# Catching JSON parse errors

**URL:** <https://discuss.elastic.co/t/catching-json-parse-errors/78083>\
**Category:** Logstash\
**Created:** [March 10, 2017, 5:09am UTC](https://discuss.elastic.co/t/catching-json-parse-errors/78083 "2017-03-10T05:09:50Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![elssar](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/elssar/32/9216_2.png) [@elssar](https://discuss.elastic.co/u/elssar)\
**Post date:** [March 10, 2017, 5:09am UTC](https://discuss.elastic.co/t/catching-json-parse-errors/78083/1 "2017-03-10T05:09:50Z")

</div>

Hi,

We have an old logstash system (v1.5) which had been running just fine until recently. Some of the messages are getting mangled, for reasons unknown, and the JSON filter keeps throwing parse fail errors. That causes logstash to panic and refuse new connections. This only happens intermittently.

While I investigate the reason for mangled logs, I'd like to ensure that logstash stops erroring out. Is there a way to catch JSON parse errors in logstash.

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [March 10, 2017, 8:40am UTC](https://discuss.elastic.co/t/catching-json-parse-errors/78083/2 "2017-03-10T08:40:00Z")

</div>

Please supply more details and logs from Logstash. The json filter should never panic over parse errors. It'll just tag failing events `_jsonparsefailure` and pass them on as plain text.

---

<div class="post-metadata">

**Author:** ![elssar](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/elssar/32/9216_2.png) [@elssar](https://discuss.elastic.co/u/elssar)\
**Post date:** [March 10, 2017, 11:16am UTC](https://discuss.elastic.co/t/catching-json-parse-errors/78083/3 "2017-03-10T11:16:20Z")

</div>

```auto
{:timestamp=>"2017-03-10T09:01:22.302000+0000", :message=>"Trouble parsing json", :source=>"json_message", :raw=>"[Invalid JSON]", :exception=>#<LogStash::Json::ParserError: Unexpected character ('i' (code 105)): was expecting a colon to separate field name and value
 at [Source: [B@594c6d08; line: 1, column: 203]>, :level=>:warn}

```

After a bunch of these, I get logs like these

```auto
{:timestamp=>"2017-03-10T04:37:20.471000+0000", :message=>"CircuitBreaker::rescuing exceptions", :name=>"Lumberjack input", :exception=>LogStash::SizedQueueTimeout::TimeoutError, :level=>:warn}
{:timestamp=>"2017-03-10T04:37:20.472000+0000", :message=>"Lumberjack input: The circuit breaker has detected a slowdown or stall in the pipeline, the input is closing the current connection and rejecting new connection until the pipeline recover.", :exception=>LogStash::CircuitBreaker::HalfOpenBreaker, :level=>:warn}
{:timestamp=>"2017-03-10T04:37:20.473000+0000", :message=>"CircuitBreaker::rescuing exceptions", :name=>"Lumberjack input", :exception=>LogStash::SizedQueueTimeout::TimeoutError, :level=>:warn}
{:timestamp=>"2017-03-10T04:37:20.477000+0000", :message=>"CircuitBreaker::rescuing exceptions", :name=>"Lumberjack input", :exception=>LogStash::SizedQueueTimeout::TimeoutError, :level=>:warn}
{:timestamp=>"2017-03-10T04:37:20.478000+0000", :message=>"Lumberjack input: The circuit breaker has detected a slowdown or stall in the pipeline, the input is closing the current connection and rejecting new connection until the pipeline recover.", :exception=>LogStash::CircuitBreaker::HalfOpenBreaker, :level=>:warn}
{:timestamp=>"2017-03-10T04:37:20.479000+0000", :message=>"CircuitBreaker::rescuing exceptions", :name=>"Lumberjack input", :exception=>LogStash::SizedQueueTimeout::TimeoutError, :level=>:warn}

```

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [March 10, 2017, 12:40pm UTC](https://discuss.elastic.co/t/catching-json-parse-errors/78083/4 "2017-03-10T12:40:52Z")

</div>

Okay, but I'm still not convinced that the JSON parse problem is what's causing the pipeline stall. The way I read the code invalid JSON will be passed through. Please show your Logstash configuration.

More recent versions of the filter have an option that silences the tagging and warning when parse errors occur.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 7, 2017, 12:40pm UTC](https://discuss.elastic.co/t/catching-json-parse-errors/78083/5 "2017-04-07T12:40:52Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
