# Issue: logstash module's \`format: json\` not work and json pipeline not matched?

**URL:** <https://discuss.elastic.co/t/issue-logstash-modules-format-json-not-work-and-json-pipeline-not-matched/159329>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [December 4, 2018, 9:58am UTC](https://discuss.elastic.co/t/issue-logstash-modules-format-json-not-work-and-json-pipeline-not-matched/159329 "2018-12-04T09:58:33Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![youzipi](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/youzipi/32/38413_2.png) [@youzipi](https://discuss.elastic.co/u/youzipi)\
**Post date:** [December 4, 2018, 9:58am UTC](https://discuss.elastic.co/t/issue-logstash-modules-format-json-not-work-and-json-pipeline-not-matched/159329/1 "2018-12-04T09:58:33Z")

</div>

the former question is because my filebeat config not create the json pipeline in es.  
I send it by modify the default format.  
Now I have new questions ,as described in the issue.  
I cannot create the json pipeline by the config shown in document.

Q1:  
**Can anyone tell me where the default pipeline from  
or how can I use custom pipeline for specific module from filebeat side?**  
Q2:  
**I cloned the source code, but i donot find how the module config parsed.**

> <https://github.com/elastic/beats/issues/9394>

update at  
2018-12-06 09:34:09

===================  
former question

===================

# Hout to config filebeat 6.5.1 logstash modules json decode?

filebeat version: 6.5.1  
elk : 6.5.1

I use the `logstash modules` to tranfer my application's log to ELK.  
but it's not parsed in elk.  
how can i parse the json in filebeat side?

In Kibana, the message body is not parsed , instead it is treated like a string.

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/6/f/6fe743b61e5cc61f90d7f8cd58c4af02e7b5a25d.png)

config :

```xml
// spring-logback.xml
    <appender name="STASH" class="ch.qos.logback.core.rolling.RollingFileAppender">
        <file>logback/center.log</file>
        <rollingPolicy class="ch.qos.logback.core.rolling.TimeBasedRollingPolicy">
            <fileNamePattern>logback/center.%d{yyyy-MM-dd}.log</fileNamePattern>
            <maxHistory>7</maxHistory>
        </rollingPolicy>
        <encoder class="net.logstash.logback.encoder.LogstashEncoder"/>
    </appender>

```

```auto
// ./modules.d/logstash.yml
- module: logstash
  # logs
  log:
    enabled: true

    # Set custom paths for the log files. If left empty,
    # Filebeat will choose the paths depending on your OS.
    var.paths: ["/Users/youzipi/projects/0/ace-security/logback/*.log"]
    # format: json # i tried this, not worked.

```

i tried configure json decode

```auto
processors:
  - decode_json_fields:
    fields: ["logstash"]
    target: ""
    overwrite_keys: true

```

but it throw an error : `Exiting: error unpacking config data: required 'object', but found 'string' in field 'processors.0.target' (source:'filebeat.yml')`

I saw the document example, it's a empty string there.

---

<div class="post-metadata">

**Author:** ![steffens](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/steffens/32/79630_2.png) [@steffens](https://discuss.elastic.co/u/steffens)\
**Post date:** [December 5, 2018, 1:59pm UTC](https://discuss.elastic.co/t/issue-logstash-modules-format-json-not-work-and-json-pipeline-not-matched/159329/2 "2018-12-05T13:59:05Z")

</div>

Which Logstash and Elasticsearch versions are you using?

Have you tried not to set target at all:

```auto
processors:
  - decode_json_fields:
    fields: ["logstash"]
    overwrite_keys: true

```

---

<div class="post-metadata">

**Author:** ![youzipi](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/youzipi/32/38413_2.png) [@youzipi](https://discuss.elastic.co/u/youzipi)\
**Post date:** [December 6, 2018, 1:44am UTC](https://discuss.elastic.co/t/issue-logstash-modules-format-json-not-work-and-json-pipeline-not-matched/159329/4 "2018-12-06T01:44:01Z")

</div>

I go into the wrong path.  
The question is that I cannot create the json pipeline by the config shown in document.  
I add more infomation and try steps in issue.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 3, 2019, 1:44am UTC](https://discuss.elastic.co/t/issue-logstash-modules-format-json-not-work-and-json-pipeline-not-matched/159329/5 "2019-01-03T01:44:09Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
