# Filebeat unicode json parse error

**URL:** <https://discuss.elastic.co/t/filebeat-unicode-json-parse-error/280167>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [August 1, 2021, 11:37pm UTC](https://discuss.elastic.co/t/filebeat-unicode-json-parse-error/280167 "2021-08-01T23:37:10Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![paano](https://avatars.discourse-cdn.com/v4/letter/p/cab0a1/32.png) [@paano](https://discuss.elastic.co/u/paano)\
**Post date:** [August 1, 2021, 11:37pm UTC](https://discuss.elastic.co/t/filebeat-unicode-json-parse-error/280167/1 "2021-08-01T23:37:10Z")

</div>

I have worked worked with json earlier, but this json output is unique, and filebeat throws error as

```auto
Error decoding JSON: invalid character 'u'

elk_filebeat | 2021-08-01T23:33:35.056Z ERROR json/json.go:51 Error decoding JSON: invalid character 'u' looking for beginning of object key string

```

The json file is

```auto
{u'service': [{u'status': {u'started': u'2021-07-04T09:28:31.000Z', u'ldapConnectionState': u'connected', u'connectionCount': 104, u'InitiatorState': u'running', u'State': u'running'}, u'name': u'APPServ'}]}

```

Tried to add the encoding to see if it changes.  
Filebeat config is pretty straight forward

```auto
- type: log
  enabled: true
  paths:
    - /var/log/*.log
  json.keys_under_root: true
  json.add_error_key: true
  encoding: "utf-8"

```

How would i go about this?

---

<div class="post-metadata">

**Author:** ![legoguy1000](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/legoguy1000/32/54301_2.png) [@legoguy1000](https://discuss.elastic.co/u/legoguy1000)\
**Post date:** [August 2, 2021, 2:12am UTC](https://discuss.elastic.co/t/filebeat-unicode-json-parse-error/280167/2 "2021-08-02T02:12:01Z")

</div>

It's complaining about the `u` preceding the text. It's not valid json.

---

<div class="post-metadata">

**Author:** ![paano](https://avatars.discourse-cdn.com/v4/letter/p/cab0a1/32.png) [@paano](https://discuss.elastic.co/u/paano)\
**Post date:** [August 2, 2021, 3:23am UTC](https://discuss.elastic.co/t/filebeat-unicode-json-parse-error/280167/3 "2021-08-02T03:23:03Z")

</div>

is there a way for filebeat to discard the `'u`

---

<div class="post-metadata">

**Author:** ![legoguy1000](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/legoguy1000/32/54301_2.png) [@legoguy1000](https://discuss.elastic.co/u/legoguy1000)\
**Post date:** [August 2, 2021, 3:37am UTC](https://discuss.elastic.co/t/filebeat-unicode-json-parse-error/280167/4 "2021-08-02T03:37:53Z")

</div>

Maybe try to script it using the script processor but besides that, not that I'm tracking.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 30, 2021, 5:38am UTC](https://discuss.elastic.co/t/filebeat-unicode-json-parse-error/280167/5 "2021-08-30T05:38:29Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
