# Filebeats input json\_lines only processing single entry

**URL:** <https://discuss.elastic.co/t/filebeats-input-json-lines-only-processing-single-entry/153348>\
**Category:** Logstash\
**Created:** [October 22, 2018, 8:41am UTC](https://discuss.elastic.co/t/filebeats-input-json-lines-only-processing-single-entry/153348 "2018-10-22T08:41:49Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Werring](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/werring/32/39402_2.png) [@Werring](https://discuss.elastic.co/u/Werring)\
**Post date:** [October 22, 2018, 8:41am UTC](https://discuss.elastic.co/t/filebeats-input-json-lines-only-processing-single-entry/153348/1 "2018-10-22T08:41:49Z")

</div>

I am just starting with logstash (and the other products of the elastic stack) but im having some issues with trying to set up my sample parser.  
Only the first line of my log is sent to the stdout when using the json\_lines codec.  
When i delete the codec line, all log entries are sent to my stdout (but not parsed as json).

Any suggestion in the right direction would be welcome!

My logstash config:

```
input {
    beats { 
        port => 5044
        codec => json_lines {}
    }
}

output {
    stdout { codec => rubydebug }
}

```

My sample log:

```
{"cocoon":{"name":"Blub","url":"https://blub.example.org/","version":"2.12.1 beta","type":"demo"},"file":{"type":"image/jpeg","extension":"jpg","name":"20180917_201321.jpg","variant":"2000px","filesize":1013002},"download":261320,"date":"2018-08-02T07:22:07.000"}
{"cocoon":{"name":"Team","url":"https://team.example.org/","version":"2.12.1 beta","type":"demo"},"file":{"type":"image/gif","extension":"gif","name":"styleguide.gif","variant":"2000px","filesize":717281},"download":547680,"date":"2018-08-27T09:51:01.000"}
{"cocoon":{"name":"Blub","url":"https://blub.example.org/","version":"2.12.1 beta","type":"demo"},"file":{"type":"application/zip","extension":"zip","name":"roos.zip","variant":"original","filesize":1862406},"download":815697,"date":"2018-03-17T23:48:02.000"}
{"cocoon":{"name":"Blub","url":"https://blub.example.org/","version":"2.12.1 beta","type":"demo"},"file":{"type":"image/jpeg","extension":"jpg","name":"logo.jpg","variant":"web","filesize":821324},"download":616235,"date":"2018-06-09T04:46:31.000"}
{"cocoon":{"name":"Doh","url":"https://doh.example.org/","version":"2.12.2 alpha","type":"dev"},"file":{"type":"image/png","extension":"png","name":"presskit-2007.png","variant":"web","filesize":869585},"download":429289,"date":"2018-05-29T02:20:40.000"}

```

Logstash output:

```
{
      "@version" => "1",
          "date" => "2018-08-02T07:22:07.000",
      "download" => 261320,
          "file" => {
          "variant" => "2000px",
             "type" => "image/jpeg",
         "filesize" => 1013002,
        "extension" => "jpg",
             "name" => "20180917_201321.jpg"
    },
        "cocoon" => {
           "type" => "demo",
            "url" => "https://blub.example.org/",
           "name" => "Blub",
        "version" => "2.12.1 beta"
    },
    "@timestamp" => 2018-10-22T07:04:29.705Z
}
```

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [October 22, 2018, 8:43am UTC](https://discuss.elastic.co/t/filebeats-input-json-lines-only-processing-single-entry/153348/2 "2018-10-22T08:43:20Z")

</div>

What if you use a `json` codec instead of `json_lines`?

---

<div class="post-metadata">

**Author:** ![Werring](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/werring/32/39402_2.png) [@Werring](https://discuss.elastic.co/u/Werring)\
**Post date:** [October 22, 2018, 8:52am UTC](https://discuss.elastic.co/t/filebeats-input-json-lines-only-processing-single-entry/153348/3 "2018-10-22T08:52:09Z")

</div>

Oh wow, that worked!  
Thanks!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 19, 2018, 8:52am UTC](https://discuss.elastic.co/t/filebeats-input-json-lines-only-processing-single-entry/153348/4 "2018-11-19T08:52:38Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
