JSON extract processor
The JSON extract processor extracts values from a JSON-encoded string field using JSONPath-like selectors, and writes each extracted value to its own target field. Supported selector syntax includes dot notation (user.address.city), bracket notation (['user']['name']), and array indexing (items[0]), with an optional $ root prefix.
To extract values from a JSON string:
- Select Create → Create processor.
- Select JSON extract from the Processor menu.
- Set Field with JSON string to the field containing the JSON string to parse.
- For each value you want to extract, select Add extraction and set:
- Selector: A JSONPath-like selector for the value to extract, for example
user.id,$.metadata.client.ip, oritems[0].name. - Target: The field to store the extracted value in.
- Type: The data type for the extracted value:
Keyword,Integer,Long,Double, orBoolean. Defaults toKeyword.
- Selector: A JSONPath-like selector for the value to extract, for example
In YAML mode, configure the JSON extract processor using the following parameters. For the complete Streamlang syntax, refer to the Streamlang reference.
| Parameter | Type | Required | Description |
|---|---|---|---|
field |
string | Yes | Source field containing the JSON string to parse. |
extractions |
array | Yes | List of extraction specifications. Each item requires a selector and target_field, and accepts an optional type. |
extractions[].selector |
string | Yes | JSONPath-like selector to extract a value, for example user.id, $.metadata.client.ip, or items[0].name. |
extractions[].target_field |
string | Yes | Target field to store the extracted value. |
extractions[].type |
string | No | Data type for the extracted value: keyword, integer, long, double, or boolean. Defaults to keyword. |
ignore_missing |
boolean | No | When true, skip this processor if the source field is missing. |
- action: json_extract
field: attributes.message
extractions:
- selector: metadata.client.ip
target_field: attributes.client.ip
Given a document with attributes.message set to {"metadata": {"client": {"ip": "192.168.1.1"}}}, the processor adds attributes.client.ip: "192.168.1.1".