# Configure logstash to input JSON file into elasticsearch

**URL:** <https://discuss.elastic.co/t/configure-logstash-to-input-json-file-into-elasticsearch/182313>\
**Category:** Logstash\
**Created:** [May 22, 2019, 7:48pm UTC](https://discuss.elastic.co/t/configure-logstash-to-input-json-file-into-elasticsearch/182313 "2019-05-22T19:48:05Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![esportuga](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/esportuga/32/45918_2.png) [@esportuga](https://discuss.elastic.co/u/esportuga)\
**Post date:** [May 22, 2019, 7:48pm UTC](https://discuss.elastic.co/t/configure-logstash-to-input-json-file-into-elasticsearch/182313/1 "2019-05-22T19:48:05Z")

</div>

Hello,

I'm accessing tweets with Tweepy and generating complete .JSON files for each Tweet.  
I set up my logstash to read each of these files and index them in Elasticsearch

See below my logstash configuration file:

input{  
file{  
codec =\> json  
path =\> ["C:/----my directory-----/twitter\_logs\*.json\*"]  
start\_position =\> "beginning"  
sincedb\_path =\> "nul"  
}  
}

filter {  
json {  
source =\> "message"  
}  
}

output{  
elasticsearch {  
hosts =\> "localhost:9200"  
index =\> "twitter"  
}  
}

See the contents of each .JSON file.

{  
"created\_at":"Tue May 21 22:18:17 +0000 2019",  
"id":1130961032392990700,  
"id\_str":"1130961032392990720",  
"text":"Ainda não superou o final de Game of Thrones? Nós também não! Confira o que preparamos para os fãs que já não sab… [https://t.co/G93RryP9OS](https://t.co/G93RryP9OS)",  
"truncated":true,  
"entities":{  
"hashtags":{},  
"symbols":{},  
"user\_mentions":{},  
"urls":[{  
"url":"[https://t.co/G93RryP9OS](https://t.co/G93RryP9OS)",  
"expanded\_url":"[https://twitter.com/i/web/status/1130961032392990720](https://twitter.com/i/web/status/1130961032392990720)",  
"display\_url":"[twitter.com/i/web/status/1…](http://twitter.com/i/web/status/1%E2%80%A6)",  
"indices":[  
117,  
140  
]  
}]  
},  
"source":"[Twitter Web Client](http://twitter.com)",  
"in\_reply\_to\_status\_id":null,  
"in\_reply\_to\_status\_id\_str":null,  
"in\_reply\_to\_user\_id":null,  
"in\_reply\_to\_user\_id\_str":null,  
"in\_reply\_to\_screen\_name":null,  
"user":{  
"id":183639847,  
"id\_str":"183639847",  
"name":"Conheça a BRQ",  
"screen\_name":"brqdigital",  
"location":"São Paulo",  
"description":"Paixão por transformar negócios com tecnologia, esse é o propósito que move a BRQ em 26 anos de história.",  
"url":"[https://t.co/IXZCQUM9nb](https://t.co/IXZCQUM9nb)",  
"entities":{  
"url":{  
"urls":[{  
"url":"[https://t.co/IXZCQUM9nb](https://t.co/IXZCQUM9nb)",  
"expanded\_url":"[http://www.brq.com](http://www.brq.com)",  
"display\_url":"[brq.com](http://brq.com)",  
"indices":[  
0,  
23  
]  
}]  
},  
"description":{  
"urls":{}  
}  
},  
"protected":false,  
"followers\_count":551,  
"friends\_count":84,  
"listed\_count":9,  
"created\_at":"Fri Aug 27 14:25:19 +0000 2010",  
"favourites\_count":8,  
"utc\_offset":null,  
"time\_zone":null,  
"geo\_enabled":true,  
"verified":false,  
"statuses\_count":606,  
"lang":null,  
"contributors\_enabled":false,  
"is\_translator":false,  
"is\_translation\_enabled":false,  
"profile\_background\_color":"4D8BB7",  
"profile\_background\_image\_url":"[http://abs.twimg.com/images/themes/theme4/bg.gif](http://abs.twimg.com/images/themes/theme4/bg.gif)",  
"profile\_background\_image\_url\_https":"[https://abs.twimg.com/images/themes/theme4/bg.gif](https://abs.twimg.com/images/themes/theme4/bg.gif)",  
"profile\_background\_tile":false,  
"profile\_image\_url":"[http://pbs.twimg.com/profile\_images/1026460187195043840/LDTi5Im9\_normal.jpg](http://pbs.twimg.com/profile_images/1026460187195043840/LDTi5Im9_normal.jpg)",  
"profile\_image\_url\_https":"[https://pbs.twimg.com/profile\_images/1026460187195043840/LDTi5Im9\_normal.jpg](https://pbs.twimg.com/profile_images/1026460187195043840/LDTi5Im9_normal.jpg)",  
"profile\_banner\_url":"[https://pbs.twimg.com/profile\_banners/183639847/1523283084](https://pbs.twimg.com/profile_banners/183639847/1523283084)",  
"profile\_link\_color":"4D8BB7",  
"profile\_sidebar\_border\_color":"FFFFFF",  
"profile\_sidebar\_fill\_color":"FBECD5",  
"profile\_text\_color":"685157",  
"profile\_use\_background\_image":false,  
"has\_extended\_profile":false,  
"default\_profile":false,  
"default\_profile\_image":false,  
"following":false,  
"follow\_request\_sent":false,  
"notifications":false,  
"translator\_type":"none"  
},  
"geo":null,  
"coordinates":null,  
"place":null,  
"contributors":null,  
"is\_quote\_status":false,  
"retweet\_count":0,  
"favorite\_count":0,  
"favorited":false,  
"retweeted":false,  
"possibly\_sensitive":false,  
"lang":"pt"  
}

When I run logstash it does not recognize any changes in the directory

 ![logstash](https://us1.discourse-cdn.com/elastic/original/3X/0/6/06495f8af718a6e25801378ae06cbd680a3fad59.png)

I think I'm setting something up wrong.  
Can someone help me?

---

<div class="post-metadata">

**Author:** ![elasticforme](https://avatars.discourse-cdn.com/v4/letter/e/f05b48/32.png) [@elasticforme](https://discuss.elastic.co/u/elasticforme)\
**Post date:** [May 22, 2019, 8:13pm UTC](https://discuss.elastic.co/t/configure-logstash-to-input-json-file-into-elasticsearch/182313/2 "2019-05-22T20:13:27Z")

</div>

> [@esportuga](#):
>
> C:/----my directory-----/twitter\_logs\*.json\*"

what happens when you do output to screen

`output { stdout { codec => rubydebug } }`

---

<div class="post-metadata">

**Author:** ![esportuga](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/esportuga/32/45918_2.png) [@esportuga](https://discuss.elastic.co/u/esportuga)\
**Post date:** [May 22, 2019, 8:26pm UTC](https://discuss.elastic.co/t/configure-logstash-to-input-json-file-into-elasticsearch/182313/3 "2019-05-22T20:26:22Z")

</div>

Same results..  
Logstash started but dont read any file..

 ![logstash2](https://us1.discourse-cdn.com/elastic/original/3X/4/b/4b5a9d3ca5e4b0007ae15909f05b61eda03d8128.png)

---

<div class="post-metadata">

**Author:** ![elasticforme](https://avatars.discourse-cdn.com/v4/letter/e/f05b48/32.png) [@elasticforme](https://discuss.elastic.co/u/elasticforme)\
**Post date:** [May 22, 2019, 8:27pm UTC](https://discuss.elastic.co/t/configure-logstash-to-input-json-file-into-elasticsearch/182313/4 "2019-05-22T20:27:49Z")

</div>

try using \ rather then / slash in your path

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 19, 2019, 8:27pm UTC](https://discuss.elastic.co/t/configure-logstash-to-input-json-file-into-elasticsearch/182313/5 "2019-06-19T20:27:50Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
