# Filebeat crashing on JSON decoder and multiline together specifying a message\_key value error

**URL:** <https://discuss.elastic.co/t/filebeat-crashing-on-json-decoder-and-multiline-together-specifying-a-message-key-value-error/176132>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [April 10, 2019, 4:07am UTC](https://discuss.elastic.co/t/filebeat-crashing-on-json-decoder-and-multiline-together-specifying-a-message-key-value-error/176132 "2019-04-10T04:07:02Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![Tharun](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tharun/32/60607_2.png) [@Tharun](https://discuss.elastic.co/u/Tharun)\
**Post date:** [April 10, 2019, 4:07am UTC](https://discuss.elastic.co/t/filebeat-crashing-on-json-decoder-and-multiline-together-specifying-a-message-key-value-error/176132/1 "2019-04-10T04:07:02Z")

</div>

Filebeat Version: 6.5.4 and Logstash Version: 6.5.4

Hello, here is the Filebeat configuration I'm using

> ```
> - type: log
> paths:
> - /var/lib/docker/containers/*/*.log
> symlinks: true
> multiline:
> pattern: ^[[:space:]]
> negate: false
> match: after
> ignore_older: 1h 
> clean_inactive: 65m
> close_inactive: 5m
> scan_frequency: 20s
> json.message_key: log
> json.keys_under_root: true
> tail_files: true
> fields:
> clustername: ${Clustername}
> processors:
> - add_kubernetes_metadata:
> in_cluster: true
> - drop_event:
> when:
> equals:
> kubernetes.container.name: "filebeat"
> 
> ```

Giving json message key as "log" is showing up a failure on logstash with error:

> Could not index event to Elasticsearch. {:status=\>400, :action=\>["index", {:\_id=\>nil, :\_index=\>"logstash-2019.04.10", :\_type=\>"doc", :routing=\>nil}, #\<LogStash::Event:0x20018e3e\>], :response=\>{"index"=\>{"\_index"=\>"logstash-2019.04.10", "\_type"=\>"doc", "\_id"=\>"uKwYBWoBV9VbumyOAOsx", "status"=\>400, "error"=\>{"type"=\>"mapper\_parsing\_exception", "reason"=\>"failed to parse field [log] of type [text]", "caused\_by"=\>{"type"=\>"illegal\_state\_exception", "reason"=\>"Can't get text on a START\_OBJECT at 1:527"}}}}}

So, to overcome this I tried commenting json.message\_key: log which was crashing filebeat.

> Exiting: When using the JSON decoder and multiline together, you need to specify a message\_key value accessing '0' (source:'/usr/share/filebeat/inputs.d/kubernetes.yml')

For a workaround to this, I just tried putting some random name in message key which fixed the crashing of filebeat however every log line is being inserted with that message key field and value is empty. In kibana, I'm seeing the default field "log" which is actually showing up the log lines, May I know the reason that is causing it and how to overcome this. Am I doing anything wrong?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 8, 2019, 4:07am UTC](https://discuss.elastic.co/t/filebeat-crashing-on-json-decoder-and-multiline-together-specifying-a-message-key-value-error/176132/2 "2019-05-08T04:07:15Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
