# JSON data split up (\_jsonparseerror) in logstash-7.2.0-1. Works fine in logstash-7.1.1-1

**URL:** <https://discuss.elastic.co/t/json-data-split-up-jsonparseerror-in-logstash-7-2-0-1-works-fine-in-logstash-7-1-1-1/190624>\
**Category:** Logstash\
**Created:** [July 16, 2019, 1:25am UTC](https://discuss.elastic.co/t/json-data-split-up-jsonparseerror-in-logstash-7-2-0-1-works-fine-in-logstash-7-1-1-1/190624 "2019-07-16T01:25:56Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![sjaganna](https://avatars.discourse-cdn.com/v4/letter/s/50afbb/32.png) [@sjaganna](https://discuss.elastic.co/u/sjaganna)\
**Post date:** [July 16, 2019, 1:25am UTC](https://discuss.elastic.co/t/json-data-split-up-jsonparseerror-in-logstash-7-2-0-1-works-fine-in-logstash-7-1-1-1/190624/1 "2019-07-16T01:25:56Z")

</div>

Hello!

I've been in the midst of working with the ELK stack for the first time. I'm currently sending data from Metricbeat -\> Logstash -\> an external script (output sent over TCP) -\> Logstash -\> Elasticsearch. However, when I upgrade the logstash version to `logstash-7.2.0-1` from `logstash-7.1.1-1`, My JSON is split up and sent in multiple documents instead of a single document which naturally leads to a \_jsonparseerror tag. For example:

An output with logstash-7.2.0-1 where the "message field" is half the message JSON and the "..." indicates the middle of the message. This shows up with a \_jsonparsefailure tag:

`[2019-07-15T18:17:29,435][ERROR][logstash.codecs.json] JSON parse error, original data now in message field {:error=>#<LogStash::Json::ParserError: Unexpected end-of-input: expected close marker for Object (start marker at [Source: (String)"{"service": {"type": "system"}, "tags": "... \"ios\": 66"}`

The output with `logstash-7.1.1-1` is clean and is parsed properly by elasticsearch. The only difference between the two is the logstash version. Any ideas?

---

<div class="post-metadata">

**Author:** ![sjabiulla](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sjabiulla/32/48429_2.png) [@sjabiulla](https://discuss.elastic.co/u/sjabiulla)\
**Post date:** [July 16, 2019, 6:39am UTC](https://discuss.elastic.co/t/json-data-split-up-jsonparseerror-in-logstash-7-2-0-1-works-fine-in-logstash-7-1-1-1/190624/2 "2019-07-16T06:39:15Z")

</div>

Check this thread once.

> [@Logs on two lines](https://discuss.elastic.co/t/logs-on-two-lines/187915):
>
> Hi, I am trying to get logs whose are on two different lines : [2019-06-18T06:57:32.032Z] [org.kie.api.internal.utils.tydhiks] [main] [141] [INFO] Adding Service org.drools.core.concurrent.EEEeeF In my logstash I tried : grok { patterns\_dir =\> "/u01/app/elk-config/logstash/patterns" match =\> ["message", "(?m)\[(?\<timestamp\>%{TIMESTAMP\_ISO8601})\]\[%{DATA:servlet}\]\[%{WORD:branch}\]\[%{DATA:PID}\]\[%{DATA:level}\]%{DATA:log\_message}"] } but it does not take the sec…

---

<div class="post-metadata">

**Author:** ![johank](https://avatars.discourse-cdn.com/v4/letter/j/e9bcb4/32.png) [@johank](https://discuss.elastic.co/u/johank)\
**Post date:** [August 12, 2019, 8:09am UTC](https://discuss.elastic.co/t/json-data-split-up-jsonparseerror-in-logstash-7-2-0-1-works-fine-in-logstash-7-1-1-1/190624/3 "2019-08-12T08:09:47Z")

</div>

We are having the same problem.

- Using LogstashTcpSocketAppender from Java to log to our logstash

7.1.1 works fine  
7.2.1 gives the error  
7.3.0 also gives the error

- Discovered when initially wanting to upgrade our old logstash 5.6.0

---

<div class="post-metadata">

**Author:** ![johank](https://avatars.discourse-cdn.com/v4/letter/j/e9bcb4/32.png) [@johank](https://discuss.elastic.co/u/johank)\
**Post date:** [August 12, 2019, 8:39am UTC](https://discuss.elastic.co/t/json-data-split-up-jsonparseerror-in-logstash-7-2-0-1-works-fine-in-logstash-7-1-1-1/190624/4 "2019-08-12T08:39:00Z")

</div>

Possible solution.

switching from codec json =\> json\_lines seems to solve it. (have only tested for 5 minutes so far)  
Probably worked before because of different code used to convert tcp stream into messages.

---

<div class="post-metadata">

**Author:** ![sjaganna](https://avatars.discourse-cdn.com/v4/letter/s/50afbb/32.png) [@sjaganna](https://discuss.elastic.co/u/sjaganna)\
**Post date:** [August 12, 2019, 3:55pm UTC](https://discuss.elastic.co/t/json-data-split-up-jsonparseerror-in-logstash-7-2-0-1-works-fine-in-logstash-7-1-1-1/190624/5 "2019-08-12T15:55:19Z")

</div>

This solution seemed to work for me as well! Thanks.  
This would have been nice to document as a breaking change in documentation.

---

<div class="post-metadata">

**Author:** ![johank](https://avatars.discourse-cdn.com/v4/letter/j/e9bcb4/32.png) [@johank](https://discuss.elastic.co/u/johank)\
**Post date:** [August 13, 2019, 7:22am UTC](https://discuss.elastic.co/t/json-data-split-up-jsonparseerror-in-logstash-7-2-0-1-works-fine-in-logstash-7-1-1-1/190624/6 "2019-08-13T07:22:33Z")

</div>

We noticed it is actually mentioned in the documentation of the logstash logback encoder. But aside from that, what made it difficult to find is that the setting "json" almost works 🙂 - I suppose "json" probably has a maximum object size it will read up/buffer to before splitting.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 10, 2019, 7:34am UTC](https://discuss.elastic.co/t/json-data-split-up-jsonparseerror-in-logstash-7-2-0-1-works-fine-in-logstash-7-1-1-1/190624/7 "2019-09-10T07:34:02Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
