# Trying to parse the content of a json into different fields

**URL:** <https://discuss.elastic.co/t/trying-to-parse-the-content-of-a-json-into-different-fields/149202>\
**Category:** Logstash\
**Created:** [September 19, 2018, 10:59pm UTC](https://discuss.elastic.co/t/trying-to-parse-the-content-of-a-json-into-different-fields/149202 "2018-09-19T22:59:23Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![ratman](https://avatars.discourse-cdn.com/v4/letter/r/3be4f8/32.png) [@ratman](https://discuss.elastic.co/u/ratman)\
**Post date:** [September 19, 2018, 10:59pm UTC](https://discuss.elastic.co/t/trying-to-parse-the-content-of-a-json-into-different-fields/149202/1 "2018-09-19T22:59:23Z")

</div>

Hello, I am quite new in elasticsearch/logstash/kibana but I am trying to build a small dashboard with some logs I am getting from different machines.  
The logs are formed by statement like this :

_INFO - TEXT - Sat Aug 18 17:53:45 CEST 2018_

_{_  
\_ "wsName": "newFile",\_  
\_ "Connection type": "WIFI: "WifiName"",\_  
\_ "RAM available": "32.78%",\_  
\_ "CPU usage": "19.72%",\_  
\_ "Internal storage available (MB)": 99999.99,\_  
\_ "External storage available (MB)": 99999.99,\_  
\_ "Connectipvity": "Is available: true. Is connected: true. Type connectivity: WIFI. Wifi signal level: 4 out of 5"\_  
_}_

I've used multiline in Filebeats and I am creating blocks of information for "INFO" and "ERROR", which are the two types of information I can have at the moment. That part goes more or less fine.  
But my problems start when I get into the Grok part. First of all, I realised I needed a custom pattern for the timestamp, so I found this :

> TIMEZ\_CUSTOM (?:[PMCE][SD]T|UTC|CEST|CET) ?(+-(:?[0-5]\d)?)?  
> DATESTAMP\_CUSTOM %{DAY} %{MONTH} %{MONTHDAY} %{TIME} %{TIMEZ\_CUSTOM } %{YEAR}

This works about fine, (added the custom patterns to the file), but my problems start when I try to parse the info inside the {}. I should retrieve some info per message from the fields inside the Json:  
-From the "Connection type", I need to retrieve the WifiName and create a new field "WifiName".  
-From the "Connectivity", I need to retrieve the Wifi Signal Level, for example "4 out of 5", which means creating a new field "Signal Level" or something like that.

And I am quite lost with this parsing. Should I use grok or is there any other way to achieve this?

Any help about how can I parse this? Every little help will be welcome!  
Thanks!

---

<div class="post-metadata">

**Author:** ![yaauie](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yaauie/32/23363_2.png) [@yaauie](https://discuss.elastic.co/u/yaauie)\
**Post date:** [September 20, 2018, 12:03am UTC](https://discuss.elastic.co/t/trying-to-parse-the-content-of-a-json-into-different-fields/149202/2 "2018-09-20T00:03:47Z")

</div>

in these cases, it's helpful to _layer_ filters. Is the JSON blob the last bit? why not capture the whole thing to a single field, and then use the JSON filter to parse the result?

```auto
filter {
  grok {
    # ... capture the _whole_ JSON blob; store it in `[@metadata][json_payload]`
  }
  json {
    source => "[@metadata][json_payload]"
  }
}

```

---

<div class="post-metadata">

**Author:** ![ratman](https://avatars.discourse-cdn.com/v4/letter/r/3be4f8/32.png) [@ratman](https://discuss.elastic.co/u/ratman)\
**Post date:** [September 20, 2018, 7:42am UTC](https://discuss.elastic.co/t/trying-to-parse-the-content-of-a-json-into-different-fields/149202/3 "2018-09-20T07:42:04Z")

</div>

Thank you for the answer, I think this might be the solution to my problem.

But could I split the info from inside the json somehow? Also, not all the information blocks contain json, can I link the json to an if condition? I tried but I didn't get any result.  
Thanks!

---

<div class="post-metadata">

**Author:** ![yaauie](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yaauie/32/23363_2.png) [@yaauie](https://discuss.elastic.co/u/yaauie)\
**Post date:** [September 20, 2018, 8:00am UTC](https://discuss.elastic.co/t/trying-to-parse-the-content-of-a-json-into-different-fields/149202/4 "2018-09-20T08:00:52Z")

</div>

> [@ratman](#):
>
> I tried but I didn't get any result

What specifically did you try? How did it behave differently than you expected? Including example pipeline configurations and _multiple_ example input events is the best way to give sufficient context for us to be of help 😊

---

<div class="post-metadata">

**Author:** ![ratman](https://avatars.discourse-cdn.com/v4/letter/r/3be4f8/32.png) [@ratman](https://discuss.elastic.co/u/ratman)\
**Post date:** [September 20, 2018, 8:15am UTC](https://discuss.elastic.co/t/trying-to-parse-the-content-of-a-json-into-different-fields/149202/5 "2018-09-20T08:15:52Z")

</div>

So, I tried something like this :

> filter {  
> mutate {  
> gsub =\> ["message", "\n\r", "\n"]  
> }  
> grok {  
> patterns\_dir =\> ["/etc/logstash/conf.d/patterns/"]  
> match =\> { "message" =\> "%{LOGLEVEL:loglevel} - %{GREEDYDATA:concepto} - %{DATESTAMP\_CUSTOM:timestamp}\n(?\<aplic\_msg\>[^\n]_)\n(?(.|\r|\n)_)"}  
> }  
> mutate {  
> gsub =\> ["timestamp", "CEST", "Etc/GMT-2"]  
> }  
> date {  
> match =\> ["timestamp", "EEE MMM dd HH:mm:ss Z yyyy"]  
> }  
> json {  
> source =\> "data"  
> }  
> }

But I am not getting any result besides the "data" field. What am I doing wrong?  
Also I am facing another problem, some blocks contain json info but some doesn't.

Can I specify multiple grok patterns in one filter?

Thanks for all the help!! 😃

---

<div class="post-metadata">

**Author:** ![ratman](https://avatars.discourse-cdn.com/v4/letter/r/3be4f8/32.png) [@ratman](https://discuss.elastic.co/u/ratman)\
**Post date:** [September 20, 2018, 2:14pm UTC](https://discuss.elastic.co/t/trying-to-parse-the-content-of-a-json-into-different-fields/149202/6 "2018-09-20T14:14:18Z")

</div>

I made it work finally! Now I am fighting with the timestamp.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 18, 2018, 2:14pm UTC](https://discuss.elastic.co/t/trying-to-parse-the-content-of-a-json-into-different-fields/149202/7 "2018-10-18T14:14:18Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
