# How to stop Filebeat from shipping incorrect JSON to Elastic?

**URL:** https://discuss.elastic.co/t/how-to-stop-filebeat-from-shipping-incorrect-json-to-elastic/369162
**Category:** Beats
**Tags:** ecs-elastic-common-schema, filebeat
**Created:** [October 21, 2024, 3:44pm UTC](https://discuss.elastic.co/t/how-to-stop-filebeat-from-shipping-incorrect-json-to-elastic/369162 "2024-10-21T15:44:02Z")
**Posts on this page:** 3
**Page:** 1

<div class="post-metadata">

### Author: ![andreycha](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andreycha/32/109183_2.png) [@andreycha](https://discuss.elastic.co/u/andreycha)
#### Post date: [October 21, 2024, 3:44pm UTC](https://discuss.elastic.co/t/how-to-stop-filebeat-from-shipping-incorrect-json-to-elastic/369162/1 "2024-10-21T15:44:02Z")

</div>

Hi,

Our applications emit logs in ECS format, a log entry per line. In Filebeat config we have a parser defined:

```auto
parsers:
  - ndjson:
      target: ''
      expand_keys: true
      overwrite_keys: true
      add_error_key: true

```

Then there is a processor in the ingest pipeline which converts some of the fields into lower case:

```auto
processors:
  - lowercase:
      field: 'log.level'
on_failure:
- set:
    field: error.message
    value: '{{ _ingest.on_failure_message }}'

```

Sometimes we have issues with free disk space which lead to incorrect log entries in the file, where one log entry is concatenated with previous incompletely written log entry, e.g.:

```auto
{"@timestamp":"2024-10-17T10:35:59.1814105+02:00","log.level":"Information","message":"Requ{"@timestamp":"2024-10-17T12:00:01.0603052+02:00","log.level":"Information","message":"Ok"}

```

Notice how the first `message` property is not written completely and then the second log entry is immediately appended to it.

When Filebeat processes such lines, it emits an error like "Error decoding JSON: invalid character '@' after object key:value pair" (error message varies a bit depending on where exactly previous log line was abrupted).

Finally, broken log lines are delivered into Elastic where `error.message` is set to "field [level] not present as part of path [log.level]".

We would like to just completely ignore such broken log lines. How to implement it properly? `ignore_decoding_error` option of `ndjson` parser seems to just control whether error log is emitted or not.

---

<div class="post-metadata">

### Author: ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)
#### Post date: [October 21, 2024, 6:17pm UTC](https://discuss.elastic.co/t/how-to-stop-filebeat-from-shipping-incorrect-json-to-elastic/369162/2 "2024-10-21T18:17:21Z")

</div>

> [@andreycha](#):
>
> `error.message`

Hi @andreycha

`processors:`

Are executed in order, so perhaps the last processors should just be a `drop_event` processor based on the contents or existence of one of the two following...

> **`add_error_key`**  
> If this setting is enabled, Filebeat adds an "error.message" and "error.type: json" key in case of JSON unmarshalling errors or when a `message_key` is defined in the configuration but cannot be used.

Something like

```auto
  - drop_event:
      when:
        equals:
          error.type: "json"

```

---

<div class="post-metadata">

### Author: ![andreycha](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andreycha/32/109183_2.png) [@andreycha](https://discuss.elastic.co/u/andreycha)
#### Post date: [November 13, 2024, 3:46pm UTC](https://discuss.elastic.co/t/how-to-stop-filebeat-from-shipping-incorrect-json-to-elastic/369162/3 "2024-11-13T15:46:14Z")

</div>

Hi @stephenb ,

Thank you, that should do the job!
