# Filebeat not parsing json in messages

**URL:** <https://discuss.elastic.co/t/filebeat-not-parsing-json-in-messages/130230>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [May 2, 2018, 10:18am UTC](https://discuss.elastic.co/t/filebeat-not-parsing-json-in-messages/130230 "2018-05-02T10:18:14Z")\
**Posts on this page:** 11\
**Page:** 1

<div class="post-metadata">

**Author:** ![utsav2307](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/utsav2307/32/30710_2.png) [@utsav2307](https://discuss.elastic.co/u/utsav2307)\
**Post date:** [May 2, 2018, 10:18am UTC](https://discuss.elastic.co/t/filebeat-not-parsing-json-in-messages/130230/1 "2018-05-02T10:18:14Z")

</div>

I have deployed filebeat as a daemonset in Kubernetes for collecting logs and below is my filebeat configuration:

```
 - type: log
       paths:
         - /var/lib/docker/containers/*/*.log
       multiline.pattern: "^[[:space:]]+(at|\\.{3})\\b|^Caused by:|^[[:space:]]"
       multiline.negate: false
       multiline.match: after
       json.message_key: log
       json.keys_under_root: true
       processors:
         - add_kubernetes_metadata:
             in_cluster: true
             namespace: ${POD_NAMESPACE}
         - decode_json_fields:
             fields: ["request","response"]

```

My logs look like this:

> {"uri":"x","request":{...}, "response":{...},"data":"abcd"}  
> {"uri":"y","request":{...}, "response":{...},"data":"xyz"}

---

<div class="post-metadata">

**Author:** ![steffens](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/steffens/32/79630_2.png) [@steffens](https://discuss.elastic.co/u/steffens)\
**Post date:** [May 2, 2018, 3:50pm UTC](https://discuss.elastic.co/t/filebeat-not-parsing-json-in-messages/130230/2 "2018-05-02T15:50:10Z")

</div>

Can you post your complete filebeat configuration? The indentation looks somewhat off in your code snippet.

Why do you have multiline and json in one type?

It's the top level JSON not be parsed or the embedded 'request', 'response' fields?

---

<div class="post-metadata">

**Author:** ![utsav2307](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/utsav2307/32/30710_2.png) [@utsav2307](https://discuss.elastic.co/u/utsav2307)\
**Post date:** [May 2, 2018, 6:45pm UTC](https://discuss.elastic.co/t/filebeat-not-parsing-json-in-messages/130230/3 "2018-05-02T18:45:13Z")

</div>

I have downloaded the official manifest file provided by elastic and made changes in prospector file:

```
 apiVersion: v1
 kind: ConfigMap
 metadata:
   name: filebeat-prospectors
   namespace: kube-system
   labels:
     k8s-app: filebeat
     kubernetes.io/cluster-service: "true"
 data:
   kubernetes.yml: |-
     - type: log
       paths:
         - /var/lib/docker/containers/*/*.log
       multiline.pattern: "^[[:space:]]+(at|\\.{3})\\b|^Caused by:|^[[:space:]]"
       multiline.negate: false
       multiline.match: after
       json.message_key: log
       json.keys_under_root: true
       processors:
         - add_kubernetes_metadata:
             in_cluster: true
             namespace: ${POD_NAMESPACE}
         - drop_event:
             when:
               or:
                 - equals:
                     kubernetes.namespace: "kube-system"
                 - equals:
                     stream: "stderr"

```

This is my complete configmap manifest. I have added multiline for catching excptions. Do these need to be in different type? If yes then how coz the log files path will remain the same, wont that be a problem?

And, nothing is getting parsed as of now. The whole json is coming as it is in elasticsearch inside a field "log".

---

<div class="post-metadata">

**Author:** ![darkmoon](https://avatars.discourse-cdn.com/v4/letter/d/ecd19e/32.png) [@darkmoon](https://discuss.elastic.co/u/darkmoon)\
**Post date:** [May 2, 2018, 7:13pm UTC](https://discuss.elastic.co/t/filebeat-not-parsing-json-in-messages/130230/4 "2018-05-02T19:13:23Z")

</div>

Ok. Do you have matching config in logstash (or elastic) to catch those documents and interpret the contents of the log field as json and break out the fields?

---

<div class="post-metadata">

**Author:** ![utsav2307](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/utsav2307/32/30710_2.png) [@utsav2307](https://discuss.elastic.co/u/utsav2307)\
**Post date:** [May 3, 2018, 4:22am UTC](https://discuss.elastic.co/t/filebeat-not-parsing-json-in-messages/130230/5 "2018-05-03T04:22:33Z")

</div>

Why logstash? From my understanding of the docs, i just need to deploy filebeat to my kubernetes cluster as a daemon set, and if the logs have json in separate lines, filebeat will automatically be able to parse it and send to elasticsearch with respective fields.

Here is a snapshot from the docs:

 ![12%20AM](https://us1.discourse-cdn.com/elastic/original/3X/b/7/b7a0f5687ada942dd7cc10d42f21de94af4db16a.png)

---

<div class="post-metadata">

**Author:** ![steffens](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/steffens/32/79630_2.png) [@steffens](https://discuss.elastic.co/u/steffens)\
**Post date:** [May 3, 2018, 11:40am UTC](https://discuss.elastic.co/t/filebeat-not-parsing-json-in-messages/130230/6 "2018-05-03T11:40:17Z")

</div>

Oh, I see. You try to forward the container logs. As docker can be somewhat painful, especially regarding multiline and when to do JSON parsing. For this use case filebeat introduced the `docker` prospector type.

e.g.

```auto
- type: docker
  containers:
    ids: "*"
    path: /var/lib/docker/containers
    stream: all
  multiline:
    pattern: ...
    ...
  processors:
    ...

```

The docker log type parses the docker JSON before executing any other transformation/parsing. See [containers](https://www.elastic.co/guide/en/beats/filebeat/current/configuration-filebeat-options.html#config-containers) in docs.

Maybe you want to start step by step. First be able to publish logs. Then add multiline for stack traces. Then add `drop_event`.

---

<div class="post-metadata">

**Author:** ![darkmoon](https://avatars.discourse-cdn.com/v4/letter/d/ecd19e/32.png) [@darkmoon](https://discuss.elastic.co/u/darkmoon)\
**Post date:** [May 3, 2018, 1:37pm UTC](https://discuss.elastic.co/t/filebeat-not-parsing-json-in-messages/130230/7 "2018-05-03T13:37:37Z")

</div>

Yes, beats 6.x has some built in parsing. If it works for you, great, but  
unless you only have one data source (for you, docker instances), it won't  
integrate with anything else.

I'm all for processing the data as close to the source as possible, but I  
haven't seen a way to configure that processing. Also, in my case, I don't  
control the endpoints and have no way of updating that code, so I do  
everything in logstash.

Also, the module filters have really bad field names.

---

<div class="post-metadata">

**Author:** ![utsav2307](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/utsav2307/32/30710_2.png) [@utsav2307](https://discuss.elastic.co/u/utsav2307)\
**Post date:** [May 4, 2018, 4:50am UTC](https://discuss.elastic.co/t/filebeat-not-parsing-json-in-messages/130230/8 "2018-05-04T04:50:43Z")

</div>

Ok let me try this out. I will get back to you on this.

---

<div class="post-metadata">

**Author:** ![utsav2307](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/utsav2307/32/30710_2.png) [@utsav2307](https://discuss.elastic.co/u/utsav2307)\
**Post date:** [May 4, 2018, 6:33am UTC](https://discuss.elastic.co/t/filebeat-not-parsing-json-in-messages/130230/9 "2018-05-04T06:33:16Z")

</div>

Hey, i did two things:

1. Upgraded to beats 6.2.4
2. Used docker type for prospector and added the following line:  
json.keys\_under\_root: true

Works now. Thanks for the help, and quick responses 🙂

---

<div class="post-metadata">

**Author:** ![utsav2307](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/utsav2307/32/30710_2.png) [@utsav2307](https://discuss.elastic.co/u/utsav2307)\
**Post date:** [May 8, 2018, 7:33am UTC](https://discuss.elastic.co/t/filebeat-not-parsing-json-in-messages/130230/10 "2018-05-08T07:33:44Z")

</div>

Hi,

So, my orginal issue was solved, but I can see that CPU consumption for filebeat spikes extremely high. Is this a known issue? or it is a problem in version 6.2.4?

 ![31%20PM](https://us1.discourse-cdn.com/elastic/original/3X/2/b/2b327327bcde03cb9f26baacadb3ca9326a6d8a0.png)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 5, 2018, 7:35am UTC](https://discuss.elastic.co/t/filebeat-not-parsing-json-in-messages/130230/11 "2018-06-05T07:35:22Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
