# Split json with no seperator

**URL:** <https://discuss.elastic.co/t/split-json-with-no-seperator/216368>\
**Category:** Logstash\
**Created:** [January 24, 2020, 6:35am UTC](https://discuss.elastic.co/t/split-json-with-no-seperator/216368 "2020-01-24T06:35:12Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![katara](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/katara/32/60143_2.png) [@katara](https://discuss.elastic.co/u/katara)\
**Post date:** [January 24, 2020, 6:35am UTC](https://discuss.elastic.co/t/split-json-with-no-seperator/216368/1 "2020-01-24T06:35:12Z")

</div>

Hi All,  
I have a nxlog tcp out marked towards Logstash,  
Here's the input from nxlog

> > {"EventReceivedTime":"2020-01-21T03:01:37.025293-07:00",  
> > "Severity":"INFO",  
> > "EventTime":"2020-01-21T03:01:37.025296-07:00",  
> > "Hostname":"ELK01",  
> > "Message":"[Thu Mar 09 08:19:21 2017] [info] [client 10.34.10.2] login successful"}  
> > {"EventReceivedTime":"2020-01-21T04:01:37.025293-07:00",  
> > "Severity":"ERROR",  
> > "EventTime":"2020-01-21T04:01:37.025296-07:00",  
> > "Hostname":"ELK01",  
> > "Message":"[Thu Mar 09 08:19:21 2017] [error] [client 10.34.10.2] Invalid method in request \x16\x03\x01"}  
> > {"EventReceivedTime":"2020-01-21T05:01:37.025293-07:00",  
> > "Severity":"ERROR",  
> > "EventTime":"2020-01-21T05:01:37.025296-07:00",  
> > "Hostname":"ELK01",  
> > "Message":"[Thu Mar 09 08:19:21 2017] [error] [client 10.34.10.2] IO exception"}

Note that there is no separator between each input. and they aren't grouped within a single output also.

Now here is my logstash conf:

> ```
> input {
> tcp {
> port => 8443
> codec => json
> type => 'nxlog-json'
> }
> }
> output {
> elasticsearch {
> hosts => ["100.89.99.03"]
> index => "testnx"
> }
> stdout { codec => rubydebug }
> }
> 
> ```

With the above even after codec being json, the data isn't getting split. It all falls in a single field - message.

For a different case, I have used the below for an API input where I was able to define everything:

> ```
> > filter
> > {
> > json
> > {
> > source => "result"
> > }
> > split
> > {
> > field => ["result"]
> > }
> 
> ```

where my data fields were ina common result set:

> ```
> {"result":[
> {
> ....
> ...."} ,
> {
> .... 
> ....
> }]}
> 
> ```

Now in my new case, I dont have a common field where all my inputs land inside.

How do i apply filters according to my input?

Please help me.

---

<div class="post-metadata">

**Author:** ![katara](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/katara/32/60143_2.png) [@katara](https://discuss.elastic.co/u/katara)\
**Post date:** [January 27, 2020, 7:37am UTC](https://discuss.elastic.co/t/split-json-with-no-seperator/216368/2 "2020-01-27T07:37:18Z")

</div>

Hi all,  
I've found the solution.  
If it helps anyone,  
I marked my codec in the below format,  
which worked for me!

> codec =\> json\_lines { charset =\> CP1252 }

Thanks!  
Katara

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 24, 2020, 7:37am UTC](https://discuss.elastic.co/t/split-json-with-no-seperator/216368/3 "2020-02-24T07:37:18Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
