JSON Jiu Jitsu: Has JSON Parsing Got You in a Chokehold?
From malformed fields to endlessly nested objects, JSON logs can feel like they’re trying to submit your SIEM. In this technical session, we’ll demonstrate how to turn that chokehold into a clean takedown using Graylog’s parsing, normalization, and enrichment capabilities. You’ll learn how to: - Quickly ingest and parse JSON from cloud, endpoint, and sources - Normalize fields with pipelines so your searches, dashboards, and alerts just work - Enrich JSON data with threat intel and asset context without breaking a sweat - Avoid performance and cost traps when dealing with large JSON payloads. Whether you’re a SOC analyst tired of regex wrestling or an admin looking to streamline onboarding, you’ll leave with practical techniques to make messy JSON your sparring partner—not your opponent. 0:00 Introduction & Session Overview 0:45 What Is JSON Parsing & Today's Goals 1:24 Pain Point #1: Payload Bloat & Field Explosion 2:28 Pain Point #2: Computational Cost of Processing Large JSON 3:32 Pain Point #3: Nested JSON & Arrays 4:26 Pain Point #4: Timestamp Formatting Issues 5:32 Pain Point #5: Field Collision & Accidental Overrides 6:40 Live Demo: Building a Parsing Rule with Parse JSON & Select JSON Path 12:50 Demo: Flatten JSON vs. Select JSON Path (Pros & Cons) 15:56 Advanced Technique: Converting Arrays to Fields with Join & CSV Map 19:25 Key Takeaways & JSON Parsing Best Practices