# Use Dissect filter on json input data

**URL:** <https://discuss.elastic.co/t/use-dissect-filter-on-json-input-data/151564>\
**Category:** Logstash\
**Created:** [October 9, 2018, 7:27am UTC](https://discuss.elastic.co/t/use-dissect-filter-on-json-input-data/151564 "2018-10-09T07:27:13Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![abhi\_latpate](https://avatars.discourse-cdn.com/v4/letter/a/e36b37/32.png) [@abhi\_latpate](https://discuss.elastic.co/u/abhi_latpate)\
**Post date:** [October 9, 2018, 7:27am UTC](https://discuss.elastic.co/t/use-dissect-filter-on-json-input-data/151564/1 "2018-10-09T07:27:14Z")

</div>

I have inputted two json files from logstash, from a variable named **_file_** , i want to create few fields using dissect filter, but this is giving me error:

this is my json input file:  
{  
"tags": [  
"jdkinstall",  
"class",  
"download",  
"jdkinstall::download",  
"file",  
"default",  
"node"  
],  
"file": "/etc/puppetlabs/code/environments/aem\_prod/modules/jdkinstall/manifests/download.pp",  
"type": "File",  
"title": "/apps/Binariesjdk",  
"line": 7,  
"resource": "6485158671b69e7dsfr0374sadfgfds813ffbaf",  
"environment": "aem\_prod",  
"certname": "[hostname.com](http://hostname.com)",  
"parameters": {  
"mode": "0750",  
"group": "webadm",  
"owner": "webadm",  
"backup": false,  
"ensure": "directory"  
},  
"exported": false  
},

my logstash configuration file is:  
input {  
file {  
path =\> "/usr/share/logstash/bin/puppet\_metrics/\*.json"  
type =\> "json"  
start\_position =\> "beginning"  
sincedb\_path =\> "/dev/null"  
}  
}

```
filter {
dissect {
  mapping => {
    "file" => "%{} %{} %{} %{} %{environment} %{} %{module} %{} %{}"
  }
}
  }

output {
  elasticsearch {
hosts => "192.168.2.101:9200"
manage_template => false
index => "logstash-%{+YYYY.MM.dd}"
user => "abhishek"
password => "2fudge"
  }
}

```

Error is repetition of similar lines:  
[WARN] 2018-10-09 09:01:12.316 [Ruby-0-Thread-9: :1] Dissector - Dissector mapping, field not found in event {"field"=\>"file", "event"=\>{"type"=\>"json", "@timestamp"=\>2018-10-09T07:01:12.166Z, "path"=\>"/usr/share/logstash/bin/puppet\_metrics/resources.json", "host"=\>"VM-1032011537", "@version"=\>"1", "message"=\>" "environment": "aem\_uat","}}  
[INFO] 2018-10-09 09:01:13.319 [[main]\>worker3] pipeline - Pipeline has terminated {:pipeline\_id=\>"main", :thread=\>"#\<Thread:0x7672b334 run\>"}

help would be appreciated, thanks

---

<div class="post-metadata">

**Author:** ![simmel](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/simmel/32/48040_2.png) [@simmel](https://discuss.elastic.co/u/simmel)\
**Post date:** [October 9, 2018, 9:43am UTC](https://discuss.elastic.co/t/use-dissect-filter-on-json-input-data/151564/2 "2018-10-09T09:43:53Z")

</div>

You need to use the JSON filter, see  
[https://www.elastic.co/guide/en/logstash/current/plugins-filters-json.html](https://www.elastic.co/guide/en/logstash/current/plugins-filters-json.html)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 6, 2018, 9:43am UTC](https://discuss.elastic.co/t/use-dissect-filter-on-json-input-data/151564/3 "2018-11-06T09:43:53Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
