested in to wherever you want them, then delete the subfield.

```
json {
  source => "description"
  target => "description_json"
}
mutate {
  rename => {
    "[description_json][field1]" => "field1"
    "[description_json][field2]" => "field2"
  }
  remove_field => ["description_json"]
}

```

Not sure what you mean by "first two fields". You don't actually mean "first two" as in the first two fields listed in the string?

---

<div class="post-metadata">

**Author:** ![astro](https://avatars.discourse-cdn.com/v4/letter/a/9dc877/32.png) [@astro](https://discuss.elastic.co/u/astro)\
**Post date:** [September 3, 2015, 2:26pm UTC](https://discuss.elastic.co/t/selective-indexing-of-fields/28609/3 "2015-09-03T14:26:05Z")

</div>

Thanks @magnusbaeck , I was working on this from morning and you made my day 😄

Thanks a lot

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 5:30am UTC](https://discuss.elastic.co/t/selective-indexing-of-fields/28609/4 "2017-07-06T05:30:13Z")

</div>


