# Broken JSON (Rsyslog -\> Logstash) - Message breaking in wrong place

**URL:** <https://discuss.elastic.co/t/broken-json-rsyslog-logstash-message-breaking-in-wrong-place/206424>\
**Category:** Logstash\
**Created:** [November 4, 2019, 2:47pm UTC](https://discuss.elastic.co/t/broken-json-rsyslog-logstash-message-breaking-in-wrong-place/206424 "2019-11-04T14:47:52Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![iget-master](https://avatars.discourse-cdn.com/v4/letter/i/f17d59/32.png) [@iget-master](https://discuss.elastic.co/u/iget-master)\
**Post date:** [November 4, 2019, 2:47pm UTC](https://discuss.elastic.co/t/broken-json-rsyslog-logstash-message-breaking-in-wrong-place/206424/1 "2019-11-04T14:47:52Z")

</div>

Hi guys,

I have a setup where my `rsyslog` log messages are sent to Logstash in JSON format.

My template in rsyslog is this:

```
template(name="json-template"
  type="list") {
    constant(value="{")
      constant(value="\"@timestamp\":\"") property(name="timereported" dateFormat="rfc3339")
      constant(value="\",\"@version\":\"1")
      constant(value="\",\"message\":\"") property(name="msg" format="json")
      constant(value="\",\"sysloghost\":\"") property(name="hostname")
      constant(value="\",\"severity\":\"") property(name="syslogseverity-text")
      constant(value="\",\"facility\":\"") property(name="syslogfacility-text")
      constant(value="\",\"programname\":\"") property(name="programname")
      constant(value="\",\"procid\":\"") property(name="procid")
    constant(value="\"}\n")
}

```

This used to works in later 6.X versions. But after upgrading to 7.x (not sure if that's the reason, but coincided) it's now broken: Some of our log messages are being tagged with `_jsonparsefailure`. Inspecting the original message that's now stored on "message" field, it always looks like a broken json.

Here some example of messages that failed:

```
programname":"CRON","procid":"14896"}

```

{"@timestamp":"2019-11-04T10:39:01.503132-03:00","@version":"1","message":" (www-data) CMD (php /var/www/artisan schedule:run \>\> /dev/null 2\>&1)","sysloghost":"fe67d4888ff3","severity":"info","facility":"cron","programname":"CRON","procid":"14897"}

```
0:36:36.358225-03:00","@version":"1","message":" custom.INFO: Triggered Aaaaa\\Bbbbbbbbb\\EmailMessageCreated [] []","sysloghost":"fe67d4888ff3","severity":"info","facility":"user","programname":"changedforsafety","procid":"12611"}

y":"cron","programname":"CRON","procid":"14675"}

```

Note that the message is always broken, something like if the logstash (or rsyslog) was not parsing the json from the start.

Can someone help me with that?

---

<div class="post-metadata">

**Author:** ![iget-master](https://avatars.discourse-cdn.com/v4/letter/i/f17d59/32.png) [@iget-master](https://discuss.elastic.co/u/iget-master)\
**Post date:** [November 4, 2019, 2:59pm UTC](https://discuss.elastic.co/t/broken-json-rsyslog-logstash-message-breaking-in-wrong-place/206424/2 "2019-11-04T14:59:21Z")

</div>

Searching again I found this topic: [JSON data split up (\_jsonparseerror) in logstash-7.2.0-1. Works fine in logstash-7.1.1-1](https://discuss.elastic.co/t/json-data-split-up-jsonparseerror-in-logstash-7-2-0-1-works-fine-in-logstash-7-1-1-1/190624/4)

Looks like my problem is similar. I just changed my codec from `json` to `json_lines` and will wait a few hours to check if the problem disappear.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 2, 2019, 2:59pm UTC](https://discuss.elastic.co/t/broken-json-rsyslog-logstash-message-breaking-in-wrong-place/206424/3 "2019-12-02T14:59:32Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
