# Can I use both json and plain logs in a common filebeat input?

**URL:** <https://discuss.elastic.co/t/can-i-use-both-json-and-plain-logs-in-a-common-filebeat-input/36879>\
**Category:** Logstash\
**Created:** [December 10, 2015, 1:28pm UTC](https://discuss.elastic.co/t/can-i-use-both-json-and-plain-logs-in-a-common-filebeat-input/36879 "2015-12-10T13:28:52Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![iammichiel](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/iammichiel/32/6557_2.png) [@iammichiel](https://discuss.elastic.co/u/iammichiel)\
**Post date:** [December 10, 2015, 1:28pm UTC](https://discuss.elastic.co/t/can-i-use-both-json-and-plain-logs-in-a-common-filebeat-input/36879/1 "2015-12-10T13:28:52Z")

</div>

Hi,

I'm trying to send both classic nginx logs (access/error) using filebeat. Which works great.  
Now, my application, also spawns logs which are json encoded. Which also works great if I send only these.

It is when I try to combine both of these input to the same logstash, things get complicated. When parsing the application logs, I simply add a `codec => json` to the input field. However, since the nginx logs are plain text, json parsing fails.

How can I solve this problem? Sending both logs to the same logstash instance?  
Can I filter in the input section?

Thanks!

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [December 10, 2015, 1:35pm UTC](https://discuss.elastic.co/t/can-i-use-both-json-and-plain-logs-in-a-common-filebeat-input/36879/2 "2015-12-10T13:35:01Z")

</div>

No, but you can use a plain codec in the input and either a) selectively apply a json filter if the line looks like JSON (e.g. begins with a left curly brace) or b) unconditionally apply a json filter and ignore any parsing errors.

---

<div class="post-metadata">

**Author:** ![Justin\_Lintz](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/justin_lintz/32/1090_2.png) [@Justin\_Lintz](https://discuss.elastic.co/u/Justin_Lintz)\
**Post date:** [December 10, 2015, 5:54pm UTC](https://discuss.elastic.co/t/can-i-use-both-json-and-plain-logs-in-a-common-filebeat-input/36879/3 "2015-12-10T17:54:55Z")

</div>

I thought the json codec falls back to plaintext if it can't parse properly

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [December 10, 2015, 5:58pm UTC](https://discuss.elastic.co/t/can-i-use-both-json-and-plain-logs-in-a-common-filebeat-input/36879/4 "2015-12-10T17:58:43Z")

</div>

> I thought the json codec falls back to plaintext if it can't parse properly

Yes, I think you're right. But does it add a tag if there's a failure? I figure one might want to distinguish messages that were JSON from plaintext messages, which the `_jsonparsefailure` tag added by the json filter would do.

One might also want to check whether the codec logs anything about the parsing failures—with a lot of plaintext messages that could produce a lot of garbage messages in the Logstash log.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 5:19am UTC](https://discuss.elastic.co/t/can-i-use-both-json-and-plain-logs-in-a-common-filebeat-input/36879/5 "2017-07-06T05:19:00Z")

</div>


