# Problems with regular expression extractor for json (prior to json extractor)

**URL:** <https://community.graylog.org/t/problems-with-regular-expression-extractor-for-json-prior-to-json-extractor/26604>\
**Category:** Graylog Central (peer support)\
**Created:** [November 19, 2022, 5:53pm UTC](https://community.graylog.org/t/problems-with-regular-expression-extractor-for-json-prior-to-json-extractor/26604 "2022-11-19T17:53:50Z")\
**Posts on this page:** 1\
**Showing post:** 2

<div class="post-metadata">

**Author:** ![gsmith](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/gsmith/32/1222_2.png) [@gsmith](https://community.graylog.org/u/gsmith)\
**Post date:** [November 21, 2022, 10:51pm UTC](https://community.graylog.org/t/problems-with-regular-expression-extractor-for-json-prior-to-json-extractor/26604/2 "2022-11-21T22:51:41Z")

</div>

Hey @erasedhammer

I seen some similar, perhaps this post might help.

> [@Parsing nested json message in field with parent object in pipeline](https://community.graylog.org/t/parsing-nested-json-message-in-field-with-parent-object-in-pipeline/26292/9):
>
> Have you experimented with flatten\_json? Here’s a source and example with something I did to bring in logs into my test system. rule "Random User Data Flatten Json Rule" // From sample data : https://randomuser.me/api/ // Api input path: \* when true then let sJson = to\_string($message.result); let sJson = regex\_replace( pattern: "^\\[|\\]$", value: sJson, replacement: "" ); let rsJson = flatten\_json(to\_string(sJson), "flatten"); set\_fields(to…

---

_[View the full topic](https://community.graylog.org/t/problems-with-regular-expression-extractor-for-json-prior-to-json-extractor/26604)._
