
A jq program is a “filter”: it takes an input, and produces an output. There are a lot of builtin filters for extracting a particular field of an object, or converting a number to a string, or various other standard tasks.

More Simple steps to begin with…

> jq -V

# Let's grab a sources
> curl https://api.github.com/users/butuzov/received_events > o.json

# We can pipe source into jq with a few ways
> cat "o.json" | jq 'length'
> jq -f o.json 'length'
> jq 'length' o.json
# Using null input + piping into another jq to minify it.
> jq --null-input --argjson test null '.test=$test'  | jq -r tostring

# How this help structured:
# each call to jquery will precent ...| and it means we runnin cat 'o.json'
> cat 'o.json'

# writing line below is same as cat o.json | jq -M '.[]', if other input not provided
> ...| jq '.'
# json output

#Kubernetes Examples

alias k="kubectl $@"
# initial
k create deployment nginx --image=nginx --dry-run -o yaml | k create -f -
k scale deployment nginx --replicas=4
k get pods

# k get pods -o json

# how many pods do i have?
k get pods -o json | jq '.items[]' | jq 'length'

# output names
k get pods -o json | jq '.items[].metadata.name'
# output names as json list
k get pods -o json | jq '[.items[].metadata.name]'
# how many pods do i have?
k get pods -o json | jq '[.items[].metadata.name]' | jq 'length'
# less piping plese
k get pods -o json | jq '[.items[].metadata.name] | length'

# new json creation
k get pods -o json | jq '{items:[{name:.items[].metadata.name, termination: .items[].spec.terminationGracePeriodSeconds}]}'

# pre filtered
k get pods -o json | jq '.items[] | {name:.metadata.name, termination: .spec.terminationGracePeriodSeconds}'
# more filters (greater or equal then 30)
k get pods -o json | jq '.items[] | {name:.metadata.name, termination: .spec.terminationGracePeriodSeconds} | select(.termination|tonumber >= 30)'
# more filters (not null)
k get pods -o json | jq '.items[] | {name:.metadata.name, termination: .spec.terminationGracePeriodSeconds} | select(.termination != null)'

#Invoking jq

  • Unix shells: jq '.["foo"]'
  • Powershell: jq '.[\"foo\"]'
  • Windows command shell: jq ".[\"foo\"]"

#Basic filters

export j='-M o.json'
> jq '.' $j                             # Identity
> echo 1 | jq '[., tojson, tostring]' | jq -r tostring
> echo 1 | jq '. < 0.12345678901234567890123456788'
> echo [20] | jq 'map([., . == 1]) | tojson'

#Object Identifier-Index

#Types and Values

> echo -n '[1, "1"]' | jq '.[] | tonumber'
> echo -n '[1, "1"]' | jq '.[] | tostring'
> echo -n '[0, false, [], {}, null, "hello"]' | jq 'type'
> echo -n '[0, false, [], {}, null, "hello"]' | jq -c 'map(type)'

# Other...
$json=$(curl -s https://api.github.com/users/butuzov/received_events)
# Array To Multi Document Json
echo $json | jq '.[] | select(.)'
echo $json | jq '.[] | select(.type == "CreateEvent") | [.]'
# Subselecting Element from Selected Object into Array
echo $json | jq '.[] | select(.type == "CreateEvent").actor | [.]'

#Builtin operators and functions


# json to csv
> jq -r 'map({id,title,url,company,location}) | (first | keys_unsorted) as $keys | map([to_entries[] | .value]) as $rows | $keys,$rows[] | @csv' jobs.json > jobs.csv
  1. We run jq -r to output raw strings (without double quotes.)
  2. In the filter part, we pipe multiple filters together, starting with map({id,title,url,company,location}). This filter instructs jq which keys we want to extract from the input JSON file.
  3. Then we use (first | keys_unsorted) as $keys filter which takes the first object, extracts its keys and stores them under the $keys variable as an array.
  4. Next, we use map([to_entries[] | .value]) as $rows filter which converts every key-value entry like "foo": "bar" into an object like {"key":"foo","value":"bar"} so we can extract only values as an array and store it in a $rows variable.
  5. Once we do it, we can use $keys,$rows[] filter to put keys and rows together and then pipe it with the @csv filter to convert JSON objects to CSV rows.

#CVS parsing

# csv to json
> ./install.sh
> jq --slurp --raw-input --raw-output \
   'split("\n") | .[1:] | map(split(",")) |
        "PassengerId": .[0],
        "Survived": "\(.[1])",
        "Pclass": .[2],
      })' \

#Other builtins

# print sorted keys
curl -s http://localhost:9200/_aliases | jq 'keys'
# print keys
curl -s http://localhost:9200/_aliases | jq 'keys_unsorted'
# object/array length
curl -s http://localhost:9200/_aliases | jq 'length'
# check for key in array
curl -s http://localhost:9200/_aliases | jq 'has("nifi-req-2024.01.11")'
# in set
echo -n '["foo", "bar"]' | jq '.[] | in({"foo": 42})'

#Conditionals and Comparisons

> json='[{"a":1,"b":10,"c":9},{"a":2,"b":25,"c":5}]'
> echo -n $json | jq -c '.[] | select((.a <= 1)).a'
> echo -n $json | jq -c '.[] | select((.a <= 1) and (.c=9)).b'
> echo -n $json | jq -c '.[] | select((.a <= 1) or (.c%3>0)).b'

#Regular expressions

The jq regex filters are defined so that they can be used using one of these patterns:



  • STRING, REGEX, and FLAGS are jq strings and subject to jq string interpolation;
  • REGEX, after string interpolation, should be a valid regular expression;
  • FILTER is one of test, match, or `capture``, as described below.

FLAGS is a string consisting of one of more of the supported flags:

  • g - Global search (find all matches, not just the first)
  • i - Case insensitive search
  • m - Multi line mode (. will match newlines)
  • n - Ignore empty matches
  • p - Both s and m modes are enabled
  • s - Single line mode (^ -> \A, $ -> \Z)
  • l - Find longest possible matches
  • x - Extended regex format (ignore whitespace and comments)
# Test
> jq -n '"a" | test("a")'
> jq -n '"a" | test("a", "x")'
> echo -n '["xabcd", "ABC"]' | jq '.[] | test("a b c # spaces are ignored"; "ix")'

# Match
echo -n '"abc abc"' | jq 'match("(abc)+"; "g")'
  "offset": 0,
  "length": 3,
  "string": "abc",
  "captures": [
      "offset": 0,
      "length": 3,
      "string": "abc",
      "name": null
  "offset": 4,
  "length": 3,
  "string": "abc",
  "captures": [
      "offset": 4,
      "length": 3,
      "string": "abc",
      "name": null
> echo -n 'abc' | jq '[ match("."; "g")] | length'

# Capture
> echo -n '"xyzzy-14"' | jq 'capture("(?<a>[a-z]+)-(?<n>[0-9]+)")'
  "a": "xyzzy",
  "n": "14"

# Split
> echo -n '"ab,cd, ef"' | jq 'split(", *"; null)'
# Splits
> echo -n '"ab,cd, ef"' | jq 'splits(", *")'

# Sub
> echo -n '"ab,cd, ef"' |jq 'sub("[^a-z]*(?<x>[a-z]+)"; "Z\(.x)"; "g")'

> echo -n '"Ab"' | jq '[sub("(?<a>.)"; "\(.a|ascii_upcase)", "\(.a|ascii_downcase)")]'

> echo -n '"Ab"' | jq 'gsub("(?<x>.)[^a]*"; "+\(.x)-")'

> jq -n 'env'
> jq -n 'env'

> jq -n 'env | keys | length'

> jq -n 'env | with_entries(select ((.key|startswith("TERM_")) or .key == "DOCKER_CONTAINER_VERSION_TAG"))'
  "TERM_SESSION_ID": "w0t0p0:D97EB7AC-19B8-4FEF-BB65-E892404B3F6C",
  "TERM_PROGRAM": "iTerm.app"


  • One-іnput C functions: acos, acosh, asin, asinh, atan, atanh, cbrt, ceil, cos, cosh, erf, erfc, exp, exp10, exp2, expm1, fabs, floor, gamma, j0, j1, lgamma, log, log10, log1p, log2, logb, nearbyint, pow10, rint, round, significand, sin, sinh, sqrt, tan, tanh, tgamma, trunc, y0, y1.
  • Two-input C math functions: atan2, copysign, drem, fdim, fmax, fmin, fmod frexp, hypot, jn, ldexp, modf, nextafter, nexttoward, pow, remainder, scalb, scalbln, yn.
  • Three-input C math functions: fma.
> echo "[1,2,3,4,5]" | jq  '. | add'
> echo "[1,2,3,4,5]" | jq  '. | add | sqrt'


You can customize colored output by setting: JQ_COLORS (e.g "JQ_COLORS=1;30:0;39:0;39:0;39:0;32:1;39:1;39")