# Edit log before parsing?

**URL:** <https://discuss.elastic.co/t/edit-log-before-parsing/154855>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [October 31, 2018, 1:55pm UTC](https://discuss.elastic.co/t/edit-log-before-parsing/154855 "2018-10-31T13:55:39Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![OffColour](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/offcolour/32/57122_2.png) [@OffColour](https://discuss.elastic.co/u/OffColour)\
**Post date:** [October 31, 2018, 1:55pm UTC](https://discuss.elastic.co/t/edit-log-before-parsing/154855/1 "2018-10-31T13:55:39Z")

</div>

Hi,

I've got some logs that are badly formed JSON. I know the exact field with the problem (it's missing a value), but getting all the components that are doing this fixed is going to take some time.

Is there any way to fix this in the raw log line before it's parsed as a stopgap measure?

---

<div class="post-metadata">

**Author:** ![jsoriano](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jsoriano/32/27920_2.png) [@jsoriano](https://discuss.elastic.co/u/jsoriano)\
**Post date:** [October 31, 2018, 2:15pm UTC](https://discuss.elastic.co/t/edit-log-before-parsing/154855/2 "2018-10-31T14:15:57Z")

</div>

Hi @OffColour,

I am not sure if it can be solved from filebeat, it depends on the exact modification needed.

There are some options to modify already parsed log lines, you can for example add custom fields with the [`fields`](https://www.elastic.co/guide/en/beats/filebeat/6.4/configuration-general-options.html#libbeat-configuration-fields) setting to add static custom fields to all events, you can also use [processors](https://www.elastic.co/guide/en/beats/filebeat/6.4/filtering-and-enhancing-data.html) to do some modifications, or [define an ingest pipeline](https://www.elastic.co/guide/en/beats/filebeat/6.4/configuring-ingest-node.html) to do further modifications.

But if the line is not parsed because it is an invalid JSON, then this can be more complicated, you can try to collect the lines as normal log lines (without JSON parsing), and then try to modify them with the mentioned mechanisms and finally parse the JSON using the [ingest processor for JSON fields](https://www.elastic.co/guide/en/elasticsearch/reference/6.4/json-processor.html).

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 28, 2018, 2:15pm UTC](https://discuss.elastic.co/t/edit-log-before-parsing/154855/3 "2018-11-28T14:15:59Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
