# Filebeat sends garbled messages \\u0000

**URL:** <https://discuss.elastic.co/t/filebeat-sends-garbled-messages-u0000/68871>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [December 13, 2016, 12:58pm UTC](https://discuss.elastic.co/t/filebeat-sends-garbled-messages-u0000/68871 "2016-12-13T12:58:03Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![Alexik](https://avatars.discourse-cdn.com/v4/letter/a/ecb155/32.png) [@Alexik](https://discuss.elastic.co/u/Alexik)\
**Post date:** [December 13, 2016, 12:58pm UTC](https://discuss.elastic.co/t/filebeat-sends-garbled-messages-u0000/68871/1 "2016-12-13T12:58:03Z")

</div>

Filebeat sends garbled messages \u0000

Hi guys,

I'm having problem with Filebeat. From time to time I'm receiving an event which looks like this:

> {  
> "\_index": "uat1-access-ws",  
> "\_type": "log",  
> "\_id": "AVj4Nau7dy5nH\_giebKm",  
> "\_score": null,  
> "\_source": {  
> "duration": null,  
> "target\_index": "ws",  
> "@timestamp": "2016-12-13T12:43:32.314Z",  
> "offset": 5226593,  
> "@version": "1",  
> "input\_type": "log",  
> "beat": {  
> "hostname": "xxxxx",  
> "name": "xxxxx",  
> "version": "5.1.1"  
> },  
> "host": "xxxxx",  
> "source": "xxxxx/ws\_access.log",  
> "message": "\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\_91" CT="text/xml" CE="-" PID="\_ib-20161213134330-682154" WS="GetAddressSuggestions"",  
> "type": "log",  
> "tags": [  
> "beats\_input\_codec\_plain\_applied",  
> "\_grokparsefailure"  
> ]

In Filebeat(5.1.1) config there is nothing fancy. I have tried to use charset utf-8/us-ascii(it's used in our logfiles) but no change. I've located particular events in logfiles and it looks exactly same as events above/belove in whole logfile.

Any idea what to do with this ?

Thanks in advance

---

<div class="post-metadata">

**Author:** ![steffens](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/steffens/32/79630_2.png) [@steffens](https://discuss.elastic.co/u/steffens)\
**Post date:** [December 13, 2016, 2:32pm UTC](https://discuss.elastic.co/t/filebeat-sends-garbled-messages-u0000/68871/2 "2016-12-13T14:32:37Z")

</div>

Are you using a network share? I've seen this happening in case of some network/output buffering writting the second part before the first part being buffered. In this case the OS will fill up the missing write with zeros.

The `\u0000` is not 'garbage', but a buffer full of bytes of value `0`. With zero being no readable ASCII-character, the `0` will be encoded as `\u0000`.

---

<div class="post-metadata">

**Author:** ![Alexik](https://avatars.discourse-cdn.com/v4/letter/a/ecb155/32.png) [@Alexik](https://discuss.elastic.co/u/Alexik)\
**Post date:** [December 13, 2016, 3:23pm UTC](https://discuss.elastic.co/t/filebeat-sends-garbled-messages-u0000/68871/3 "2016-12-13T15:23:59Z")

</div>

Thanks for your reply.  
Filebeat runs on server with logs and send them via beat protocol to listening logstash on particular port. Quite normal scenario.  
So I think I will try to dig deeper in network stack and see what I can find. I will try to keep this threat up-to-date.

---

<div class="post-metadata">

**Author:** ![ruflin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ruflin/32/3116_2.png) [@ruflin](https://discuss.elastic.co/u/ruflin)\
**Post date:** [December 14, 2016, 8:40am UTC](https://discuss.elastic.co/t/filebeat-sends-garbled-messages-u0000/68871/4 "2016-12-14T08:40:58Z")

</div>

Also have a look at [Filebeat 5.0 with multiline, split event data to two events](https://discuss.elastic.co/t/filebeat-5-0-with-multiline-split-event-data-to-two-events/60380/12) where this \u0000 also showed up.

---

<div class="post-metadata">

**Author:** ![steffens](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/steffens/32/79630_2.png) [@steffens](https://discuss.elastic.co/u/steffens)\
**Post date:** [December 14, 2016, 3:06pm UTC](https://discuss.elastic.co/t/filebeat-sends-garbled-messages-u0000/68871/5 "2016-12-14T15:06:41Z")

</div>

who is producing the logs? Is the disk remote or local?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 11, 2017, 3:06pm UTC](https://discuss.elastic.co/t/filebeat-sends-garbled-messages-u0000/68871/6 "2017-01-11T15:06:50Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
