# 【Filebeat S3 input】JSONファイルの取込について

**URL:** <https://discuss.elastic.co/t/filebeat-s3-input-json/245729>\
**Category:** 日本語による質問・議論はこちら\
**Created:** [August 20, 2020, 8:28am UTC](https://discuss.elastic.co/t/filebeat-s3-input-json/245729 "2020-08-20T08:28:06Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![harue](https://avatars.discourse-cdn.com/v4/letter/h/82dd89/32.png) [@harue](https://discuss.elastic.co/u/harue)\
**Post date:** [August 20, 2020, 8:28am UTC](https://discuss.elastic.co/t/filebeat-s3-input-json/245729/1 "2020-08-20T08:28:06Z")

</div>

お世話になります。

FilebeatのS3 inputを使用し、JSONファイルの取込を検証しています。  
FilebeatのアウトプットはElasticSearchで、ingest node(JSON processor)を使用しindex登録します。

▼filebeat.yml(抜粋)

filebeat.inputs:

- type: s3  
enabled: true  
queue\_url: XXXX  
access\_key\_id: XXXX  
secret\_access\_key: XXXX  
pipeline: "XXXX"  
visibility\_timeout: 600  
**expand\_event\_list\_from\_field: Records**

▼ingest node(JSON processor)

```
  {
    "json": {
      "field": "message",
      "target_field": "json_target"
    }
  }

```

①1つの配列データ

▼jsonデータ

```
{
    "Records": [
       {
            "eventVersion": "1.07",
            "eventTime": "2019-11-14T00:51:00Z",
            "awsRegion": "us-east-1",
            "eventID": "EXAMPLE8-9621-4d00-b913-beca2EXAMPLE"
        },
        {
            "eventVersion": "1.07",
            "eventTime": "2019-11-14T00:52:00Z",
            "awsRegion": "us-east-1",
            "eventID": "EXAMPLEc-28be-486c-8928-49ce6EXAMPLE"
        }
    ]
}

```

▼検証結果  
indexは登録されたが、1番目の要素("eventTime": "2019-11-14T00:51:00Z")のみが登録された

➁ ①のデータに配列でない項目を追加

▼jsonデータ

```
{
   "type": "aaa",
    "id": "aaa--12345",
    "spec_version": "2.0",
   "Records": [
        {
            "eventVersion": "1.07",
            "eventTime": "2019-11-14T00:51:00Z",
            "awsRegion": "us-east-1",
            "eventID": "EXAMPLE8-9621-4d00-b913-beca2EXAMPLE"
        },
        {
            "eventVersion": "1.07",
            "eventTime": "2019-11-14T00:52:00Z",
            "awsRegion": "us-east-1",
            "eventID": "EXAMPLEc-28be-486c-8928-49ce6EXAMPLE"
        }
    ]
}

```

▼検証結果  
filebeatで以下WARNが発生  
`#011WARN#011[s3]#011s3/input.go:529#011Decode json failed for 'aaa/bbb.json', skipping this file`

③複数の配列データ

▼jsonデータ

```
{
    "Records": [
      {
            "eventVersion": "1.07",
            "eventTime": "2019-11-14T00:51:00Z",
            "awsRegion": "us-east-1",
            "eventID": "EXAMPLE8-9621-4d00-b913-beca2EXAMPLE"
        },
      {
            "eventVersion": "1.07",
            "eventTime": "2019-11-14T00:52:00Z",
            "awsRegion": "us-east-1",
            "eventID": "EXAMPLEc-28be-486c-8928-49ce6EXAMPLE"
        }
    ],
     "aaa": [
         {
            "aaa_name": "ccc",
            "bbb_name": "ddd"
         },
         {
            "aaa_name": "ccc",
            "bbb_name": "eee"
         },
         {
            "aaa_name": "ccc",
            "bbb_name": "fff"
         }
   ]

```

▼検証結果  
indexは登録されたが、1番目の要素("eventTime": "2019-11-14T00:51:00Z")のみが登録された(①と同様)

▼ご質問  
・①③に関して  
配列は"expand\_event\_list\_from\_field"で指定した1番目の要素はindex登録されましたが、2番目以降の要素は登録されませんでした。登録するには何を設定すれば良いでしょうか？

また、"expand\_event\_list\_from\_field"の値は複数設定出来ない認識ですが  
複数の配列を指定し、全ての要素をindex登録する方法はありますでしょうか？

・②に関して  
配列でない項目を設定したところ、filebeatでWARNが発生しindex登録されませんでした。  
WARNを発生させない方法はありますでしょうか？

お手数ですが、回答を頂けますと幸いです。  
以上、宜しくお願い致します。

---

<div class="post-metadata">

**Author:** ![harue](https://avatars.discourse-cdn.com/v4/letter/h/82dd89/32.png) [@harue](https://discuss.elastic.co/u/harue)\
**Post date:** [August 26, 2020, 2:21am UTC](https://discuss.elastic.co/t/filebeat-s3-input-json/245729/2 "2020-08-26T02:21:35Z")

</div>

下記を参考にFilebeatをv7.9にバージョンアップし、「 **expand\_event\_list\_from\_field** 」を設定無にしたところ、上記事象は解決しました。

> [@Filebeat s3 cannot parse jsonl file who's content-type is set to application/json](https://discuss.elastic.co/t/filebeat-s3-cannot-parse-jsonl-file-whos-content-type-is-set-to-application-json/239374):
>
> Hello! I was hoping y'all could help me out. The essence of my problem is that the filebeat S3 input plugin cannot process an s3 object who's content-type is application/json AND the object content is a separate json object per line (i.e. jsonl). Processing such an object used to be possible until v7.7.0 when the S3 input plugin started enforcing json parsing if it saw a content-type of application/json: [https://github.com/elastic/beats/blob/5e69e25b920e3d93bec76a09a31da3ab35a55607/x-pack/fileb…](https://github.com/elastic/beats/blob/5e69e25b920e3d93bec76a09a31da3ab35a55607/x-pack/filebeat/input/s3/input.go#L432)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 23, 2020, 2:21am UTC](https://discuss.elastic.co/t/filebeat-s3-input-json/245729/3 "2020-09-23T02:21:52Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
