# Error: "type" : "json\_parse\_exception"

**URL:** <https://discuss.elastic.co/t/error-type-json-parse-exception/134395>\
**Category:** Kibana\
**Created:** [June 4, 2018, 9:29am UTC](https://discuss.elastic.co/t/error-type-json-parse-exception/134395 "2018-06-04T09:29:49Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![nasos](https://avatars.discourse-cdn.com/v4/letter/n/7bcc69/32.png) [@nasos](https://discuss.elastic.co/u/nasos)\
**Post date:** [June 4, 2018, 9:29am UTC](https://discuss.elastic.co/t/error-type-json-parse-exception/134395/1 "2018-06-04T09:29:50Z")

</div>

Hi all,

I am new in Elastic and I want to visualize data in Kibana from csv file.

the Data (kibana\_test1.csv) are in the following form:

user\_id,item\_id,event\_type,user\_location,user\_favorite\_brand,item\_brand  
278673,234,purchase,City,Nokia,Samsung  
278674,235,purchase,City,Nokia,Samsung  
278675,236,purchase,City,Nokia,Samsung  
278676,237,purchase,City,Nokia,Samsung  
278677,238,purchase,City,Nokia,Samsung  
278678,239,purchase,City,Nokia,Samsung  
278679,240,purchase,City,Nokia,Samsung  
278680,241,purchase,City,Nokia,Samsung  
278681,242,purchase,City,Nokia,Samsung  
278682,243,purchase,City,Nokia,Samsung  
278683,244,purchase,City,Nokia,Samsung  
278684,245,purchase,City,Nokia,Samsung

My logstash configuration file ( logstash-simple.conf) is:

input {  
file {  
path =\> "/home/nasos/Documents/kibana\_test1.csv"  
start\_position =\> "beginning"}  
}

filter {

csv {  
separator =\> ","  
columns =\> ["user\_id","item\_id","event\_type","user\_location","user\_favorite\_brand","item\_brand"]  
}  
}

output {  
elasticsearch {  
action =\> "index"  
hosts =\> ["localhost:9200"]  
index =\> "data"  
user =\> "elastic"  
password =\> "My\_password"  
}  
stdout { codec =\> rubydebug }  
}

I have put the password (of elastic) that is generated from the command:  
bin/x-pack/setup-passwords auto

I have created an index in Kibana- Dev Tools:

PUT /kibana\_test1  
{  
"mappings": {  
"doc": {  
"properties": {  
"user\_id": {"type": "integer"},  
"item\_id": {"type": "integer"},  
"event\_type": {"type": "keyword"},  
"user\_location": {"type": "keyword"},  
"user\_favorite\_brand": {"type": "keyword"},  
"item\_brand": {"type": "keyword"}  
}  
}  
}  
}

and I used

sudo ./logstash -f logstash-simple.conf --path.settings=/etc/logstash

and I got the following message:

Sending Logstash's logs to /var/log/logstash which is now configured via log4j2.properties

It seem that it works fine so far. Isn't it?

when I used the Elasticsearch bulk API to load the data sets;

curl -H 'Content-Type: application/x-ndjson' -XPOST -u elastic 'localhost:9200/kibana\_test1/doc/\_bulk?pretty' --data-binary @kibana\_test1.csv

I got the following error:

{  
"error" : {  
"root\_cause" : [  
{  
"type" : "json\_parse\_exception",  
"reason" : "Unrecognized token 'user\_id': was expecting ('true', 'false' or 'null')\n at [Source: org.elasticsearch.transport.netty4.ByteBufStreamInput@4df98756; line: 1, column: 9]"  
}  
],  
"type" : "json\_parse\_exception",  
"reason" : "Unrecognized token 'user\_id': was expecting ('true', 'false' or 'null')\n at [Source: org.elasticsearch.transport.netty4.ByteBufStreamInput@4df98756; line: 1, column: 9]"  
},  
"status" : 500  
}

Could you please help?  
Thx

---

<div class="post-metadata">

**Author:** ![bhavyarm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bhavyarm/32/22392_2.png) [@bhavyarm](https://discuss.elastic.co/u/bhavyarm)\
**Post date:** [June 4, 2018, 7:44pm UTC](https://discuss.elastic.co/t/error-type-json-parse-exception/134395/2 "2018-06-04T19:44:54Z")

</div>

Hi,

Couple of things are happening here:

1. This command works only for uploading a .json file and you are using to load .csv file:

```auto
curl -H 'Content-Type: application/x-ndjson' -XPOST -u elastic 'localhost:9200/kibana_test1/doc/_bulk?pretty' --data-binary @kibana_test1.csv

```

1. You can ingest data into elasticsearch either using logstash or doing the bulk upload as the above command. You don't need to do both. If your logstash config is successful then that should be loading your data into Elasticsearch.  
Can you check [http://localhost:9200/\_cat/indices](http://localhost:9200/_cat/indices) (you have to use your es ip) and then check if you have the data? I also think you can just do a bulk upload of your data by making sure your file is in .json format.

Thanks,  
Bhavya

---

<div class="post-metadata">

**Author:** ![nasos](https://avatars.discourse-cdn.com/v4/letter/n/7bcc69/32.png) [@nasos](https://discuss.elastic.co/u/nasos)\
**Post date:** [June 5, 2018, 8:11am UTC](https://discuss.elastic.co/t/error-type-json-parse-exception/134395/3 "2018-06-05T08:11:23Z")

</div>

> [@nasos](#):
>
> sudo ./logstash -f logstash-simple.conf --path.settings=/etc/logstash

Hello Bhavya,

thank you for your prompt response. I have some questions regarding the above comments:

1. Shall I use Json-p format to load data using elasticsearch bulk API (curl -H .....)?
2. Also, I used logstash to ingest data to elasticsearch. I see it on indices list ( "cat/indices")

> yellow open kibana\_test1 ySFDAm3UR0ymEyUXxEaBRQ 5 1 0 0 1.2kb 1.2kb

but I cannot see it on "Set Up Index Patterns" in Kibana. Shall I set up a mapping for the data in csv file?

Please find my logstash-plain.log above:

```
[2018-06-05T10:48:46,353][INFO][logstash.outputs.elasticsearch] ES Output version determined {:es_version=>6}
[2018-06-05T10:48:46,353][WARN][logstash.outputs.elasticsearch] Detected a 6.x and above cluster: the `type` event field won't be used to determine the document _type {:es_version=>6}
[2018-06-05T10:48:46,354][INFO][logstash.outputs.elasticsearch] Using mapping template from {:path=>nil}
[2018-06-05T10:48:46,355][INFO][logstash.outputs.elasticsearch] Attempting to install template {:manage_template=>{"template"=>"logstash-*", "version"=>60001, "settings"=>{"index.refresh_interval"=>"5s"}, "map$
[2018-06-05T10:48:46,357][INFO][logstash.outputs.elasticsearch] New Elasticsearch output {:class=>"LogStash::Outputs::ElasticSearch", :hosts=>["//localhost:9200"]}
[2018-06-05T10:48:46,386][ERROR][logstash.pipeline] Error registering plugin {:pipeline_id=>"main", :plugin=>"#<LogStash::FilterDelegator:0x77ebf0fb @metric_events_out=org.jruby.proxy.org.logstash.instr$
[2018-06-05T10:48:46,387][ERROR][logstash.pipeline] Pipeline aborted due to error {:pipeline_id=>"main", :exception=>#<Grok::PatternError: pattern %{COSMOBILECOMMON} not defined>, :backtrace=>["/usr/sha$
[2018-06-05T10:48:46,390][ERROR][logstash.agent] Failed to execute action {:id=>:main, :action_type=>LogStash::ConvergeResult::FailedAction, :message=>"Could not execute action: LogStash::PipelineAct$
[2018-06-05T10:48:46,396][INFO][logstash.inputs.metrics] Monitoring License OK
[2018-06-05T10:48:47,728][INFO][logstash.pipeline] Pipeline has terminated {:pipeline_id=>".monitoring-logstash", :thread=>"#<Thread:0x41591aa@/usr/share/logstash/logstash-core/lib/logstash/pipeline.rb$

```

Thank you.

BR,  
Nasos

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 3, 2018, 8:11am UTC](https://discuss.elastic.co/t/error-type-json-parse-exception/134395/4 "2018-07-03T08:11:33Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
