# How to disable JSON parser

**URL:** <https://discuss.elastic.co/t/how-to-disable-json-parser/279336>\
**Category:** Logstash\
**Created:** [July 22, 2021, 4:33am UTC](https://discuss.elastic.co/t/how-to-disable-json-parser/279336 "2021-07-22T04:33:44Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![maxim.mokhov](https://avatars.discourse-cdn.com/v4/letter/m/51bf81/32.png) [@maxim.mokhov](https://discuss.elastic.co/u/maxim.mokhov)\
**Post date:** [July 22, 2021, 4:33am UTC](https://discuss.elastic.co/t/how-to-disable-json-parser/279336/1 "2021-07-22T04:33:44Z")

</div>

I have different logs from applications, and I want sent it to elasticsearch.  
In some cases in logs appear JSON. I want to send it in elasticsearch as plaintext. But in log logstash I see "JSON parse failure":

```auto
[2021-07-22T07:08:51,808][ERROR][logstash.inputs.gelf] JSON parse failure. Falling back to plain-text {:error=>#<LogStash::Json::ParserError: Unexpected character ('f' (code 102)): was expecting comma to separate Object entries
 at [Source: (byte[])"{"facility":"fluentd","protocol ...

```

In input section I use codec =\> "plain" .  
In filter section I not use any JSON modificators.

How I can wholly disable JSON parser for this pipeline?

my logstash config:

```auto
input {
  gelf {
    use_tcp => true
    port => 5046
    remap => false
    tags => ["cicd-k8s-gelf"]
	codec => "plain"
  }
}

filter {
  ruby { code => "event.set('@orig_timestamp' , LogStash::Timestamp.new)" }

  if "cicd-k8s-gelf" in [tags] {
    ruby {
      code => '
        t = Time.at(event.get("@orig_timestamp").to_i)
        t2 = Time.at(event.get("@timestamp").to_i)
        event.set("[@metadata][d_t]", t.strftime("%Y.%m.%d")) 
        event.set("@diff_time", t-t2)
      '
    }
  }
}

output {
  if "cicd-k8s-gelf" in [tags] {
    elasticsearch {
      hosts => ["ELK_SERVERS"]
      index => "INDEX-%{[@metadata][d_t]}"
      user => "${USER}"
      password => "${PWD}"
      manage_template => false
      ilm_enabled => false
    }
  }
}

```

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [July 22, 2021, 3:37pm UTC](https://discuss.elastic.co/t/how-to-disable-json-parser/279336/2 "2021-07-22T15:37:49Z")

</div>

My reading of the [code](https://github.com/logstash-plugins/logstash-input-gelf/blob/2502e04a682f869c9d29ed9a2cac36a0a280a879/lib/logstash/inputs/gelf.rb#L206) is that it unconditionally calls the JSON parser, so no, you cannot disable it.

---

<div class="post-metadata">

**Author:** ![maxim.mokhov](https://avatars.discourse-cdn.com/v4/letter/m/51bf81/32.png) [@maxim.mokhov](https://discuss.elastic.co/u/maxim.mokhov)\
**Post date:** [July 22, 2021, 11:22pm UTC](https://discuss.elastic.co/t/how-to-disable-json-parser/279336/3 "2021-07-22T23:22:37Z")

</div>

I understand, thanks

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 19, 2021, 11:23pm UTC](https://discuss.elastic.co/t/how-to-disable-json-parser/279336/4 "2021-08-19T23:23:00Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
