# Can a logstash filter error be forwarded to elastic?

**URL:** <https://discuss.elastic.co/t/can-a-logstash-filter-error-be-forwarded-to-elastic/293742>\
**Category:** Logstash\
**Created:** [January 7, 2022, 1:06pm UTC](https://discuss.elastic.co/t/can-a-logstash-filter-error-be-forwarded-to-elastic/293742 "2022-01-07T13:06:28Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![DavidMarcu](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/davidmarcu/32/99980_2.png) [@DavidMarcu](https://discuss.elastic.co/u/DavidMarcu)\
**Post date:** [January 7, 2022, 1:06pm UTC](https://discuss.elastic.co/t/can-a-logstash-filter-error-be-forwarded-to-elastic/293742/1 "2022-01-07T13:06:28Z")

</div>

I'm having these json parsing errors from time to time:

```auto
2022-01-07T12:15:19,872][WARN][logstash.filters.json] Error parsing json
 {:source=>"message", :raw=>" { the invalid json }", :exception=>#<LogStash::Json::ParserError: Unrecognized character escape 'x' (code 120)

```

Is there a way to get the **:exception** field in the logstash config file?  
Since what I want is to create a field containing that exception message, though I'm not sure if that's possible.

---

<div class="post-metadata">

**Author:** ![hocho](https://avatars.discourse-cdn.com/v4/letter/h/8e7dd6/32.png) [@hocho](https://discuss.elastic.co/u/hocho)\
**Post date:** [January 7, 2022, 2:44pm UTC](https://discuss.elastic.co/t/can-a-logstash-filter-error-be-forwarded-to-elastic/293742/2 "2022-01-07T14:44:33Z")

</div>

If there is a json parse failure the tags field is populated with "\_jsonparsefailure". If there is a general exception field I do not know.

---

<div class="post-metadata">

**Author:** ![DavidMarcu](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/davidmarcu/32/99980_2.png) [@DavidMarcu](https://discuss.elastic.co/u/DavidMarcu)\
**Post date:** [January 7, 2022, 3:29pm UTC](https://discuss.elastic.co/t/can-a-logstash-filter-error-be-forwarded-to-elastic/293742/3 "2022-01-07T15:29:31Z")

</div>

Yeah, that seems to be case. I wanted to add in Elasticsearch more details regarding as to why and where the json filter fails to parse. I think the only chance I got if I want this behaviour is to implement a raw ruby script in a ruby filter and try to manually parse it.

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [January 7, 2022, 5:38pm UTC](https://discuss.elastic.co/t/can-a-logstash-filter-error-be-forwarded-to-elastic/293742/4 "2022-01-07T17:38:51Z")

</div>

You can re-purpose the [core](https://github.com/logstash-plugins/logstash-filter-json/blob/4d54cceab462a6e8f39d48bd72beba9b796a97be/lib/logstash/filters/json.rb#L80) of the json filter. The following code

```
    ruby {
        code => '
            @source = "message"
            source = event.get(@source)
            return unless source

            begin
                parsed = LogStash::Json.load(source)
            rescue => e
                event.set("jsonException", e.to_s)
                return
            end

            @target = "jsonData"
            if @target
                event.set(@target, parsed)
            end
        '
    }

```

results in

```
"jsonException" => "Unexpected character (',' (code 44)): was expecting a colon to separate field name and value\n at [Source: (byte[])\"{ \"baz\", \"oh!\" }\r\"; line: 1, column: 9]",

```

ETA: Come to think of it, I would remove the code that deals with @target, and use a json filter to do the actual parsing so that you have all the other options of it available. Just re-parse in ruby to capture the exception.

---

<div class="post-metadata">

**Author:** ![DavidMarcu](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/davidmarcu/32/99980_2.png) [@DavidMarcu](https://discuss.elastic.co/u/DavidMarcu)\
**Post date:** [January 10, 2022, 8:15am UTC](https://discuss.elastic.co/t/can-a-logstash-filter-error-be-forwarded-to-elastic/293742/5 "2022-01-10T08:15:44Z")

</div>

I was going to do something similar, but I think this solution is even more complete than what I had in mind.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 7, 2022, 8:15am UTC](https://discuss.elastic.co/t/can-a-logstash-filter-error-be-forwarded-to-elastic/293742/6 "2022-02-07T08:15:46Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
