# HTTP NLog to Logstash Not Parsing Right

**URL:** <https://discuss.elastic.co/t/http-nlog-to-logstash-not-parsing-right/154070>\
**Category:** Logstash\
**Created:** [October 25, 2018, 10:25pm UTC](https://discuss.elastic.co/t/http-nlog-to-logstash-not-parsing-right/154070 "2018-10-25T22:25:58Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![hmendoza](https://avatars.discourse-cdn.com/v4/letter/h/90ced4/32.png) [@hmendoza](https://discuss.elastic.co/u/hmendoza)\
**Post date:** [October 25, 2018, 10:25pm UTC](https://discuss.elastic.co/t/http-nlog-to-logstash-not-parsing-right/154070/1 "2018-10-25T22:25:58Z")

</div>

I have a similar issue than [Empty result when using TCP input to collect NLog JSON events](https://discuss.elastic.co/t/empty-result-when-using-tcp-input-to-collect-nlog-json-events/126107) and no one posted a response to that (automatically got closed after 28 days).

I captured the output that NLog is sending to ElasticSearch. It’s sending HTTP POST data as a bulk insert. That’s a REST API call used to do bulk insert to ElasticSearch. I captured the payload that is sent and it’s sent as multiple separate JSON objects. That’s apparently known as NDJSON.

In LogStash we’re capturing the input as HTTP. The problem we’re having currently is that when we read the input and output that to a file, we only get the first JSON object and not the subsequent ones.

It works as expected if the input filter is a file, but not if it is HTTP.

Here is the configurations we are using

**Test 1:** NDJSON input from a file, output to a file. Input codec JSON, output codec rubydebug

```
input {

http {

port =&gt; 5046

codec =&gt; json

}

}

filter {

}

output {

file {

codec =&gt; rubydebug

path =&gt; &quot;/var/log/temptest2.log&quot;

}

}

```

Result: The full NDJSON gets written to the output file.

**Test 2:** NDJSON input from HTTP, output to a file. Input codec JSON, output codec rubydebug

I send the NDJSON file data with a cURL command: curl -s -H "Content-Type: application/json" -XPOST localhost:5046/\_bulk --data-binary "@bulk.txt"

That’s the same file I used for the file input in Test 1.

```
input {

http {

port =&gt; 5046

codec =&gt; json

}

}

filter {

}

output {

file {

codec =&gt; rubydebug

path =&gt; &quot;/var/log/temptest3.log&quot;

}

}

```

Result: Only the first JSON object gets written to the file.

So it appears that the issue is with the HTTP input filter not processing the input correctly. I’ve tried multiple different codecs (json, json\_lines,multi\_line,es\_bulk) (es\_bulk seemed the most promising).

Can anyone please help?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 22, 2018, 10:28pm UTC](https://discuss.elastic.co/t/http-nlog-to-logstash-not-parsing-right/154070/2 "2018-11-22T22:28:20Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
