# Beats to post JSON to elasticsearch

**URL:** <https://discuss.elastic.co/t/beats-to-post-json-to-elasticsearch/53651>\
**Category:** Beats\
**Created:** [June 22, 2016, 11:03am UTC](https://discuss.elastic.co/t/beats-to-post-json-to-elasticsearch/53651 "2016-06-22T11:03:52Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![Rohit\_Shrivastava](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rohit_shrivastava/32/9850_2.png) [@Rohit\_Shrivastava](https://discuss.elastic.co/u/Rohit_Shrivastava)\
**Post date:** [June 22, 2016, 11:03am UTC](https://discuss.elastic.co/t/beats-to-post-json-to-elasticsearch/53651/1 "2016-06-22T11:03:52Z")

</div>

Hi

I was following [https://www.elastic.co/blog/structured-logging-filebeat](https://www.elastic.co/blog/structured-logging-filebeat)

I am using Folebeat 1.2.3. Is there any requirement of any specifc version of ElasticSearch also to make it work. I am posting to AWS ElasticSearch service.

After following everything also it has not created message as json.  
I am getting following output

`{ "_index": "test-2016.06.22", "_type": "log", "_id": "AVV3sPlZgL-ny14uxzET", "_score": null, "_source": { "@timestamp": "2016-06-22T10:38:52.292Z", "beat": { "hostname": "QHSL24698", "name": "QHSL24698" }, "count": 1, "fields": { "planet": "Magrathea", "service": "<nil>" }, "input_type": "log", "message": "{\"verified\": false, \"user\": \"arthur\", \"session_id\": \"91e5b9d\", \"id\": 42, \"event\": \"tests\"}", "offset": 476, "source": "C:\\Users\\shrivastavar\\Documents\\Tesla\\Architecture Work\\ELK\\NetSeriLog\\NetSeriLogSample\\logs\\log.txt", "type": "log" }, "fields": { "@timestamp": [1466591932292] }, "sort": [1466591932292] }`

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [June 22, 2016, 1:04pm UTC](https://discuss.elastic.co/t/beats-to-post-json-to-elasticsearch/53651/2 "2016-06-22T13:04:51Z")

</div>

From the blog post, "Starting with version 5.0 (currently in alpha, but you can give it a try), Filebeat is able to also natively decode JSON objects if they are stored one per line like in the above example."

You need to use Filebeat 5.x if you want JSON support.

---

<div class="post-metadata">

**Author:** ![Rohit\_Shrivastava](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rohit_shrivastava/32/9850_2.png) [@Rohit\_Shrivastava](https://discuss.elastic.co/u/Rohit_Shrivastava)\
**Post date:** [June 23, 2016, 2:06pm UTC](https://discuss.elastic.co/t/beats-to-post-json-to-elasticsearch/53651/3 "2016-06-23T14:06:53Z")

</div>

I am installing on windows 7 and I have following configuration for logging in filebeat.yml

`logging.level: info logging.to_files: true logging.files.path: "C:\ProgramData\filebeat\Logs" logging.files.name: mybeat.log`

However I see no logs and nothing happens. could you please tell me why filebeat not logging anything?

---

<div class="post-metadata">

**Author:** ![Rohit\_Shrivastava](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rohit_shrivastava/32/9850_2.png) [@Rohit\_Shrivastava](https://discuss.elastic.co/u/Rohit_Shrivastava)\
**Post date:** [June 24, 2016, 10:21am UTC](https://discuss.elastic.co/t/beats-to-post-json-to-elasticsearch/53651/4 "2016-06-24T10:21:53Z")

</div>

Managed to fix this issue. @andrewkroh could you please tell me is there any workaround to make filebeat5.0.0alpha3 to work for json with line breaks basically multi line support?

---

<div class="post-metadata">

**Author:** ![steffens](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/steffens/32/79630_2.png) [@steffens](https://discuss.elastic.co/u/steffens)\
**Post date:** [June 24, 2016, 11:44am UTC](https://discuss.elastic.co/t/beats-to-post-json-to-elasticsearch/53651/5 "2016-06-24T11:44:18Z")

</div>

It's an [open issue on github](https://github.com/elastic/beats/issues/1208).

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 13, 2016, 11:03am UTC](https://discuss.elastic.co/t/beats-to-post-json-to-elasticsearch/53651/6 "2016-07-13T11:03:54Z")

</div>

This topic was automatically closed after 21 days. New replies are no longer allowed.
