# To get message field for json filter

**URL:** <https://discuss.elastic.co/t/to-get-message-field-for-json-filter/337968>\
**Category:** Logstash\
**Created:** [July 9, 2023, 9:21pm UTC](https://discuss.elastic.co/t/to-get-message-field-for-json-filter/337968 "2023-07-09T21:21:02Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![a.emrekaraman](https://avatars.discourse-cdn.com/v4/letter/a/bc79bd/32.png) [@a.emrekaraman](https://discuss.elastic.co/u/a.emrekaraman)\
**Post date:** [July 9, 2023, 9:21pm UTC](https://discuss.elastic.co/t/to-get-message-field-for-json-filter/337968/1 "2023-07-09T21:21:02Z")

</div>

Hi Team,

I use json filter to parse my json data but my json data has "message" value. that's why ı'm not able to get standard message field which have all parsed log. I just have "message" field which come from json log data. How can I get both message field ? I tried to rename message field for json data but was not able to get message field which show whole parsed log.

json data example;  
mxlayer[2076559]: {" **message**":"Not a valid password","context":{"type":"RESTAPI","subtype":"RESPONSE","details":

---

<div class="post-metadata">

**Author:** ![carly.richmond](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/carly.richmond/32/104935_2.png) [@carly.richmond](https://discuss.elastic.co/u/carly.richmond)\
**Post date:** [July 10, 2023, 12:35pm UTC](https://discuss.elastic.co/t/to-get-message-field-for-json-filter/337968/2 "2023-07-10T12:35:04Z")

</div>

Hi @a.emrekaraman,

To confirm, by JSON filter, are you suggesting you're using [Logstash](https://www.elastic.co/guide/en/logstash/current/plugins-filters-json.html) to ingest data into Elasticsearch?

---

<div class="post-metadata">

**Author:** ![a.emrekaraman](https://avatars.discourse-cdn.com/v4/letter/a/bc79bd/32.png) [@a.emrekaraman](https://discuss.elastic.co/u/a.emrekaraman)\
**Post date:** [July 11, 2023, 10:48pm UTC](https://discuss.elastic.co/t/to-get-message-field-for-json-filter/337968/3 "2023-07-11T22:48:57Z")

</div>

Hi Carly,

Yes, I'm using logstash to ingest data into elasticsearch.

Thanks

---

<div class="post-metadata">

**Author:** ![carly.richmond](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/carly.richmond/32/104935_2.png) [@carly.richmond](https://discuss.elastic.co/u/carly.richmond)\
**Post date:** [July 12, 2023, 9:10am UTC](https://discuss.elastic.co/t/to-get-message-field-for-json-filter/337968/4 "2023-07-12T09:10:03Z")

</div>

Thanks for confirming @a.emrekaraman. I've changed the topic of your question to Logstash.

Can you share your current configuration and what you mean by:

> get both message field

Would it not just be the case of pulling out the message field using the [source attribute](https://www.elastic.co/guide/en/logstash/current/plugins-filters-json.html#plugins-filters-json-source)?

---

<div class="post-metadata">

**Author:** ![Rios](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rios/32/95745_2.png) [@Rios](https://discuss.elastic.co/u/Rios)\
**Post date:** [July 12, 2023, 9:48am UTC](https://discuss.elastic.co/t/to-get-message-field-for-json-filter/337968/5 "2023-07-12T09:48:42Z")

</div>

Not clear what is the main problem:

- message and message inside -\>use [event][orginal] which contains LS "message" no the field inside
- incorrect JSON structure -\>use grok to extract fields

Edit: Another thing, you can use also different "target"=\> "something"

> By default, it will place the parsed JSON in the root (top level) of the Logstash event, but this filter can be configured to place the JSON into any arbitrary event field, using the `target` configuration.

---

<div class="post-metadata">

**Author:** ![Rios](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rios/32/95745_2.png) [@Rios](https://discuss.elastic.co/u/Rios)\
**Post date:** [July 12, 2023, 12:44pm UTC](https://discuss.elastic.co/t/to-get-message-field-for-json-filter/337968/7 "2023-07-12T12:44:48Z")

</div>

Not sure have you solved. Might be:

- your message is not pure JSON structure - have more fields inside the message
- it hasn't been properly formatted, use JSON viewer like [https://jsonlint.com/](https://jsonlint.com/) to discover data inconsistency
- your data is not valid in some cases like too long line don't have quotes at the end

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 9, 2023, 12:45pm UTC](https://discuss.elastic.co/t/to-get-message-field-for-json-filter/337968/8 "2023-08-09T12:45:08Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
