JSON Jiu Jitsu: Has JSON Parsing Got You in a Chokehold?

Graylog
57 views April 13, 2026

From malformed fields to endlessly nested objects, JSON logs can feel like they’re trying to submit your SIEM. In this technical session, we’ll demonstrate how to turn that chokehold into a clean takedown using Graylog’s parsing, normalization, and enrichment capabilities. You’ll learn how to: - Quickly ingest and parse JSON from cloud, endpoint, and sources - Normalize fields with pipelines so your searches, dashboards, and alerts just work - Enrich JSON data with threat intel and asset context without breaking a sweat - Avoid performance and cost traps when dealing with large JSON payloads. Whether you’re a SOC analyst tired of regex wrestling or an admin looking to streamline onboarding, you’ll leave with practical techniques to make messy JSON your sparring partner—not your opponent. 0:00 Introduction & Session Overview 0:45 What Is JSON Parsing & Today's Goals 1:24 Pain Point #1: Payload Bloat & Field Explosion 2:28 Pain Point #2: Computational Cost of Processing Large JSON 3:32 Pain Point #3: Nested JSON & Arrays 4:26 Pain Point #4: Timestamp Formatting Issues 5:32 Pain Point #5: Field Collision & Accidental Overrides 6:40 Live Demo: Building a Parsing Rule with Parse JSON & Select JSON Path 12:50 Demo: Flatten JSON vs. Select JSON Path (Pros & Cons) 15:56 Advanced Technique: Converting Arrays to Fields with Join & CSV Map 19:25 Key Takeaways & JSON Parsing Best Practices

Keyboard shortcuts

On. Switch them off if they collide with your assistive tools; ? still opens this sheet.

Go to

Press g then the letter.

  • gh Latest
  • gs Sources
  • gm Media
  • gv Videos
  • gp Podcasts
  • gc Calendar
  • gd Decoder
  • gz Dataviz
  • ga Datasets
  • gb Blog
  • gk Markets
  • gj Careers
  • gn Prompt Notebook

On this page

  • / Focus search, where there is one
  • t Back to top
  • ? This list
  • Esc Close