# Support for JSON arrays in Metricbeat HTTP Module

**URL:** <https://discuss.elastic.co/t/support-for-json-arrays-in-metricbeat-http-module/129659>\
**Category:** Beats\
**Tags:** metricbeat\
**Created:** [April 26, 2018, 12:19pm UTC](https://discuss.elastic.co/t/support-for-json-arrays-in-metricbeat-http-module/129659 "2018-04-26T12:19:33Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![BennyInc](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bennyinc/32/21751_2.png) [@BennyInc](https://discuss.elastic.co/u/BennyInc)\
**Post date:** [April 26, 2018, 12:19pm UTC](https://discuss.elastic.co/t/support-for-json-arrays-in-metricbeat-http-module/129659/1 "2018-04-26T12:19:34Z")

</div>

Continuing the discussion from [Configuring multiple paths in http module](https://discuss.elastic.co/t/configuring-multiple-paths-in-http-module/121564/8):

In the old discussion I explained my usecase, which is gathering metrics from IBM Liberty.

Yesterday I downloaded a 6.3 Snapshot to test the new json.is\_array behavior. While this did work in a way, it did not work fully as expected.

My input as captured from [https://localhost:9443/IBMJMXConnectorREST/mbeans/WebSphere%3Aname%3DLargeThreadPool%2Ctype%3DThreadPoolStats/attributes](https://localhost:9443/IBMJMXConnectorREST/mbeans/WebSphere%3Aname%3DLargeThreadPool%2Ctype%3DThreadPoolStats/attributes) is this:

```
[
{
name: "PoolSize",
value: {
value: "1563",
type: "java.lang.Integer"
}
},
{
name: "PoolName",
value: {
value: "LargeThreadPool",
type: "java.lang.String"
}
},
{
name: "ActiveThreads",
value: {
value: "1",
type: "java.lang.Integer"
}
}
]

```

I expected these three data points to be contained in one event sent to my elasticsearch cluster. Unfortunately, I actually receive three events, containing the payload like this:

```
"http": {
  "ThreadPoolStats": {
    "value": {
      "value": "LargeThreadPool",
      "type": "java.lang.String"
    },
    "name": "PoolName"
  }
}

```

In another event's \_source:

```
"http": {
  "ThreadPoolStats": {
    "name": "PoolSize",
    "value": {
      "value": "2500",
      "type": "java.lang.Integer"
    }
  }
}

```

Is there a way to have them contained in an array or object within one single event?

---

<div class="post-metadata">

**Author:** ![exekias](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/exekias/32/28718_2.png) [@exekias](https://discuss.elastic.co/u/exekias)\
**Post date:** [April 26, 2018, 2:06pm UTC](https://discuss.elastic.co/t/support-for-json-arrays-in-metricbeat-http-module/129659/2 "2018-04-26T14:06:07Z")

</div>

Hi @BennyInc,

That is the expected behavior, storing the 3 documents as an array in Elasticsearch would make querying the data more difficult.

I guess you could merge them together later in the chain (Logstash or Ingest node), or use Logstash to do the HTTP fetching.

May I ask why do you want them in an array?

Best regards

---

<div class="post-metadata">

**Author:** ![BennyInc](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bennyinc/32/21751_2.png) [@BennyInc](https://discuss.elastic.co/u/BennyInc)\
**Post date:** [April 26, 2018, 2:58pm UTC](https://discuss.elastic.co/t/support-for-json-arrays-in-metricbeat-http-module/129659/3 "2018-04-26T14:58:00Z")

</div>

Having them together would allow me to compare the PoolSize with the number of ActiveThreads directly in a graph. With multiple events, one of the values will always be zero which brought up errors in my graph.

I haven't tried it again however, now that the events at last have the same timestamp.

---

<div class="post-metadata">

**Author:** ![exekias](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/exekias/32/28718_2.png) [@exekias](https://discuss.elastic.co/u/exekias)\
**Post date:** [April 26, 2018, 9:19pm UTC](https://discuss.elastic.co/t/support-for-json-arrays-in-metricbeat-http-module/129659/4 "2018-04-26T21:19:22Z")

</div>

You should be able to draw the 2 different series I think, did you give that a try?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 24, 2018, 9:33pm UTC](https://discuss.elastic.co/t/support-for-json-arrays-in-metricbeat-http-module/129659/5 "2018-05-24T21:33:06Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
