Use subset of json entry as document

I have several json entries in a huge file, in the form of:


What I want to use this file as input but keep everything under (not including) result, i,e I want my input to be


It goes without saying that after _raw there are many fields following...

Any suggestions?

Do I need to work on the .json file level with some parsing, or is there a logstash filter appropriate for this use case?

So basically you want to remove all fields that are not result?

Start with a json filter

filter { json { source => "message" } }

Then you can remove fields using

    ruby {
        code => '
            event.to_hash().each { |k, v|
                if k != "result"

and then move the fields inside result to the top level. @timestamp needs to be parsed, which I choose not to do in ruby.

            event.get("result").each { |k, v|
                if k == "@timestamp"
                    event.set("timestamp", v)
                    event.set(k, v)


date { match => [ "timestamp", ISO8601 ] }

The above seems to produce no events;

are we sure about this?

filter { json { source => "message" } }

I do not have a message field anywhere.

Also my input codec should be plain or json ?

Oh, if you used a json codec on the input then indeed you will not have a message field and do not need a json filter.

