# Unable to create index based of message body key

**URL:** <https://discuss.elastic.co/t/unable-to-create-index-based-of-message-body-key/178420>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [April 25, 2019, 9:59am UTC](https://discuss.elastic.co/t/unable-to-create-index-based-of-message-body-key/178420 "2019-04-25T09:59:32Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![ishu52](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ishu52/32/44325_2.png) [@ishu52](https://discuss.elastic.co/u/ishu52)\
**Post date:** [April 25, 2019, 9:59am UTC](https://discuss.elastic.co/t/unable-to-create-index-based-of-message-body-key/178420/1 "2019-04-25T09:59:32Z")

</div>

I wanted to create index based on the key 'request-id' which inside json body of the log message.

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/7/5/751c9560fd12fbac2c89fb7a3647165ddbe85eaf.png)

I am trying to put filter on filebeat.config to get the logs based on request-id.

I wanted to know how can i parse json message into ES fields so that I can apply filter on the same.

---

<div class="post-metadata">

**Author:** ![steffens](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/steffens/32/79630_2.png) [@steffens](https://discuss.elastic.co/u/steffens)\
**Post date:** [April 25, 2019, 10:55am UTC](https://discuss.elastic.co/t/unable-to-create-index-based-of-message-body-key/178420/2 "2019-04-25T10:55:51Z")

</div>

Can you share your filebeat configuration? Inputs support json parsing, plus Beats also provide a processor for parsing json.

---

<div class="post-metadata">

**Author:** ![ishu52](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ishu52/32/44325_2.png) [@ishu52](https://discuss.elastic.co/u/ishu52)\
**Post date:** [April 26, 2019, 7:00am UTC](https://discuss.elastic.co/t/unable-to-create-index-based-of-message-body-key/178420/3 "2019-04-26T07:00:16Z")

</div>

This is my config settings:

I am using processors: decode\_json\_fields

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/4/2/4215f91b6fe3d2beb2de7626a3949b8999461c5b.png)

Expectation is to create index based on the key coming in Json body of the message.

---

<div class="post-metadata">

**Author:** ![steffens](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/steffens/32/79630_2.png) [@steffens](https://discuss.elastic.co/u/steffens)\
**Post date:** [April 26, 2019, 3:28pm UTC](https://discuss.elastic.co/t/unable-to-create-index-based-of-message-body-key/178420/4 "2019-04-26T15:28:47Z")

</div>

Please do not share pictures of config files or logs.

From you configuration it looks like the log message is already parsed, yet the first screenshot shows that it is not parsed. Did you just added the processors?

Once you have the json correctly parsed you can configure the index name in `output.elasticsearch.index: '%{[field.name]}`. Problem is that your `request_id` is an array of strings, but we need a string. For extracting the ID from the array you will need [this process that is currently in development](https://github.com/elastic/beats/pull/11761).

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 24, 2019, 3:28pm UTC](https://discuss.elastic.co/t/unable-to-create-index-based-of-message-body-key/178420/5 "2019-05-24T15:28:50Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
