# Fatal level logs are not processing in Logstash

**URL:** <https://discuss.elastic.co/t/fatal-level-logs-are-not-processing-in-logstash/358308>\
**Category:** Logstash\
**Created:** [April 26, 2024, 4:27pm UTC](https://discuss.elastic.co/t/fatal-level-logs-are-not-processing-in-logstash/358308 "2024-04-26T16:27:54Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![ErGeek](https://avatars.discourse-cdn.com/v4/letter/e/e5b9ba/32.png) [@ErGeek](https://discuss.elastic.co/u/ErGeek)\
**Post date:** [April 26, 2024, 4:27pm UTC](https://discuss.elastic.co/t/fatal-level-logs-are-not-processing-in-logstash/358308/1 "2024-04-26T16:27:54Z")

</div>

Hi All,

We have an architecture where the log-flow process starts from Beats -\> AWS MSK (Kafka) -\> Logstash (Self hosted)-\> Elasticsearch -\> Kibana.

But we are facing a challenge where the FATAL level logs are coming till Kafka and not getting filtered from the Logstash when we are using the below filter 🙂  
filter {

```
    json {
            source => "message"

```

}

```
fingerprint {
   source => ["fingerprint", "log"]
   target => "[@metadata][fingerprint]"
   method => "SHA1"
   concatenate_sources => true
}

```

}

But when we remove the filter "json {  
source =\> "message"  
}", we are able to get the logs along with the message field.

Could anyone please suggest on how to get the FATAL logs without making any change in the filter part?

Regards,  
Nalin

---

<div class="post-metadata">

**Author:** ![yago82](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yago82/32/97755_2.png) [@yago82](https://discuss.elastic.co/u/yago82)\
**Post date:** [June 17, 2024, 12:46pm UTC](https://discuss.elastic.co/t/fatal-level-logs-are-not-processing-in-logstash/358308/2 "2024-06-17T12:46:57Z")

</div>

> [@ErGeek](#):
>
> Hi All,
> 
> We have an architecture where the log-flow process starts from Beats -\> AWS MSK (Kafka) -\> Logstash (Self hosted)-\> Elasticsearch -\> Kibana.
> 
> But we are facing a challenge where the FATAL level logs are coming till Kafka and not getting filtered from the Logstash when we are using the below filter 🙂  
> filter {
> 
> ```auto
> json {
> source => "message"
> 
> ```
> 
> }
> 
> ```auto
> fingerprint {
> source => ["fingerprint", "log"]
> target => "[@metadata][fingerprint]"
> method => "SHA1"
> concatenate_sources => true
> }
> 
> ```
> 
> }
> 
> But when we remove the filter "json {  
> source =\> "message"  
> }", we are able to get the logs along with the message field.
> 
> Could anyone please suggest on how to get the FATAL logs without making any change in the filter part?
> 
> Regards,  
> Nalin

Hi,

FATAL log are in JSON format?

Regards
