# Trying to analyze data but getting wrong data format from log what are the options its big data

**URL:** <https://discuss.elastic.co/t/trying-to-analyze-data-but-getting-wrong-data-format-from-log-what-are-the-options-its-big-data/309376>\
**Category:** Kibana\
**Created:** [July 12, 2022, 6:27am UTC](https://discuss.elastic.co/t/trying-to-analyze-data-but-getting-wrong-data-format-from-log-what-are-the-options-its-big-data/309376 "2022-07-12T06:27:26Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Gaming\_zone](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/gaming_zone/32/101881_2.png) [@Gaming\_zone](https://discuss.elastic.co/u/Gaming_zone)\
**Post date:** [July 12, 2022, 6:27am UTC](https://discuss.elastic.co/t/trying-to-analyze-data-but-getting-wrong-data-format-from-log-what-are-the-options-its-big-data/309376/1 "2022-07-12T06:27:26Z")

</div>

I have to analyze the given kind of data but the data format is not n json what is the problem and how i might change it.  
this is the dummy json and i have to analyze data in original  
{"\_index": "dummy\_elk","\_id": "dummy\_id\_111","\_version": 12,"\_score": 12,"\_ignored": ["event.original.keyword","message.keyword"],"\_source": {"event": {"original": "\<14\>Mon Jul 04 06:40:39 GMT 2022Info: {"timestamp": 2018-7-4T6:40:39,"callerApplication": Caller\_Application\_1,"apiProduct": API\_Producgt\_1,"apiProxy": API\_Proxy\_1,"messageid": message\_id\_1234,"environment": dev,"basePath": /base\_dummy/v1,"pathSuffix": /socre\_dummy\_api, "proxyEndpoint": https://ip\_address/base\_dummy/v1/socre\_dummy\_api,"targetEndpoint": ,"method": POST,"httpStatusCode": 200,"responseTime": 915216707,"requestBody": {"MobileNumber": "5267890", "Name": "Name\_Dummy\_1 ", "Pan": "xxxpxxxxxx"},"responseBody": { "JSON1": "JSON\_Dummy1", "CreatedOn": "2022-07-04 11:43:36.94", "Error\_Msg": "abc", "OfferID\_Dummy": "offer\_1234", "Pan": "xxxpxxxxx", "Score": "700"}}\u000"}}}

---

<div class="post-metadata">

**Author:** ![LeeDr](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leedr/32/9289_2.png) [@LeeDr](https://discuss.elastic.co/u/LeeDr)\
**Post date:** [July 14, 2022, 11:52pm UTC](https://discuss.elastic.co/t/trying-to-analyze-data-but-getting-wrong-data-format-from-log-what-are-the-options-its-big-data/309376/2 "2022-07-14T23:52:26Z")

</div>

I think you'll need to add some more information before anybody can help you. Is that an NGINX proxy log or something? We have integrations that help ingest various types of logs.

---

<div class="post-metadata">

**Author:** ![hendry.lim](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/hendry.lim/32/71328_2.png) [@hendry.lim](https://discuss.elastic.co/u/hendry.lim)\
**Post date:** [July 15, 2022, 1:27am UTC](https://discuss.elastic.co/t/trying-to-analyze-data-but-getting-wrong-data-format-from-log-what-are-the-options-its-big-data/309376/3 "2022-07-15T01:27:17Z")

</div>

You will need to implement additional parsing either using Logstash or Elasticsearch ingest pipeline. Based on the `event.original`, it looks like you are receiving a log in syslog format. I would foresee that you will need to look at `grok` and `json` filter/processor.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 12, 2022, 1:27am UTC](https://discuss.elastic.co/t/trying-to-analyze-data-but-getting-wrong-data-format-from-log-what-are-the-options-its-big-data/309376/4 "2022-08-12T01:27:19Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
