# Using data from a json document field in a Visualization

**URL:** <https://discuss.elastic.co/t/using-data-from-a-json-document-field-in-a-visualization/186536>\
**Category:** Kibana\
**Created:** [June 19, 2019, 8:00pm UTC](https://discuss.elastic.co/t/using-data-from-a-json-document-field-in-a-visualization/186536 "2019-06-19T20:00:17Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![relentless](https://avatars.discourse-cdn.com/v4/letter/r/a8b319/32.png) [@relentless](https://discuss.elastic.co/u/relentless)\
**Post date:** [June 19, 2019, 8:00pm UTC](https://discuss.elastic.co/t/using-data-from-a-json-document-field-in-a-visualization/186536/1 "2019-06-19T20:00:17Z")

</div>

Hi Guys

I have a log which produces a field called relatedData. This field contains a small json document.  
e.g  
"relatedData": "{"method":"Put","StartDateTime":"2019-06-20T07:57:08.9337817+12:00","EndDateTime":"2019-06-20T07:57:08.9494062+12:00","TimeTakenInMilliSeconds":15.624500000000001}",

I'm wanting to extract the value for TimeTakenInMelliSeconds and use that number in a visualization. But not sure how to go about it.  
Any ideas on how to approach this with kibana? I'm thinking it could be a scripted field but didn't see any examples of other people doing it.

---

<div class="post-metadata">

**Author:** ![lukas](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/lukas/32/6812_2.png) [@lukas](https://discuss.elastic.co/u/lukas)\
**Post date:** [June 19, 2019, 9:27pm UTC](https://discuss.elastic.co/t/using-data-from-a-json-document-field-in-a-visualization/186536/2 "2019-06-19T21:27:55Z")

</div>

Does `relatedData` contain the same fields in each document, or is it dynamic?

---

<div class="post-metadata">

**Author:** ![relentless](https://avatars.discourse-cdn.com/v4/letter/r/a8b319/32.png) [@relentless](https://discuss.elastic.co/u/relentless)\
**Post date:** [June 19, 2019, 10:46pm UTC](https://discuss.elastic.co/t/using-data-from-a-json-document-field-in-a-visualization/186536/3 "2019-06-19T22:46:45Z")

</div>

It contains different data types (sometimes json objects, sometimes strings), we have api's dumping logs and any extra information (like an exception message or a user friendly message etc) is placed in this. But we could create a new field that specifically logs this particular data object if that would make it much easier.

---

<div class="post-metadata">

**Author:** ![lukas](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/lukas/32/6812_2.png) [@lukas](https://discuss.elastic.co/u/lukas)\
**Post date:** [June 19, 2019, 11:17pm UTC](https://discuss.elastic.co/t/using-data-from-a-json-document-field-in-a-visualization/186536/4 "2019-06-19T23:17:02Z")

</div>

Creating a separate field specifically for the timestamp would definitely make this task easier. If that's not possible, however, you could probably accomplish this through a scripted field that gets the value for `relatedData`, parses the JSON and then extracts the `TimeTakenInMilliseconds`.

---

<div class="post-metadata">

**Author:** ![relentless](https://avatars.discourse-cdn.com/v4/letter/r/a8b319/32.png) [@relentless](https://discuss.elastic.co/u/relentless)\
**Post date:** [June 19, 2019, 11:48pm UTC](https://discuss.elastic.co/t/using-data-from-a-json-document-field-in-a-visualization/186536/5 "2019-06-19T23:48:35Z")

</div>

We do have the default @timestamp field in each document and bunch of other fields. Sorry I just provided the particular field I was interested in trying to parse. Sounds like I should be using a scripted field with a regex to pull this information out. Is that about right?

---

<div class="post-metadata">

**Author:** ![relentless](https://avatars.discourse-cdn.com/v4/letter/r/a8b319/32.png) [@relentless](https://discuss.elastic.co/u/relentless)\
**Post date:** [June 20, 2019, 1:17am UTC](https://discuss.elastic.co/t/using-data-from-a-json-document-field-in-a-visualization/186536/6 "2019-06-20T01:17:28Z")

</div>

Actually now that I'm looking through the painless docs they say that regex is disabled by default for performance reasons.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 18, 2019, 1:17am UTC](https://discuss.elastic.co/t/using-data-from-a-json-document-field-in-a-visualization/186536/7 "2019-07-18T01:17:29Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
