# All Packetbeat dashboards version 7.15.0 don't work: Invalid JSON in search source

**URL:** <https://discuss.elastic.co/t/all-packetbeat-dashboards-version-7-15-0-dont-work-invalid-json-in-search-source/285824>\
**Category:** Beats\
**Tags:** packetbeat\
**Created:** [October 4, 2021, 2:06pm UTC](https://discuss.elastic.co/t/all-packetbeat-dashboards-version-7-15-0-dont-work-invalid-json-in-search-source/285824 "2021-10-04T14:06:06Z")\
**Posts on this page:** 16\
**Page:** 1

<div class="post-metadata">

**Author:** ![hermanator](https://avatars.discourse-cdn.com/v4/letter/h/d9b06d/32.png) [@hermanator](https://discuss.elastic.co/u/hermanator)\
**Post date:** [October 4, 2021, 2:06pm UTC](https://discuss.elastic.co/t/all-packetbeat-dashboards-version-7-15-0-dont-work-invalid-json-in-search-source/285824/1 "2021-10-04T14:06:06Z")

</div>

Hello,  
I can't get the dashboards for packetbeat to work. The list with packetbeat dashboards are visible in Kibana, but after clicking any of them I get the error: `Invalid JSON in search source.`

I've setup packetbeat version 7.15.0 with the command packetbeat setup --dashboards

---

<div class="post-metadata">

**Author:** ![hermanator](https://avatars.discourse-cdn.com/v4/letter/h/d9b06d/32.png) [@hermanator](https://discuss.elastic.co/u/hermanator)\
**Post date:** [October 4, 2021, 4:34pm UTC](https://discuss.elastic.co/t/all-packetbeat-dashboards-version-7-15-0-dont-work-invalid-json-in-search-source/285824/2 "2021-10-04T16:34:02Z")

</div>

looks like a bug in the packetbeat DEB 7.15.0. Files in directory /usr/share/packetbeat/kibana/7/dashboard/ contain too much backslashes.

Can someone fix this?

---

<div class="post-metadata">

**Author:** ![Ryan\_Schellenberg](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ryan_schellenberg/32/95491_2.png) [@Ryan\_Schellenberg](https://discuss.elastic.co/u/Ryan_Schellenberg)\
**Post date:** [October 6, 2021, 11:09am UTC](https://discuss.elastic.co/t/all-packetbeat-dashboards-version-7-15-0-dont-work-invalid-json-in-search-source/285824/3 "2021-10-06T11:09:58Z")

</div>

I just installed Packetbeat today and ran into the same error

---

<div class="post-metadata">

**Author:** ![Ryan\_Schellenberg](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ryan_schellenberg/32/95491_2.png) [@Ryan\_Schellenberg](https://discuss.elastic.co/u/Ryan_Schellenberg)\
**Post date:** [October 6, 2021, 1:47pm UTC](https://discuss.elastic.co/t/all-packetbeat-dashboards-version-7-15-0-dont-work-invalid-json-in-search-source/285824/4 "2021-10-06T13:47:28Z")

</div>

Turns out you have to have data in the indices... My bad.

---

<div class="post-metadata">

**Author:** ![hermanator](https://avatars.discourse-cdn.com/v4/letter/h/d9b06d/32.png) [@hermanator](https://discuss.elastic.co/u/hermanator)\
**Post date:** [October 6, 2021, 10:07pm UTC](https://discuss.elastic.co/t/all-packetbeat-dashboards-version-7-15-0-dont-work-invalid-json-in-search-source/285824/5 "2021-10-06T22:07:33Z")

</div>

did you install from a Debian package? And version 7.15.0?

---

<div class="post-metadata">

**Author:** ![Ryan\_Schellenberg](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ryan_schellenberg/32/95491_2.png) [@Ryan\_Schellenberg](https://discuss.elastic.co/u/Ryan_Schellenberg)\
**Post date:** [October 7, 2021, 2:55pm UTC](https://discuss.elastic.co/t/all-packetbeat-dashboards-version-7-15-0-dont-work-invalid-json-in-search-source/285824/6 "2021-10-07T14:55:14Z")

</div>

I did - downloaded from here:  
[https://artifacts.elastic.co/downloads/beats/packetbeat/packetbeat-7.15.0-amd64.deb](https://artifacts.elastic.co/downloads/beats/packetbeat/packetbeat-7.15.0-amd64.deb)

I have data flowing into the indices now, still throwing the json error.

---

<div class="post-metadata">

**Author:** ![myleftsocket](https://avatars.discourse-cdn.com/v4/letter/m/d07c76/32.png) [@myleftsocket](https://discuss.elastic.co/u/myleftsocket)\
**Post date:** [October 8, 2021, 5:58pm UTC](https://discuss.elastic.co/t/all-packetbeat-dashboards-version-7-15-0-dont-work-invalid-json-in-search-source/285824/8 "2021-10-08T17:58:15Z")

</div>

Same problem here.. ☹

---

<div class="post-metadata">

**Author:** ![neil6323](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/neil6323/32/92234_2.png) [@neil6323](https://discuss.elastic.co/u/neil6323)\
**Post date:** [October 12, 2021, 5:59am UTC](https://discuss.elastic.co/t/all-packetbeat-dashboards-version-7-15-0-dont-work-invalid-json-in-search-source/285824/9 "2021-10-12T05:59:17Z")

</div>

I have also hit this issue. I've got some custom dashboards that use packetbeat, configured from a previous version that work, but the out of the box dashboards fail as stated.

---

<div class="post-metadata">

**Author:** ![jamie.hynds](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jamie.hynds/32/84205_2.png) [@jamie.hynds](https://discuss.elastic.co/u/jamie.hynds)\
**Post date:** [October 13, 2021, 1:20pm UTC](https://discuss.elastic.co/t/all-packetbeat-dashboards-version-7-15-0-dont-work-invalid-json-in-search-source/285824/10 "2021-10-13T13:20:31Z")

</div>

Hi all, thanks for reporting this issue with our Packetbeat dashboards and apologies for the inconvenience it's causing. After some investigation, it's an issue on our side and we're currently working on an urgent fix. Will report back once I have a timeline as to when the fix will be available.

---

<div class="post-metadata">

**Author:** ![kvch](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kvch/32/72058_2.png) [@kvch](https://discuss.elastic.co/u/kvch)\
**Post date:** [October 13, 2021, 1:42pm UTC](https://discuss.elastic.co/t/all-packetbeat-dashboards-version-7-15-0-dont-work-invalid-json-in-search-source/285824/11 "2021-10-13T13:42:32Z")

</div>

PR is available with a fix: [Remove unncessary Python script for unpacking dashboards by kvch · Pull Request #28395 · elastic/beats · GitHub](https://github.com/elastic/beats/pull/28395)

---

<div class="post-metadata">

**Author:** ![fgjensen](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/fgjensen/32/62320_2.png) [@fgjensen](https://discuss.elastic.co/u/fgjensen)\
**Post date:** [October 14, 2021, 8:45pm UTC](https://discuss.elastic.co/t/all-packetbeat-dashboards-version-7-15-0-dont-work-invalid-json-in-search-source/285824/12 "2021-10-14T20:45:16Z")

</div>

Same error message in the winlogbeat dashboards in the 7.15.0 package as in the packetbeat for debian. Could you provide a fix for that, too, please?

---

<div class="post-metadata">

**Author:** ![kvch](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kvch/32/72058_2.png) [@kvch](https://discuss.elastic.co/u/kvch)\
**Post date:** [October 15, 2021, 9:01am UTC](https://discuss.elastic.co/t/all-packetbeat-dashboards-version-7-15-0-dont-work-invalid-json-in-search-source/285824/13 "2021-10-15T09:01:02Z")

</div>

My PR fixes the problem for **all** Beats, including Winlogbeat.

---

<div class="post-metadata">

**Author:** ![hermanator](https://avatars.discourse-cdn.com/v4/letter/h/d9b06d/32.png) [@hermanator](https://discuss.elastic.co/u/hermanator)\
**Post date:** [October 15, 2021, 8:39pm UTC](https://discuss.elastic.co/t/all-packetbeat-dashboards-version-7-15-0-dont-work-invalid-json-in-search-source/285824/14 "2021-10-15T20:39:51Z")

</div>

Problem still exists in 7.15.1.

Invalid JSON in search source after loading packetbeat dashboards into Kibana.

---

<div class="post-metadata">

**Author:** ![kvch](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kvch/32/72058_2.png) [@kvch](https://discuss.elastic.co/u/kvch)\
**Post date:** [October 18, 2021, 8:48am UTC](https://discuss.elastic.co/t/all-packetbeat-dashboards-version-7-15-0-dont-work-invalid-json-in-search-source/285824/15 "2021-10-18T08:48:47Z")

</div>

Yes, it exists. The fix is going to be released in 7.15.2.

---

<div class="post-metadata">

**Author:** ![Riley\_Cooper](https://avatars.discourse-cdn.com/v4/letter/r/bbce88/32.png) [@Riley\_Cooper](https://discuss.elastic.co/u/Riley_Cooper)\
**Post date:** [October 18, 2021, 11:15pm UTC](https://discuss.elastic.co/t/all-packetbeat-dashboards-version-7-15-0-dont-work-invalid-json-in-search-source/285824/16 "2021-10-18T23:15:02Z")

</div>

For all wondering, I noticed the JSON format in the .json files in the kibana setup directory are all incorrectly formatted, you can easily manually change the formatting within Kibana itself (under 'Stack Management' \> 'Saved Objects' \> '{SELECTED DASHBOARD}') or within the files themselves if you urgently need to use the dashboards.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 16, 2021, 1:15am UTC](https://discuss.elastic.co/t/all-packetbeat-dashboards-version-7-15-0-dont-work-invalid-json-in-search-source/285824/17 "2021-11-16T01:15:37Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
