# How to get multiline JSON parsing configured?

**URL:** <https://discuss.elastic.co/t/how-to-get-multiline-json-parsing-configured/255409>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [November 14, 2020, 5:19pm UTC](https://discuss.elastic.co/t/how-to-get-multiline-json-parsing-configured/255409 "2020-11-14T17:19:19Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![houmie](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/houmie/32/78999_2.png) [@houmie](https://discuss.elastic.co/u/houmie)\
**Post date:** [November 14, 2020, 5:19pm UTC](https://discuss.elastic.co/t/how-to-get-multiline-json-parsing-configured/255409/1 "2020-11-14T17:19:19Z")

</div>

Hello,

When I try to activate multiline JSON parsing directly I get this error message::

> Exiting: Failed to start crawler: starting input failed: Error while initializing input: When using the JSON decoder and multiline together, you need to specify a message\_key value accessing 'filebeat.inputs.0' (source:'/etc/filebeat/filebeat.yml')

I don't quite understand `json.message_key`.  
This is my JSON:

```auto
{
"email": "hh@gmail.com",
"event": "resources.connect_v5",
"level": "info",
"req_vpn": "DE-FSN-X",
"request_id": "51cfc42e-62f1-45c5-b075-e2bae5b42a3b",
"timestamp": "2020-11-14T16:18:36.830208Z",
"vpn_code": "DE-FSN-X"
}
{
...
}

```

**filebeat.yml:**

```auto
filebeat.inputs:
- type: log
  enabled: true
  paths:
    - /home/admin/file.json
  json.keys_under_root: true
  json.add_error_key: true
  multiline.type: pattern
  multiline.pattern: '^{'
  multiline.negate: true
  multiline.match: after

```

Thank you,  
Houman

---

<div class="post-metadata">

**Author:** ![wangqinghuan](https://avatars.discourse-cdn.com/v4/letter/w/d26b3c/32.png) [@wangqinghuan](https://discuss.elastic.co/u/wangqinghuan)\
**Post date:** [November 14, 2020, 5:39pm UTC](https://discuss.elastic.co/t/how-to-get-multiline-json-parsing-configured/255409/2 "2020-11-14T17:39:45Z")

</div>

> [@houmie](#):
>
> `json.keys_under_root`

Follow this:

```auto
filebeat.inputs:
- type: log
  enabled: true
  paths:
    - /path/to/file.json
  multiline.pattern: '^{'
  multiline.negate: true 
  multiline.match: after
  processors:
  - decode_json_fields:
      fields: ["message"]
      target: "json"

```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 12, 2020, 7:39pm UTC](https://discuss.elastic.co/t/how-to-get-multiline-json-parsing-configured/255409/3 "2020-12-12T19:39:46Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
