# Discover in Kibana show differrent data in Table vs. JSON

**URL:** <https://discuss.elastic.co/t/discover-in-kibana-show-differrent-data-in-table-vs-json/254892>\
**Category:** Logstash\
**Created:** [November 10, 2020, 10:27am UTC](https://discuss.elastic.co/t/discover-in-kibana-show-differrent-data-in-table-vs-json/254892 "2020-11-10T10:27:29Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![Michaela\_Krkosova](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/michaela_krkosova/32/46926_2.png) [@Michaela\_Krkosova](https://discuss.elastic.co/u/Michaela_Krkosova)\
**Post date:** [November 10, 2020, 10:27am UTC](https://discuss.elastic.co/t/discover-in-kibana-show-differrent-data-in-table-vs-json/254892/1 "2020-11-10T10:27:29Z")

</div>

Hi there  
I use ELK Stack 7.2. and when I import data, I Discover in Kibana I see proper data, but in JSON, there is missing letter (Š). I see that Kibana can read it properly. I push data to Elastistack via Logstash (ISO-8859-1 coding).

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/1/b/1be838ffef3e411c68c05b7286f57fcf8863ec63.png)

I need to get proper data to my app, should I modify my REST request?  
Thank you

Misha

---

<div class="post-metadata">

**Author:** ![Vadims\_Daleckis](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/vadims_daleckis/32/57613_2.png) [@Vadims\_Daleckis](https://discuss.elastic.co/u/Vadims_Daleckis)\
**Post date:** [November 10, 2020, 11:17am UTC](https://discuss.elastic.co/t/discover-in-kibana-show-differrent-data-in-table-vs-json/254892/2 "2020-11-10T11:17:49Z")

</div>

Usually UTF-8 encoding should be used for JSON, see [https://tools.ietf.org/html/rfc8259#section-8.1](https://tools.ietf.org/html/rfc8259#section-8.1)

Is it possible for you to change Logstash encoding to UTF-8 instead of ISO-8859-1 encoding? If yes, does it solve the problem?

---

<div class="post-metadata">

**Author:** ![Michaela\_Krkosova](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/michaela_krkosova/32/46926_2.png) [@Michaela\_Krkosova](https://discuss.elastic.co/u/Michaela_Krkosova)\
**Post date:** [November 10, 2020, 11:38am UTC](https://discuss.elastic.co/t/discover-in-kibana-show-differrent-data-in-table-vs-json/254892/3 "2020-11-10T11:38:24Z")

</div>

Hi,  
UTF-8 didn't work for czech diacritics (č,š,ť,...) ☹ so we must use ISO-8859-1  
here is Logstash conf

```
input {
    tcp {
        port => 5010
    }
    beats {
        port => 5044
    }
    file {
        mode => "read"
        path => ["D:/fulltext-search-input/*.log"]
        codec => json { charset => "ISO-8859-1" }
        start_position => "beginning"
        sincedb_path => "NUL"
        file_completed_action => "delete"   
    }
}

output {
  elasticsearch {
    	hosts => ["http://HELIOS-TELE:9200"]
        index => "%{[@metadata][beat]}"
        document_id => "%{[@metadata][@id]}"
        action => "%{[@metadata][@action]}"
    }
}
```

---

<div class="post-metadata">

**Author:** ![Vadims\_Daleckis](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/vadims_daleckis/32/57613_2.png) [@Vadims\_Daleckis](https://discuss.elastic.co/u/Vadims_Daleckis)\
**Post date:** [November 10, 2020, 5:42pm UTC](https://discuss.elastic.co/t/discover-in-kibana-show-differrent-data-in-table-vs-json/254892/4 "2020-11-10T17:42:15Z")

</div>

I've added `Logstash` tag to this thread to see if Logstash team has ideas.

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [November 10, 2020, 7:13pm UTC](https://discuss.elastic.co/t/discover-in-kibana-show-differrent-data-in-table-vs-json/254892/5 "2020-11-10T19:13:37Z")

</div>

I would suggest removing the json codec using a plain (or other) codec to do the charset handling, then parsing it using a json filter.

There is an [open issue](https://github.com/logstash-plugins/logstash-codec-json/issues/8) from jordansissel that says using the charset option on a json codec does not work.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 8, 2020, 7:13pm UTC](https://discuss.elastic.co/t/discover-in-kibana-show-differrent-data-in-table-vs-json/254892/6 "2020-12-08T19:13:45Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
