Logentries Docs

Find comprehensive guides and documentation to help you start and continue to work with Logentries.


Search results for "{{ search.query }}"

No results found for "{{search.query}}".
View All Results

JSON Structure

JSON structured logs are regularly produced by software components and are promoted as a logging best practice. JSON formatted logs are easily produced and consumed by a variety of software components and are human readable.

JSON Parsing Specification

The system will automatically parse JSON formatted log events formatted in compliance with the JSON Specification (IETF RFC 4627). To take advantage of the prettification option, the entry must be a single object ({ … }) or array of JSON objects. JSON objects that appear embedded in unstructured data will still have their keys recognised but you will not be able to expand the JSON hierarchy.

If there is multiple keys which share the same name in a JSON object then the parser will interpret the last key as the correct key.

Nested JSON

You can use the JSON hierarchy for queries and alerts. For example if you’re sending logs like the below example.

  "volume": "blaring",
  "current" : {
               "band": "rednex",
               "song": "cotton eye joe",
  "next" : {
           "band": "the dubliners",
           "song": "finnegan's wake",

We use dot notation for nested objects and integers for array positions. Below we have provided some example queries using the dot notation and array positions you may find helpful.

Example Queries

You want to find when the volume is blaring


You want to find when current band is Rednex.

where(current.band = "rednex")

You want to find a member of the Dubliners named “Ciaran”

where(next.members.2.firstname = "Ciaran")

Here are more examples of queries and the resulting matches based on the log message example above.

JSON dot notation




cotton eyed joe










You can set up an alert if someone tries to stick some Nickelback on with a pattern like “next.band”=”nickelback” this could tag the messages or send an email based on the tag or alert set up.


*Json entries whose depth is more than 10 levels are not supported. They will not be parsed.
Nested keys are resolved fully before they are stored, i.e. current.members is not a key

*Any pre-existing alerts or saved queries may need to be updated. If there are any alerts or queries that search against child objects, (e.g. where(band) in the example above), the change could break your queries.

*Logentries doesn't recognise the \n as a new line within the log message, to do this you would need to add "\u2028" Unicode line separator in your JSON.

We suggest to update your queries to support both old and new query. So using the example above, you could query for where(band OR current.band).

JSON Structure