# Parsing nested json message in field with parent object in pipeline

**URL:** <https://community.graylog.org/t/parsing-nested-json-message-in-field-with-parent-object-in-pipeline/26292>\
**Category:** Graylog Central (peer support)\
**Tags:** pipeline-rules\
**Created:** [October 25, 2022, 10:39pm UTC](https://community.graylog.org/t/parsing-nested-json-message-in-field-with-parent-object-in-pipeline/26292 "2022-10-25T22:39:32Z")\
**Posts on this page:** 1\
**Showing post:** 9

<div class="post-metadata">

**Author:** ![jivepig](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/jivepig/32/13737_2.png) [@jivepig](https://community.graylog.org/u/jivepig)\
**Post date:** [October 31, 2022, 3:34pm UTC](https://community.graylog.org/t/parsing-nested-json-message-in-field-with-parent-object-in-pipeline/26292/9 "2022-10-31T15:34:31Z")

</div>

Have you experimented with flatten\_json?  
Here’s a source and example with something I did to bring in logs into my test system.

```auto
rule "Random User Data Flatten Json Rule"
// From sample data : https://randomuser.me/api/
// Api input path: *
when
    true
then
    let sJson = to_string($message.result);
    let sJson = regex_replace(
        pattern: "^\\[|\\]$",
        value: sJson,
        replacement: ""
        );
    let rsJson = flatten_json(to_string(sJson), "flatten");
    set_fields(to_map(rsJson));
    remove_field("result");
    set_field("message", "parsed user data");
end
```

---

_[View the full topic](https://community.graylog.org/t/parsing-nested-json-message-in-field-with-parent-object-in-pipeline/26292)._
