# Getting Json parsing exception in logstash.filters.json

**URL:** <https://discuss.elastic.co/t/getting-json-parsing-exception-in-logstash-filters-json/223489>\
**Category:** Logstash\
**Created:** [March 13, 2020, 10:52am UTC](https://discuss.elastic.co/t/getting-json-parsing-exception-in-logstash-filters-json/223489 "2020-03-13T10:52:17Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Arpit\_Pruthi](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/arpit_pruthi/32/47218_2.png) [@Arpit\_Pruthi](https://discuss.elastic.co/u/Arpit_Pruthi)\
**Post date:** [March 13, 2020, 10:52am UTC](https://discuss.elastic.co/t/getting-json-parsing-exception-in-logstash-filters-json/223489/1 "2020-03-13T10:52:17Z")

</div>

This is my logstash config :-

```
input { stdin { } } 
    filter {
    grok{ 
    patterns_dir => ["./patterns"] 
    match => {"message" => "^abc-logs:%{TEMP:msg}"
    }} 
    json{source => "msg"} 
    kv{
    source => "msg" 
    trim_value => "{}" 
    field_split => "\s*,\s*"
    }} 
    output { stdout {} }

```

This is my patterns file:-

```
TEMP (%{SPACE}*([a-zA-z]+%{SPACE}*)+=?%{SPACE}*{%{NUMBER}}?%{SPACE}*,?%{SPACE}*)+

```

Everything works fine I get the final required output for my input example:-

```
{
           "msg" => "Id={2},inni={3}",
       "message" => "abc-logs:Id={2},inni={3}",
      "@version" => "1",
          "host" => "arpit.pruthi",
    "@timestamp" => 2020-03-13T09:37:31.807Z,
          "tags" => [
        [0] "_jsonparsefailure"
    ],
          "inni" => "3",
       "Id" => "2"
}

```

Id and inni comes in json but I also get the exception as :-

`[logstash.filters.json] Error parsing json {:source=>"msg", :raw=>"Id={2},inni={3}", :exception=>#<LogStash::Json::ParserError: Unrecognized token 'Id': was expecting ('true', 'false' or 'null')`

Please help

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [March 13, 2020, 5:49pm UTC](https://discuss.elastic.co/t/getting-json-parsing-exception-in-logstash-filters-json/223489/2 "2020-03-13T17:49:05Z")

</div>

> [@Arpit\_Pruthi](#):
>
> Id={2},inni={3}

That's not valid JSON, so I would not expect a json filter to be able to parse it.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 10, 2020, 5:57pm UTC](https://discuss.elastic.co/t/getting-json-parsing-exception-in-logstash-filters-json/223489/3 "2020-04-10T17:57:41Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
