# Err: Error decoding JSON

**URL:** <https://discuss.elastic.co/t/err-error-decoding-json/71244>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [January 11, 2017, 3:39pm UTC](https://discuss.elastic.co/t/err-error-decoding-json/71244 "2017-01-11T15:39:49Z")\
**Posts on this page:** 19\
**Page:** 1

<div class="post-metadata">

**Author:** ![dallmon](https://avatars.discourse-cdn.com/v4/letter/d/c37758/32.png) [@dallmon](https://discuss.elastic.co/u/dallmon)\
**Post date:** [January 11, 2017, 3:39pm UTC](https://discuss.elastic.co/t/err-error-decoding-json/71244/1 "2017-01-11T15:39:49Z")

</div>

I get this very often with Filebeat 5.1.1. I modified the logp call in json.go to log the input data. Two examples:

JSON in input file:  
{"QuestionId":922254,"Username":"jtberry","Expiration":"2016-12-28T00:04:00","Source":"Distribute Has Copy Tools","Question":"Get Has Copy Tools from all machines with any Computer Name not matching ".\*""}

Error in filebeat log:  
2017-01-11T07:26:39-07:00 ERR Error decoding JSON: json: cannot unmarshal number into Go value of type map[string]interface {} 922254,"Username":"jtberry","Expiration":"2016-12-28T00:04:00","Source":"Distribute Has Copy Tools","Question":"Get Has Copy Tools from all machines with any Computer Name not matching ".\*""}

JSON in input file:  
{"QuestionId":922254,"Username":"jtberry","Expiration":"2016-12-28T00:04:00","Source":"Distribute Has Copy Tools","Question":"Get Has Copy Tools from all machines with any Computer Name not matching ".\*""}

Error in filebeat log:  
2017-01-11T07:31:44-07:00 ERR Error decoding JSON: invalid character 'i' in literal true (expecting 'r') tion":"Get Has Copy Tools from all machines with any Computer Name not matching ".\*""}

In both cases, the JSON parser tried to parse partial lines - lines with the beginning few characters lopped off. It should be noted that we do not add to existing files, but replace the file with new data. We want all the lines logged to logstash.

Any help would be appreciated. I'm afraid I don't know enough about Filebeat to know what I should include here.

Thanks,  
Dave

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [January 11, 2017, 7:32pm UTC](https://discuss.elastic.co/t/err-error-decoding-json/71244/2 "2017-01-11T19:32:31Z")

</div>

> [@dallmon](#):
>
> It should be noted that we do not add to existing files, but replace the file with new data.

Can you add more details about how you do this? What does it? And what's your Filebeat config.

---

<div class="post-metadata">

**Author:** ![dallmon](https://avatars.discourse-cdn.com/v4/letter/d/c37758/32.png) [@dallmon](https://discuss.elastic.co/u/dallmon)\
**Post date:** [January 11, 2017, 8:10pm UTC](https://discuss.elastic.co/t/err-error-decoding-json/71244/3 "2017-01-11T20:10:55Z")

</div>

We have an application, Tanium, that writes a json file out to the directory once each day. The existing file is deleted, then the new file is created. There appear to be 1 or 2 seconds between these two events. The configuration is:

```
filebeat:
  prospectors:
    - input_type: log
      paths:
        - C:\Program Files\filebeat\FlashPlayerComputers_ToJSON.json
      document_type: beats

      tail_files: false
      close_removed: true
      clean_removed: true

      fields:
         property: infosec
         product: tanium_itsm
         tanium_type: inventory
      json.message_key: "Computer Name"

output.logstash:
  hosts: ["--logstash server--:51002"]
  ssl.certificate_authorities: ['C:\Program Files\filebeat\bundle.crt']
  ssl.certificate: 'C:\Program Files\filebeat\local.crt'
  ssl.key: 'C:\Program Files\filebeat\local.key'

```

With the clean\_removed it fails one out of 5 or 6 times, but at least 2 out of 3 times without it.

Thank you.  
Dave

---

<div class="post-metadata">

**Author:** ![ruflin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ruflin/32/3116_2.png) [@ruflin](https://discuss.elastic.co/u/ruflin)\
**Post date:** [January 12, 2017, 1:29pm UTC](https://discuss.elastic.co/t/err-error-decoding-json/71244/4 "2017-01-12T13:29:14Z")

</div>

If I understand you correctly, the error only happens on deletion of the file?

---

<div class="post-metadata">

**Author:** ![dallmon](https://avatars.discourse-cdn.com/v4/letter/d/c37758/32.png) [@dallmon](https://discuss.elastic.co/u/dallmon)\
**Post date:** [January 12, 2017, 2:02pm UTC](https://discuss.elastic.co/t/err-error-decoding-json/71244/5 "2017-01-12T14:02:48Z")

</div>

Without these three lines it happens every time the file is read. With them it happens 1 out of 5 times:

```
  tail_files: false
  close_removed: true
  clean_removed: true

```

Thanks,  
Dave

---

<div class="post-metadata">

**Author:** ![ruflin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ruflin/32/3116_2.png) [@ruflin](https://discuss.elastic.co/u/ruflin)\
**Post date:** [January 16, 2017, 1:48pm UTC](https://discuss.elastic.co/t/err-error-decoding-json/71244/6 "2017-01-16T13:48:11Z")

</div>

@dallmon Sorry to ask again. By 1 out of 5 times you mean 1 out of 5 times when a log entry is read or when the file is deleted? I'm trying to figure out if it is related to the deletion of the file or not.

---

<div class="post-metadata">

**Author:** ![dallmon](https://avatars.discourse-cdn.com/v4/letter/d/c37758/32.png) [@dallmon](https://discuss.elastic.co/u/dallmon)\
**Post date:** [January 17, 2017, 3:38pm UTC](https://discuss.elastic.co/t/err-error-decoding-json/71244/7 "2017-01-17T15:38:58Z")

</div>

1 out of 5 times when the file is read there is a JSON parsing error. When we switch to tail mode, there are no problems parsing the JSON. That may be the solution.

Thanks,  
Dave

---

<div class="post-metadata">

**Author:** ![ruflin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ruflin/32/3116_2.png) [@ruflin](https://discuss.elastic.co/u/ruflin)\
**Post date:** [January 18, 2017, 12:42pm UTC](https://discuss.elastic.co/t/err-error-decoding-json/71244/8 "2017-01-18T12:42:41Z")

</div>

Any chance you could share the log files? How are these logs written?

---

<div class="post-metadata">

**Author:** ![dallmon](https://avatars.discourse-cdn.com/v4/letter/d/c37758/32.png) [@dallmon](https://discuss.elastic.co/u/dallmon)\
**Post date:** [January 18, 2017, 3:18pm UTC](https://discuss.elastic.co/t/err-error-decoding-json/71244/9 "2017-01-18T15:18:28Z")

</div>

The file is one JSON object per line. It is written by the Tanium system so I don't have knowledge of exactly how it is written, but it looks like it deletes the file then creates the new file. The 2MB data files contain data that looks like:

```
{"Computer Name":"LMDV-VIRAJ.","Name":"Adobe Flash Player Install Manager","Version":"24.0.0.186","Uninstallable":"Not Uninstallable","Count":"1","Age":"604800"}
{"Computer Name":"LMCM-JYDAV.","Name":"Adobe Flash Player Install Manager","Version":"24.0.0.186","Uninstallable":"Not Uninstallable","Count":"1","Age":"604800"}
{"Computer Name":"LMCP-AXSIMPSON.","Name":"Adobe Flash Player Install Manager","Version":"23.0.0.205","Uninstallable":"Not Uninstallable","Count":"1","Age":"604800"}

```

There are no parsing errors when the file is tailed rather than replaced, but tailing introduces a whole new set of maintenance issues I would rather avoid.

Thanks,  
Dave

---

<div class="post-metadata">

**Author:** ![ruflin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ruflin/32/3116_2.png) [@ruflin](https://discuss.elastic.co/u/ruflin)\
**Post date:** [January 23, 2017, 10:40am UTC](https://discuss.elastic.co/t/err-error-decoding-json/71244/10 "2017-01-23T10:40:22Z")

</div>

I somehow have the suspicion that it could be related to how the file is written. Instead of tailing, could you rotate the file? I somehow suspect that the file is truncated in the middle of reading. If the file would be replaced, filebeat would probably keep it open. Is it a new file or is the same file reused?

---

<div class="post-metadata">

**Author:** ![dallmon](https://avatars.discourse-cdn.com/v4/letter/d/c37758/32.png) [@dallmon](https://discuss.elastic.co/u/dallmon)\
**Post date:** [January 23, 2017, 3:29pm UTC](https://discuss.elastic.co/t/err-error-decoding-json/71244/11 "2017-01-23T15:29:33Z")

</div>

New file same name. I believe, only because I've seen it happen in Explorer, that the file is deleted then rewritten.

---

<div class="post-metadata">

**Author:** ![ruflin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ruflin/32/3116_2.png) [@ruflin](https://discuss.elastic.co/u/ruflin)\
**Post date:** [January 25, 2017, 9:35am UTC](https://discuss.elastic.co/t/err-error-decoding-json/71244/12 "2017-01-25T09:35:06Z")

</div>

Hm, if it is a new file with a new inode then this would not support my previous theory. Because filebeat will keep the old file open until it finished reading. Also as you are on Windows I would potentially expect filebeat to kind of block the creation of the new file with the same name before the old one is completely removed. Can you verify that it is a new file and not a truncated one?

---

<div class="post-metadata">

**Author:** ![dallmon](https://avatars.discourse-cdn.com/v4/letter/d/c37758/32.png) [@dallmon](https://discuss.elastic.co/u/dallmon)\
**Post date:** [January 25, 2017, 12:52pm UTC](https://discuss.elastic.co/t/err-error-decoding-json/71244/13 "2017-01-25T12:52:18Z")

</div>

I can't verify that it is a new file. The vendor says it is a known issue and they have a fix that will allow it to work with Filebeat. It will be available Thursday. I'll see what happens then and update this thread. I'll try to find out exactly what they changed.

---

<div class="post-metadata">

**Author:** ![ruflin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ruflin/32/3116_2.png) [@ruflin](https://discuss.elastic.co/u/ruflin)\
**Post date:** [January 26, 2017, 12:21pm UTC](https://discuss.elastic.co/t/err-error-decoding-json/71244/14 "2017-01-26T12:21:02Z")

</div>

Interesting. Can I ask who the vendor is? Keep me posted.

---

<div class="post-metadata">

**Author:** ![dallmon](https://avatars.discourse-cdn.com/v4/letter/d/c37758/32.png) [@dallmon](https://discuss.elastic.co/u/dallmon)\
**Post date:** [January 26, 2017, 1:54pm UTC](https://discuss.elastic.co/t/err-error-decoding-json/71244/15 "2017-01-26T13:54:30Z")

</div>

The vendor is Tanium.

---

<div class="post-metadata">

**Author:** ![dallmon](https://avatars.discourse-cdn.com/v4/letter/d/c37758/32.png) [@dallmon](https://discuss.elastic.co/u/dallmon)\
**Post date:** [February 22, 2017, 1:54pm UTC](https://discuss.elastic.co/t/err-error-decoding-json/71244/16 "2017-02-22T13:54:52Z")

</div>

The solution:

Upgrade to 5.2.1 Filebeat  
configuration:  
close\_eof: true  
ignore\_older: 60s  
clean\_inactive: 120s

In two instances I had to change the times to 90 and 125 respectively.

Thanks all for your help.  
Dave

---

<div class="post-metadata">

**Author:** ![ruflin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ruflin/32/3116_2.png) [@ruflin](https://discuss.elastic.co/u/ruflin)\
**Post date:** [February 24, 2017, 9:57am UTC](https://discuss.elastic.co/t/err-error-decoding-json/71244/17 "2017-02-24T09:57:33Z")

</div>

Glad to hear you got it working. Did also Tanium change something on their side?

---

<div class="post-metadata">

**Author:** ![dallmon](https://avatars.discourse-cdn.com/v4/letter/d/c37758/32.png) [@dallmon](https://discuss.elastic.co/u/dallmon)\
**Post date:** [February 24, 2017, 2:09pm UTC](https://discuss.elastic.co/t/err-error-decoding-json/71244/18 "2017-02-24T14:09:00Z")

</div>

Tanium changed something, but by itself their change made no difference at all in the behavior.

Thanks,  
Dave

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 24, 2017, 2:09pm UTC](https://discuss.elastic.co/t/err-error-decoding-json/71244/19 "2017-03-24T14:09:00Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
