# \[Solved\]How to convert a json format string to json object for only one field of a full log text in ruby filter?

**URL:** <https://discuss.elastic.co/t/solved-how-to-convert-a-json-format-string-to-json-object-for-only-one-field-of-a-full-log-text-in-ruby-filter/180312>\
**Category:** Logstash\
**Created:** [May 9, 2019, 8:29am UTC](https://discuss.elastic.co/t/solved-how-to-convert-a-json-format-string-to-json-object-for-only-one-field-of-a-full-log-text-in-ruby-filter/180312 "2019-05-09T08:29:38Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![Adminstrator](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/adminstrator/32/42575_2.png) [@Adminstrator](https://discuss.elastic.co/u/Adminstrator)\
**Post date:** [May 9, 2019, 8:29am UTC](https://discuss.elastic.co/t/solved-how-to-convert-a-json-format-string-to-json-object-for-only-one-field-of-a-full-log-text-in-ruby-filter/180312/1 "2019-05-09T08:29:38Z")

</div>

I use filebeat to collcet log.Then push log to kafka ,then use logstash to parse every log record.then push to another kafka again.then use another logstash push the log to elasticsearch.

And the log is splited by '\t'.one field('respone\_body') is json format string like below

```auto
{"ret":0,"msg":"","data":[]}
```

how can i convert it to json in ruby filter?  
because my elasticsearch defined the response\_body as a mapping with object type and dynamic true.

below is my logstash ruby filter.

```auto
ruby {
          init => "@kname = ['datetime','level','logger','thread','version','respose_body']"
          code => 'event.append(Hash[@kname.zip(event["message"].split("\t"))])'
          remove_field => ['input_type','beat','host','message','offset','kafka'] 
    }
```

and this is log, it is a full string with 5 tablespace.

```auto
2019-05-09-15:00:04.258	ACCESS	ad_service\inc\Router 333 0.1	{"ret":0,"msg":"","data":[]}
```

I have tried below solution,But still not work.  
ruby filter code.

```auto
event["json_respone_body"] = event["respone_body"].to_json
```

Logstatsh error information:

```auto
{:timestamp=>"2019-05-10T18:08:19.938000+0800", :message=>"Ruby exception occurred: uninitialized constant LogStash::Filters::Ruby::JSON", :level=>:error}
```

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [May 9, 2019, 1:49pm UTC](https://discuss.elastic.co/t/solved-how-to-convert-a-json-format-string-to-json-object-for-only-one-field-of-a-full-log-text-in-ruby-filter/180312/2 "2019-05-09T13:49:07Z")

</div>

Why not use a [json](https://www.elastic.co/guide/en/logstash/current/plugins-filters-json.html) filter?

---

<div class="post-metadata">

**Author:** ![Adminstrator](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/adminstrator/32/42575_2.png) [@Adminstrator](https://discuss.elastic.co/u/Adminstrator)\
**Post date:** [May 10, 2019, 2:20am UTC](https://discuss.elastic.co/t/solved-how-to-convert-a-json-format-string-to-json-object-for-only-one-field-of-a-full-log-text-in-ruby-filter/180312/4 "2019-05-10T02:20:43Z")

</div>

because just one field is json format.But the full log record is still recogized as string.

---

<div class="post-metadata">

**Author:** ![Adminstrator](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/adminstrator/32/42575_2.png) [@Adminstrator](https://discuss.elastic.co/u/Adminstrator)\
**Post date:** [May 14, 2019, 8:07am UTC](https://discuss.elastic.co/t/solved-how-to-convert-a-json-format-string-to-json-object-for-only-one-field-of-a-full-log-text-in-ruby-filter/180312/5 "2019-05-14T08:07:36Z")

</div>

somebody can give some advices? thanks a lot.

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [May 14, 2019, 1:03pm UTC](https://discuss.elastic.co/t/solved-how-to-convert-a-json-format-string-to-json-object-for-only-one-field-of-a-full-log-text-in-ruby-filter/180312/6 "2019-05-14T13:03:50Z")

</div>

Use a json filter. You tell the filter which field to parse. It does not have to be message, it can be anything.

---

<div class="post-metadata">

**Author:** ![Adminstrator](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/adminstrator/32/42575_2.png) [@Adminstrator](https://discuss.elastic.co/u/Adminstrator)\
**Post date:** [May 15, 2019, 1:54am UTC](https://discuss.elastic.co/t/solved-how-to-convert-a-json-format-string-to-json-object-for-only-one-field-of-a-full-log-text-in-ruby-filter/180312/7 "2019-05-15T01:54:45Z")

</div>

but the other fields have to be deal with as string.And I hide some ruby code for the other fields.  
you mean filter deat twice,the first time use ruby code,and the second time use json filter?  
how can I configure it? like below?

```auto
 json {
        source => "%{respone_body}"
        add_field => {"json_respone_body" => "%{respone_body}"}
    }
```

```auto
 json {
        source => event["respone_body"]
        target => event["json_respone_body"]
    }
```

the two I tried,looks like still not working...

---

<div class="post-metadata">

**Author:** ![Adminstrator](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/adminstrator/32/42575_2.png) [@Adminstrator](https://discuss.elastic.co/u/Adminstrator)\
**Post date:** [May 15, 2019, 7:41am UTC](https://discuss.elastic.co/t/solved-how-to-convert-a-json-format-string-to-json-object-for-only-one-field-of-a-full-log-text-in-ruby-filter/180312/8 "2019-05-15T07:41:38Z")

</div>

use this works

```auto
 json {
        source => "respone_body"
        target => "json_respone_body"
    }
```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 12, 2019, 7:46am UTC](https://discuss.elastic.co/t/solved-how-to-convert-a-json-format-string-to-json-object-for-only-one-field-of-a-full-log-text-in-ruby-filter/180312/9 "2019-06-12T07:46:21Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
