# Error parsing json but data still thrown to elastic

**URL:** <https://discuss.elastic.co/t/error-parsing-json-but-data-still-thrown-to-elastic/328922>\
**Category:** Logstash\
**Created:** [March 30, 2023, 10:11am UTC](https://discuss.elastic.co/t/error-parsing-json-but-data-still-thrown-to-elastic/328922 "2023-03-30T10:11:46Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![yuswanul](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yuswanul/32/101662_2.png) [@yuswanul](https://discuss.elastic.co/u/yuswanul)\
**Post date:** [March 30, 2023, 10:11am UTC](https://discuss.elastic.co/t/error-parsing-json-but-data-still-thrown-to-elastic/328922/1 "2023-03-30T10:11:46Z")

</div>

Hi there,  
i want to ask about this error. anyone know what this error is trying to tell ?

```auto
exception=>java.lang.ClassCastException: class org.jruby.RubyHash cannot be cast to class org.jruby.RubyIO (org.jruby.RubyHash and org.jruby.RubyIO are in unnamed module of loader 'app'

```

this is my config pipeline related to json filter  
 ![image](https://us1.discourse-cdn.com/elastic/original/3X/b/9/b93fb93b89e641a600913184a4e2e06c963287ca.png)

fyi, i use v 7.13 and my data is like nested json. so it's look like this

```auto
{
    "xxxxxx": "cccc",
    "data" : {
         "sasasas": "eiwqo"
 }
}

```

thanks

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [March 30, 2023, 5:57pm UTC](https://discuss.elastic.co/t/error-parsing-json-but-data-still-thrown-to-elastic/328922/2 "2023-03-30T17:57:42Z")

</div>

It is telling you that your field is not JSON. With this configuration

```
input { generator { count => 1 lines => [''] } }
output { stdout { codec => rubydebug { metadata => false } } }
filter {
    mutate { add_field => { "[data][sasasas]" => "eiwqo" } }
    json { source => "data" target => "data" }
}

```

the json filter will produce this error

> Error parsing json {:source=\>"data", :raw=\>{"sasasas"=\>"eiwqo"}, :exception=\>#\<Java::JavaLang::ClassCastException: class org.jruby.RubyHash cannot be cast to class org.jruby.RubyIO (org.jruby.RubyHash and org.jruby.RubyIO are in unnamed module of loader 'app')\>}

Check what the ":raw" data is in your error message. I think the exception is thrown [here](https://github.com/guyboertje/jrjackson/blob/d789df3ce7b917a5f2b386c75d4298e75c80fbc4/src/main/java/com/jrjackson/JrJacksonBase.java#L138) in JrJackson.

---

<div class="post-metadata">

**Author:** ![yuswanul](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yuswanul/32/101662_2.png) [@yuswanul](https://discuss.elastic.co/u/yuswanul)\
**Post date:** [March 30, 2023, 9:10pm UTC](https://discuss.elastic.co/t/error-parsing-json-but-data-still-thrown-to-elastic/328922/3 "2023-03-30T21:10:57Z")

</div>

Not json? Hmmm but i'm quite sure the data is a valid json. I was validated it in some json validation online sites

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [March 31, 2023, 2:02am UTC](https://discuss.elastic.co/t/error-parsing-json-but-data-still-thrown-to-elastic/328922/4 "2023-03-31T02:02:17Z")

</div>

The exception message includes the data that is expected to be JSON. What does that message show?

---

<div class="post-metadata">

**Author:** ![yuswanul](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yuswanul/32/101662_2.png) [@yuswanul](https://discuss.elastic.co/u/yuswanul)\
**Post date:** [March 31, 2023, 3:52am UTC](https://discuss.elastic.co/t/error-parsing-json-but-data-still-thrown-to-elastic/328922/5 "2023-03-31T03:52:43Z")

</div>

it says "Error parsing json source =\> "data" ". i can't show you the full log because it contains sensitive data. the error line is just both of this

> Error parsing json {:source=\>"data"

> :exception=\>java.lang.ClassCastException: class org.jruby.RubyHash cannot be cast to class org.jruby.RubyIO (org.jruby.RubyHash and org.jruby.RubyIO are in unnamed module of loader 'app'

but strangely, the raw data on field _data_ are still parsed. all of these fields come from _data_

![image](https://us1.discourse-cdn.com/elastic/original/3X/3/a/3a8161b0f009aff7d4b213ebde20b1757dfbefbf.png)

---

<div class="post-metadata">

**Author:** ![yuswanul](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yuswanul/32/101662_2.png) [@yuswanul](https://discuss.elastic.co/u/yuswanul)\
**Post date:** [March 31, 2023, 4:03am UTC](https://discuss.elastic.co/t/error-parsing-json-but-data-still-thrown-to-elastic/328922/6 "2023-03-31T04:03:40Z")

</div>

so it's start from grok pattern. in original raw data, it look like this  
(some other data in log) responseBody=[{"responsecode":"00","data": { "name": "xxx"}}]

and in grok pattern i made like this  
`%{TIMESTAMP}.......(some other pattern) ResponseBody=\[%GREEDYDATA:responseBody}\]`

so it resulting a field named responseBody and the value will look like this  
{"xxxxxx":"xxx","data":{"xxx","dsda":"xxx"}}

it should be a valid json right?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 28, 2023, 4:04am UTC](https://discuss.elastic.co/t/error-parsing-json-but-data-still-thrown-to-elastic/328922/7 "2023-04-28T04:04:24Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
