# Error json parsing opensearch logs with logstash

**URL:** <https://discuss.elastic.co/t/error-json-parsing-opensearch-logs-with-logstash/345398>\
**Category:** Logstash\
**Created:** [October 19, 2023, 1:54pm UTC](https://discuss.elastic.co/t/error-json-parsing-opensearch-logs-with-logstash/345398 "2023-10-19T13:54:10Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Xhar](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/xhar/32/126590_2.png) [@Xhar](https://discuss.elastic.co/u/Xhar)\
**Post date:** [October 19, 2023, 1:54pm UTC](https://discuss.elastic.co/t/error-json-parsing-opensearch-logs-with-logstash/345398/1 "2023-10-19T13:54:11Z")

</div>

Hello, i'm trying to parse suricata, logstash and opensearch logs with dictionary filter, here's part of my config

```auto
input {
  file {
    path => "/opt/logs/opensearchTest/opensearch_server.json"
    codec => "json"
    type => "opensearch_log"
  }
}
filter {
  if [type] == "opensearch_log" {
    if [level] == "ERROR" {
      mutate {
        add_field => { "translated_values" => " **********" }
      }
    } else {
      translate {
        source => "message"
        target => "translated_field"
        dictionary => {
          " *******" => "*******"
          " **********" => "****"
          " *********" => "**********"
        }
        fallback => ""
      }

      mutate {
        add_field => { "translated_values" => "%{translated_field}" }
        remove_field => ["message", "translated_field"]
      }
    }
  }
}
output {
 else if [type] == "logstash_log" or [type] == "suricata_log" or [type] == "opensearch_log" {
    if [translated_values] {
      http {
        http_method => "post"
        url => "http:// ************ /"
        format => "form"

        headers => {
          "Authorization" => "Token *********"
          "Content-Type" => "application/json"
        }

        mapping => ["action_result", "True", "action_type", "add_audit", "comment", "%{translated_values}"]
      }
    }
  } 
}

```

and i've got the same pattern for logstash and suricata, that perfectly works, but with opensearch logs i receive this error:

```auto
JSON parse error, original data now in message field {:message=>"incompatible json object type=java.lang.String , only hash map or arrays are supported", :exception=>LogStash::Json::ParserError, :data=>"\"type\": \"server\", \"timestamp\": \"2023-10-19T00:00:00,834+03:00\", \"level\": \"INFO\", \"component\": \"o.o.c.m.MetadataUpdateSettingsService\", \"cluster.name\": \"opensearch\", \"node.name\": \"astra-altar-wazuh\", \"message\": \"updating number_of_replicas to [0] for indices [wazuh-monitoring-2023.42w]\", \"cluster.uuid\": \"7wgF5XaTRuqjNBptO52m-g\", \"node.id\": \"JBRbEq1VTey6vZjMxcWPfQ\"

```

here's example of opensearch logs:

```auto
{"type": "server", "timestamp": "2023-10-19T11:33:04,042+03:00", "level": "INFO", "component": "o.o.p.PluginsService", "cluster.name": "opensearch", "node.name": "astra-altar-wazuh", "message": "PluginService:onIndexModule index:[wazuh-monitoring-2023.37w/mbsyMgM7STWGQ6zkR6FdHw]", "cluster.uuid": "7wgF5XaTRuqjNBptO52m-g", "node.id": "JBRbEq1VTey6vZjMxcWPfQ" }
{"type": "server", "timestamp": "2023-10-19T11:33:04,045+03:00", "level": "INFO", "component": "o.o.p.PluginsService", "cluster.name": "opensearch", "node.name": "astra-altar-wazuh", "message": "PluginService:onIndexModule index:[.kibana_1/0XetZAI8QqSmtSAOuOrsxg]", "cluster.uuid": "7wgF5XaTRuqjNBptO52m-g", "node.id": "JBRbEq1VTey6vZjMxcWPfQ" }
{"type": "server", "timestamp": "2023-10-19T11:33:04,123+03:00", "level": "INFO", "component": "o.o.c.r.a.AllocationService", "cluster.name": "opensearch", "node.name": "astra-altar-wazuh", "message": "Cluster health status changed from [RED] to [YELLOW] (reason: [shards started [[.kibana_1][0]]]).", "cluster.uuid": "7wgF5XaTRuqjNBptO52m-g", "node.id": "JBRbEq1VTey6vZjMxcWPfQ" }
{"type": "server", "timestamp": "2023-10-19T11:34:25,979+03:00", "level": "INFO", "component": "o.o.n.Node", "cluster.name": "opensearch", "node.name": "astra-altar-wazuh", "message": "stopping ...", "cluster.uuid": "7wgF5XaTRuqjNBptO52m-g", "node.id": "JBRbEq1VTey6vZjMxcWPfQ" }

```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 19, 2023, 1:54pm UTC](https://discuss.elastic.co/t/error-json-parsing-opensearch-logs-with-logstash/345398/2 "2023-10-19T13:54:11Z")

</div>

OpenSearch/OpenDistro are AWS run products and differ from the original Elasticsearch and Kibana products that Elastic builds and maintains. You may need to contact them directly for further assistance.

(This is an automated response from your friendly Elastic bot. Please report this post if you have any suggestions or concerns :elasticheart: )

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [October 19, 2023, 3:21pm UTC](https://discuss.elastic.co/t/error-json-parsing-opensearch-logs-with-logstash/345398/3 "2023-10-19T15:21:07Z")

</div>

The message indicates that your log entries are not surrounded by {}

---

<div class="post-metadata">

**Author:** ![Xhar](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/xhar/32/126590_2.png) [@Xhar](https://discuss.elastic.co/u/Xhar)\
**Post date:** [October 20, 2023, 6:44am UTC](https://discuss.elastic.co/t/error-json-parsing-opensearch-logs-with-logstash/345398/4 "2023-10-20T06:44:21Z")

</div>

but as you see they surrounded by {} ☹

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 17, 2023, 6:44am UTC](https://discuss.elastic.co/t/error-json-parsing-opensearch-logs-with-logstash/345398/5 "2023-11-17T06:44:39Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
