# If \_jsonparsefailure in \[tags\]

**URL:** <https://discuss.elastic.co/t/if--jsonparsefailure-in-tags/73062>\
**Category:** Logstash\
**Created:** [January 27, 2017, 8:51pm UTC](https://discuss.elastic.co/t/if--jsonparsefailure-in-tags/73062 "2017-01-27T20:51:48Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![alexus](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/alexus/32/12696_2.png) [@alexus](https://discuss.elastic.co/u/alexus)\
**Post date:** [January 27, 2017, 8:51pm UTC](https://discuss.elastic.co/t/if--jsonparsefailure-in-tags/73062/1 "2017-01-27T20:51:49Z")

</div>

My filter:

> filter {  
> json {  
> source =\> "message"  
> }  
> }

_sometimes_, I see events tagged as "\_jsonparsefailure", however some events (NON-JSON) are being dropped completely.

How do I output events to elasticsearch without dropping them?

---

<div class="post-metadata">

**Author:** ![anhlqn](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/anhlqn/32/5454_2.png) [@anhlqn](https://discuss.elastic.co/u/anhlqn)\
**Post date:** [January 27, 2017, 10:17pm UTC](https://discuss.elastic.co/t/if--jsonparsefailure-in-tags/73062/2 "2017-01-27T22:17:13Z")

</div>

```auto
output {
if "_jsonparsefailure" in [tags] {
		file {
			path => "logs/_jsonparsefailure.txt"
		}
	}
}

```

This config outputs failed messages to file so that you can review them later.

---

<div class="post-metadata">

**Author:** ![alexus](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/alexus/32/12696_2.png) [@alexus](https://discuss.elastic.co/u/alexus)\
**Post date:** [January 28, 2017, 4:01am UTC](https://discuss.elastic.co/t/if--jsonparsefailure-in-tags/73062/3 "2017-01-28T04:01:32Z")

</div>

Thank you, however it doesn't look like what I need though...

My entire logstash config:

```
input {
  gelf { codec => "json" }
}

filter {
  json {
    source => "message"
  }
}

output {
  elasticsearch { hosts => ["0:9200"] }
}

```

I need write into elasticsearch not into \_jsonparsefailure.txt file.

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [January 29, 2017, 7:01pm UTC](https://discuss.elastic.co/t/if--jsonparsefailure-in-tags/73062/4 "2017-01-29T19:01:03Z")

</div>

Logstash won't drop messages just because the json filter fails. However, it might drop then because ES rejects them. Check your Logstash logs to make sure that isn't the case.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 26, 2017, 7:01pm UTC](https://discuss.elastic.co/t/if--jsonparsefailure-in-tags/73062/5 "2017-02-26T19:01:08Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
