# Set "target" in JSON filter to be variable

**URL:** <https://discuss.elastic.co/t/set-target-in-json-filter-to-be-variable/249434>\
**Category:** Logstash\
**Created:** [September 22, 2020, 2:15am UTC](https://discuss.elastic.co/t/set-target-in-json-filter-to-be-variable/249434 "2020-09-22T02:15:37Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Mohamed\_Saeed](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mohamed_saeed/32/75982_2.png) [@Mohamed\_Saeed](https://discuss.elastic.co/u/Mohamed_Saeed)\
**Post date:** [September 22, 2020, 2:15am UTC](https://discuss.elastic.co/t/set-target-in-json-filter-to-be-variable/249434/1 "2020-09-22T02:15:37Z")

</div>

I'm trying to use json filter to parse logs but I want to save them under a new field. I know that I can do something like the following:

```auto
    filter {
        json{
            source => "message"
            target => "foo"
        }
    }

```

But I want to use target as variable.

For example, assume that I have the following:

```auto
{
  "_index": "filebeat-7.3.0-2020.09.22",
  "_type": "_doc",
  "_id": "LKqHs3QBl7NXO7ofpbfK",
  "_score": 1,
  "_source": {
    ...
    ...
    "message": "{\"level\":\"info\",\"timestamp\":\"2020-09-22T01:54:58.894Z\",\"caller\":\"middleware@v1.0.3/logger.go:59\",\"message\":\"Default Log\",\"requestId\":\"2917737d-d98f-4ed4-b9b5-8c614daf2e2e\",\"method\":\"POST\",\"endpoint\":\"/v1/automation-job/dequeue\",\"StatusCode\":404,\"duration\":\"1.441251ms\"}",
    ...
    ...

    "kubernetes": {
      "container": {
        "name": "test-foo"
      },
      ...
    }
  },
}

```

I want to set "target" value to be the value of `kubernetes.container.name`. In this case, it will be = `test-foo`. And if the value of `kubernetes.container.name` changed, the target field changes accordingly.

I tried to use the following setups but they didn't work:

1. 

```auto
    filter {
        json{
            source => "message"
            target => "%{[kubernetes][container][name]}"
        }
    }

```

1. 

```auto
    filter {
        json{
            source => "message"
            target => "%{kubernetes.container.name}"
        }
    }

```

1. 

```auto
    filter {
        json{
            source => "message"
            target => [kubernetes][container][name]
        }
    }

```

Any help, please?

logstash version. 7.3.0  
elasticsearch 7.3.0

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [September 22, 2020, 2:48pm UTC](https://discuss.elastic.co/t/set-target-in-json-filter-to-be-variable/249434/2 "2020-09-22T14:48:37Z")

</div>

> [@Mohamed\_Saeed](#):
>
> Any help, please?

I do not think that can be done directly, but you could use a fixed target and then move it using mutate.

---

<div class="post-metadata">

**Author:** ![Mohamed\_Saeed](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mohamed_saeed/32/75982_2.png) [@Mohamed\_Saeed](https://discuss.elastic.co/u/Mohamed_Saeed)\
**Post date:** [September 23, 2020, 12:36am UTC](https://discuss.elastic.co/t/set-target-in-json-filter-to-be-variable/249434/3 "2020-09-23T00:36:10Z")

</div>

Wow, It worked that way. It weird thought that `target` can't be variable.

Thanks very much 😃

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 21, 2020, 12:36am UTC](https://discuss.elastic.co/t/set-target-in-json-filter-to-be-variable/249434/4 "2020-10-21T00:36:13Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
