# Json and normal logs as input

**URL:** <https://discuss.elastic.co/t/json-and-normal-logs-as-input/319205>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [November 17, 2022, 2:17pm UTC](https://discuss.elastic.co/t/json-and-normal-logs-as-input/319205 "2022-11-17T14:17:40Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![anon90868141](https://avatars.discourse-cdn.com/v4/letter/a/7ab992/32.png) [@anon90868141](https://discuss.elastic.co/u/anon90868141)\
**Post date:** [November 17, 2022, 2:17pm UTC](https://discuss.elastic.co/t/json-and-normal-logs-as-input/319205/1 "2022-11-17T14:17:40Z")

</div>

Hi,

what is the best practice when using filestream as type and having 2 different input paths of logs where 1 is a simple \*.log and the other one is a \*.json?

Should I still just use e.g. the following although like 50% of the logs are not json?:

```auto
  parsers:
  - ndjson:
      keys_under_root: true
      expand_keys: true

```

Another solution could be:

```auto
---
- type: filestream
  paths:
    - /var/log/elasticsearch/*.json

  parsers:
  - ndjson:
      keys_under_root: true
      expand_keys: true

---
- type: filestream
  paths:
    - /var/log/elasticsearch/gc*

  - multiline:
      type: pattern
      pattern: '...'
      negate: true
      match: after
```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 15, 2022, 4:17pm UTC](https://discuss.elastic.co/t/json-and-normal-logs-as-input/319205/2 "2022-12-15T16:17:44Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
