# How to map JSON log fields to GELF and send them to Graylog

**URL:** <https://community.graylog.org/t/how-to-map-json-log-fields-to-gelf-and-send-them-to-graylog/1188>\
**Category:** Graylog Central (peer support)\
**Created:** [May 19, 2017, 7:50am UTC](https://community.graylog.org/t/how-to-map-json-log-fields-to-gelf-and-send-them-to-graylog/1188 "2017-05-19T07:50:43Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![aalexgabi](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/aalexgabi/32/364_2.png) [@aalexgabi](https://community.graylog.org/u/aalexgabi)\
**Post date:** [May 19, 2017, 7:50am UTC](https://community.graylog.org/t/how-to-map-json-log-fields-to-gelf-and-send-them-to-graylog/1188/1 "2017-05-19T07:50:43Z")

</div>

I have some log files that I am trying to send to Graylog. The format is one JSON object per line and here is an indented one:

```auto
{
  "time": "2017-05-17T11:28:18.677Z",
  "levelName": "INFO",
  "msg": "SchedulerService.lock: Locked instance",
  "context": {
    "instanceId": "566c6513-d0e0-46b3-9b8a-441131e6feff"
  },
  "name": "export-scheduler",
  "hostname": "33acf099f16f",
  "pid": 2435,
  "level": 30,
  "v": 0
}

```

I’m trying to send local logs with the following mapping:

```auto
GELF field:	log field
---
version:	"1.1"
host:	hostname JSON field
short_message:	msg JSON field
full_message:	entire JSON object
timestamp:	time JSON field converted to UNIX timestamp
facility:	name JSON field

```

The idea is to have the actual host, timestamp, facility, and short message sent to Graylog. I did not find a way to do this using sidecar collector or filebeats. This seems like a basic need to me but it’s not obvious how to do it. Overwriting fields afterwards via extractors is deprecated in Graylog.

Any ideas on how to achieve this?

---

<div class="post-metadata">

**Author:** ![jochen](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/jochen/32/8_2.png) [@jochen](https://community.graylog.org/u/jochen)\
**Post date:** [May 19, 2017, 8:30am UTC](https://community.graylog.org/t/how-to-map-json-log-fields-to-gelf-and-send-them-to-graylog/1188/2 "2017-05-19T08:30:36Z")

</div>

> [@aalexgabi](#):
>
> Overwriting fields afterwards via extractors is deprecated in Graylog.

Why do you think that?

---

<div class="post-metadata">

**Author:** ![aalexgabi](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/aalexgabi/32/364_2.png) [@aalexgabi](https://community.graylog.org/u/aalexgabi)\
**Post date:** [May 19, 2017, 9:33am UTC](https://community.graylog.org/t/how-to-map-json-log-fields-to-gelf-and-send-them-to-graylog/1188/3 "2017-05-19T09:33:00Z")

</div>

I found a comment here: [https://github.com/Graylog2/graylog2-server/issues/456#issuecomment-36340587](https://github.com/Graylog2/graylog2-server/issues/456#issuecomment-36340587)

---

<div class="post-metadata">

**Author:** ![jochen](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/jochen/32/8_2.png) [@jochen](https://community.graylog.org/u/jochen)\
**Post date:** [May 19, 2017, 9:40am UTC](https://community.graylog.org/t/how-to-map-json-log-fields-to-gelf-and-send-them-to-graylog/1188/4 "2017-05-19T09:40:56Z")

</div>

I think you’ve misinterpreted that comment.

---

<div class="post-metadata">

**Author:** ![aalexgabi](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/aalexgabi/32/364_2.png) [@aalexgabi](https://community.graylog.org/u/aalexgabi)\
**Post date:** [May 19, 2017, 8:59pm UTC](https://community.graylog.org/t/how-to-map-json-log-fields-to-gelf-and-send-them-to-graylog/1188/5 "2017-05-19T20:59:27Z")

</div>

An extractor configured to overwrite the timestamp and other fields worked. Now everything works fine. The date format had to be changed. Thank you for the quick reply!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/flex016/uploads/graylog/original/3X/c/7/c7c09c6b5099570133d6502b83f50ba4430de5b6.png) [@system](https://community.graylog.org/u/system)\
**Post date:** [June 2, 2017, 8:59pm UTC](https://community.graylog.org/t/how-to-map-json-log-fields-to-gelf-and-send-them-to-graylog/1188/6 "2017-06-02T20:59:43Z")

</div>

This topic was automatically closed 14 days after the last reply. New replies are no longer allowed.
