# Filebeat 6.4.3 suddenly starts giving Error decoding JSON: json: cannot unmarshal number into Go value of type map\[string\]interface {}

**URL:** <https://discuss.elastic.co/t/filebeat-6-4-3-suddenly-starts-giving-error-decoding-json-json-cannot-unmarshal-number-into-go-value-of-type-map-string-interface/183839>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [June 1, 2019, 9:26pm UTC](https://discuss.elastic.co/t/filebeat-6-4-3-suddenly-starts-giving-error-decoding-json-json-cannot-unmarshal-number-into-go-value-of-type-map-string-interface/183839 "2019-06-01T21:26:58Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![pvi](https://avatars.discourse-cdn.com/v4/letter/p/7c8e57/32.png) [@pvi](https://discuss.elastic.co/u/pvi)\
**Post date:** [June 1, 2019, 9:26pm UTC](https://discuss.elastic.co/t/filebeat-6-4-3-suddenly-starts-giving-error-decoding-json-json-cannot-unmarshal-number-into-go-value-of-type-map-string-interface/183839/1 "2019-06-01T21:26:58Z")

</div>

After rebooting filebeat docker on one of our servers it started giving this error for every log line:

> Error decoding JSON: json: cannot unmarshal number into Go value of type map[string]interface {}

I can't really find what is causing this as all other servers seem to be running fine still. However, I can reproduce the issue locally in a test setup:

Filebeat Dockerfile:

```
FROM docker.elastic.co/beats/filebeat:6.4.3
COPY filebeat.yml /usr/share/filebeat/filebeat.yml
USER root
RUN chown root:filebeat /usr/share/filebeat/filebeat.yml

```

filebeat.yml:

```
filebeat.inputs:
  - type: docker
    #containers.ids: '*'
    containers.ids: ['e5601a3a6a11ee8857cd0edc600515e794e56b28d306fd139618c3060999169d']
    containers.stream: 'all'
    combine_partial: true
    multiline.pattern: '^\d{4}-\d{2}-\d{2}'
    multiline.negate: true
    multiline.match: after
    ignore_older: 24h
    harvester_limit: 0
    json.keys_under_root: true
    json.add_error_key: true
    json.message_key: log

#processors:
# - add_docker_metadata:
# host: "unix:///var/run/docker.sock"

#output.logstash:
# hosts: ["xxx:5044"]

output.console:
  enabled: true
  pretty: true

#xpack.monitoring:
# enabled: true
# elasticsearch:
# hosts: ["xxx:9200"]

```

Log file located at /tmp/filebeat-docker-test/var/lib/docker/containers/e5601a3a6a11ee8857cd0edc600515e794e56b28d306fd139618c3060999169d/e5601a3a6a11ee8857cd0edc600515e794e56b28d306fd139618c3060999169d-json.log:

```
{"log":"2019-06-01T18:58:39.942Z\u0009ERROR\u0009json/json.go:51\u0009Error decoding JSON: json: cannot unmarshal number into Go value of type map[string]interface {}\n","stream":"stderr","time":"2019-06-01T18:58:39.942960262Z"}
{"log":"2019-06-01T18:58:39.942Z\u0009ERROR\u0009json/json.go:51\u0009Error decoding JSON: json: cannot unmarshal number into Go value of type map[string]interface {}\n","stream":"stderr","time":"2019-06-01T18:58:39.942960262Z"}

```

**Build the docker container and run with:** _docker run --mount type=bind,source=/tmp/filebeat-docker-test/var/lib/docker,target=/var/lib/docker filebeat -e -d "_"\*

This post would get too long if I add the output, but the output showed the _Error decoding JSON: json: cannot unmarshal number into Go value of type map[string]interface {}_ error once per log line. And the resulted documents do actually show the log field from the original log json.

I checked there is one JSON object per line. And as mentioned before, filebeat does seem to be running fine on other servers currently. But I can't really see whatever is different there, and am too afraid to restart anything there now..

Am I overlooking anything here?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 29, 2019, 9:27pm UTC](https://discuss.elastic.co/t/filebeat-6-4-3-suddenly-starts-giving-error-decoding-json-json-cannot-unmarshal-number-into-go-value-of-type-map-string-interface/183839/2 "2019-06-29T21:27:00Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
