# Http module: "invalid character '\<' looking for beginning of value"

**URL:** <https://discuss.elastic.co/t/http-module-invalid-character-looking-for-beginning-of-value/148082>\
**Category:** Beats\
**Tags:** metricbeat\
**Created:** [September 11, 2018, 7:55am UTC](https://discuss.elastic.co/t/http-module-invalid-character-looking-for-beginning-of-value/148082 "2018-09-11T07:55:01Z")\
**Posts on this page:** 10\
**Page:** 1

<div class="post-metadata">

**Author:** ![MarkusB](https://avatars.discourse-cdn.com/v4/letter/m/7cd45c/32.png) [@MarkusB](https://discuss.elastic.co/u/MarkusB)\
**Post date:** [September 11, 2018, 7:55am UTC](https://discuss.elastic.co/t/http-module-invalid-character-looking-for-beginning-of-value/148082/1 "2018-09-11T07:55:01Z")

</div>

Hi all,  
My first steps with Elastic, so maybe a dumb question. Running 6.4.0 with Metricbeat http module polling a SmartMeter.

Test with Google Chrome:  
[http://192.168.13.50:8080/xml/json.php?mode=infomin](http://192.168.13.50:8080/xml/json.php?mode=infomin)  
JSON Reply of SmartMeter:  
{"devicetype":"ALL3690","devicename":"ALL3690","softversion":"320","patchlevel":"1052","revision":"0.02"}

http.yml

- module: http  
metricsets: ["json"]  
period: 5s  
hosts: ["192.168.13.50:8080"]  
namespace: "json\_namespace"  
path: "/xml/json.php?mode=infomin"

Metricbeat debug output:  
"@timestamp": "2018-09-11T07:48:45.447Z",  
"@metadata": {  
"beat": "metricbeat",  
"type": "doc",  
"version": "6.4.0"  
},  
"error": {  
"message": "invalid character '\<' looking for beginning of value"  
},  
"metricset": {  
"name": "json",  
"module": "http",  
"host": "192.168.13.50:8080",  
"rtt": 2969  
},  
"beat": {  
"name": "SBU",  
"hostname": "SBU",  
"version": "6.4.0"  
},  
"host": {  
"name": "SBU"  
}  
}

Any ideas what is wrong? Configuration? Malformed JSON reply? Thanks in advance.

---

<div class="post-metadata">

**Author:** ![Mario\_Castro](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mario_castro/32/35107_2.png) [@Mario\_Castro](https://discuss.elastic.co/u/Mario_Castro)\
**Post date:** [September 11, 2018, 8:45am UTC](https://discuss.elastic.co/t/http-module-invalid-character-looking-for-beginning-of-value/148082/2 "2018-09-11T08:45:06Z")

</div>

Hi @MarkusB 🙂

I'm not sure about the root of your issue but that message is the error of Go trying to parse a JSON but that has probably received an HTML (like `<html><head>...`) That's why it is warning about the `<` character at the beginning.

It's probably not making the request where you are expecting or to the path you are expecting. I'd try to set the path without the first `/` and set the host with the `http://` schema just in case. Also if you have an Nginx or some proxy, I'll review there just in case.

Best regards.

---

<div class="post-metadata">

**Author:** ![MarkusB](https://avatars.discourse-cdn.com/v4/letter/m/7cd45c/32.png) [@MarkusB](https://discuss.elastic.co/u/MarkusB)\
**Post date:** [September 11, 2018, 9:23am UTC](https://discuss.elastic.co/t/http-module-invalid-character-looking-for-beginning-of-value/148082/3 "2018-09-11T09:23:22Z")

</div>

Hi @Mario_Castro

Thanks for your quick reply. I tried both of your hints with the same result. So if it's not an obvious configuration fault, I'll set up Wireshark to find out what is going back and forth.

Kind regards

---

<div class="post-metadata">

**Author:** ![Mario\_Castro](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mario_castro/32/35107_2.png) [@Mario\_Castro](https://discuss.elastic.co/u/Mario_Castro)\
**Post date:** [September 11, 2018, 9:59am UTC](https://discuss.elastic.co/t/http-module-invalid-character-looking-for-beginning-of-value/148082/4 "2018-09-11T09:59:05Z")

</div>

Can you paste the _curl_ output of `curl -vvvv http://192.168.13.50:8080/xml/json.php?mode=infomin`?

Maybe it's something with the Content-Type of the headers

---

<div class="post-metadata">

**Author:** ![MarkusB](https://avatars.discourse-cdn.com/v4/letter/m/7cd45c/32.png) [@MarkusB](https://discuss.elastic.co/u/MarkusB)\
**Post date:** [September 11, 2018, 11:20am UTC](https://discuss.elastic.co/t/http-module-invalid-character-looking-for-beginning-of-value/148082/5 "2018-09-11T11:20:18Z")

</div>

With Wireshark I found out that the GET string ends up like:  
[http://192.168.13.50:8080/xml/json.php%3Fmode=infomin](http://192.168.13.50:8080/xml/json.php%3Fmode=infomin)

So the reply of the SmartMeter is 404 page not found because of the %3F in the URL.  
The big question is also how to get the ? in the URL instead of %3F replacement...

---

<div class="post-metadata">

**Author:** ![Mario\_Castro](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mario_castro/32/35107_2.png) [@Mario\_Castro](https://discuss.elastic.co/u/Mario_Castro)\
**Post date:** [September 11, 2018, 2:46pm UTC](https://discuss.elastic.co/t/http-module-invalid-character-looking-for-beginning-of-value/148082/6 "2018-09-11T14:46:07Z")

</div>

I have been able to reproduce it locally and it seems like a bug in the `http` module.

I have opened an issue in Github to follow the fix, you can find it here: [https://github.com/elastic/beats/issues/8286](https://github.com/elastic/beats/issues/8286)

Thanks for reporting!

---

<div class="post-metadata">

**Author:** ![Mario\_Castro](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mario_castro/32/35107_2.png) [@Mario\_Castro](https://discuss.elastic.co/u/Mario_Castro)\
**Post date:** [September 27, 2018, 8:48am UTC](https://discuss.elastic.co/t/http-module-invalid-character-looking-for-beginning-of-value/148082/7 "2018-09-27T08:48:59Z")

</div>

Hi @MarkusB

Just to follow up, we have added a parameter to solve this kind of issue, you can see the merged PR here [https://github.com/elastic/beats/pull/8292/#pullrequestreview-154757159](https://github.com/elastic/beats/pull/8292/#pullrequestreview-154757159)

Again, thanks for reporting!

---

<div class="post-metadata">

**Author:** ![MarkusB](https://avatars.discourse-cdn.com/v4/letter/m/7cd45c/32.png) [@MarkusB](https://discuss.elastic.co/u/MarkusB)\
**Post date:** [September 27, 2018, 9:29am UTC](https://discuss.elastic.co/t/http-module-invalid-character-looking-for-beginning-of-value/148082/8 "2018-09-27T09:29:03Z")

</div>

Hi @Mario_Castro  
Thanks a lot for the quick solution and for keeping me in the loop. The current downloadable Metricbeat version is 6.4.1 which does not contain your recent changes. When do you think the next release will be available? Is there a fixed schedule?

---

<div class="post-metadata">

**Author:** ![Mario\_Castro](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mario_castro/32/35107_2.png) [@Mario\_Castro](https://discuss.elastic.co/u/Mario_Castro)\
**Post date:** [September 27, 2018, 10:36am UTC](https://discuss.elastic.co/t/http-module-invalid-character-looking-for-beginning-of-value/148082/9 "2018-09-27T10:36:25Z")

</div>

Not really, but in this case I guess that it will be released soon, probably in the next version which is 6.4.2

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 25, 2018, 10:36am UTC](https://discuss.elastic.co/t/http-module-invalid-character-looking-for-beginning-of-value/148082/10 "2018-10-25T10:36:42Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
