# Json\_errors in kibana 5.5

**URL:** <https://discuss.elastic.co/t/json-errors-in-kibana-5-5/193812>\
**Category:** Kibana\
**Created:** [August 5, 2019, 2:07pm UTC](https://discuss.elastic.co/t/json-errors-in-kibana-5-5/193812 "2019-08-05T14:07:47Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![irobot678](https://avatars.discourse-cdn.com/v4/letter/i/54ee81/32.png) [@irobot678](https://discuss.elastic.co/u/irobot678)\
**Post date:** [August 5, 2019, 2:07pm UTC](https://discuss.elastic.co/t/json-errors-in-kibana-5-5/193812/1 "2019-08-05T14:07:47Z")

</div>

Hi,

I have observed few logs are not updating properly and its showing a new fleid json\_error in document details .

This never happend before and i have no clue why? whats the reason behind it.

Please help me solve it.

References :

 ![Screenshot_2019-08-05%20Kibana](https://us1.discourse-cdn.com/elastic/original/3X/e/b/ebba63185f55f96ba2b4592c4dab32f6aebd6590.png)

 ![json_error_2](https://us1.discourse-cdn.com/elastic/original/3X/f/7/f70fd4eb393dacd3a70f4fffd59a88aa09f053da.png)

---

<div class="post-metadata">

**Author:** ![jbudz](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jbudz/32/45922_2.png) [@jbudz](https://discuss.elastic.co/u/jbudz)\
**Post date:** [August 5, 2019, 6:44pm UTC](https://discuss.elastic.co/t/json-errors-in-kibana-5-5/193812/2 "2019-08-05T18:44:23Z")

</div>

This looks like it's happening upstream - can you share a little info about what's ingesting the logs? It looks like it's consistent with using the filebeat json parser on invalid json. The message field in the first event for example is missing a `{"some_property": "C`

---

<div class="post-metadata">

**Author:** ![irobot678](https://avatars.discourse-cdn.com/v4/letter/i/54ee81/32.png) [@irobot678](https://discuss.elastic.co/u/irobot678)\
**Post date:** [August 5, 2019, 7:10pm UTC](https://discuss.elastic.co/t/json-errors-in-kibana-5-5/193812/3 "2019-08-05T19:10:35Z")

</div>

Thanks @jbudz for the reply ,

We are using filebeat to read the logs from the file and then send logs to logstash to apply grok filter and then output is sent to Elastic search.

Can you please help understand where I went wrong and why this is happening ?

---

<div class="post-metadata">

**Author:** ![irobot678](https://avatars.discourse-cdn.com/v4/letter/i/54ee81/32.png) [@irobot678](https://discuss.elastic.co/u/irobot678)\
**Post date:** [August 6, 2019, 3:39pm UTC](https://discuss.elastic.co/t/json-errors-in-kibana-5-5/193812/4 "2019-08-06T15:39:41Z")

</div>

HI,

Can some one please help me solve it.

---

<div class="post-metadata">

**Author:** ![jbudz](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jbudz/32/45922_2.png) [@jbudz](https://discuss.elastic.co/u/jbudz)\
**Post date:** [August 6, 2019, 6:23pm UTC](https://discuss.elastic.co/t/json-errors-in-kibana-5-5/193812/5 "2019-08-06T18:23:10Z")

</div>

I believe we're cutting off the log at some point in between the file and elasticsearch. Is the file you're reading from output in json? Can you share the respective filebeat and logstash configurations?

---

<div class="post-metadata">

**Author:** ![irobot678](https://avatars.discourse-cdn.com/v4/letter/i/54ee81/32.png) [@irobot678](https://discuss.elastic.co/u/irobot678)\
**Post date:** [August 8, 2019, 6:11am UTC](https://discuss.elastic.co/t/json-errors-in-kibana-5-5/193812/6 "2019-08-08T06:11:10Z")

</div>

@jbudz sorry for the late reply.

Please look into my configurations below and help me correct the configuration. If i did something wrong.

filebeat.conf

> filebeat.registry\_file: /var/log/containers/filebeat\_registry  
> filebeat.prospectors:
> 
> - input\_type: log  
> paths:
> - "/var/log/containers/\*.log"  
> exclude\_files: ['filebeat1.\*log','monitoring-influxdb.\*log','influxdb.\*log','weave-net.\*log','esmaster.\*log','esdata.\*log','esclient._log','kubeproxy.log','kube.log','grafana_.log','weave-npc.\*log','weave.\*log','weave-net.\*log','jmxtrans.\*log','kibana.\*log','logstash.\*log','kubernetes-dashboard.\*log','qa.\*log']  
> symlinks: true  
> json.message\_key: log  
> json.keys\_under\_root: true  
> json.add\_error\_key: true  
> multiline.pattern: '\[1\]{4}-[0-9]{2}-[0-9]{2}'  
> multiline.negate: true  
> multiline.match: after  
> document\_type: kube-logs  
> reload.enabled: true  
> reload.period: 10s  
> output.logstash:  
> hosts: ${LOGSTASH\_HOSTS}  
> timeout: 800  
> bulk\_max\_size: 100  
> logging.level: ${LOG\_LEVEL}

logstash.conf

> input {
> 
> beats {
> 
> ```
> port => 5000
> 
> ```
> 
> }
> 
> }
> 
> filter {
> 
> if [type] == "kube-logs" {
> 
> ```
> mutate { rename => ["log", "message"] }
> 
> date {
> 
> match => ["time", "ISO8601"]
> 
> remove_field => ["time"]
> 
> }
> 
> grok {
> 
> match => { "source" => "/var/log/containers/%{DATA:pod_name}_%{DATA:namespace}_%{GREEDYDATA:container_name}-%{DATA:container_id}.log" }
> 
> remove_field => ["source"]
> 
> }
> 
> if [message] =~ /\d{15}/ {
> 
> grok {
> match => ["message","%{TIMESTAMP_ISO8601:date}\*\[%{LOGLEVEL:log-level}\]\*%{DATA:thread}\*%{DATA:class}\*%{DATA:method}\*%{DATA:imei}\*%{DATA:token}\*%{GREEDYDATA:messagedata}"] 		
> }
> }
> else {
>    
> grok {
> match => ["message","%{TIMESTAMP_ISO8601:date}\*\[%{LOGLEVEL:log-level}\]\*%{DATA:thread}\*%{DATA:class}\*%{DATA:method}\*%{GREEDYDATA:messagedata}"] 	
>     
> }
> }
> 
> ```
> 
> }
> 
> output {
> 
> ```
> elasticsearch { hosts => ['http://localhost:9200']}
> 
> ```
> 
> }

* * *

1. 0-9

---

<div class="post-metadata">

**Author:** ![jbudz](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jbudz/32/45922_2.png) [@jbudz](https://discuss.elastic.co/u/jbudz)\
**Post date:** [August 12, 2019, 9:32pm UTC](https://discuss.elastic.co/t/json-errors-in-kibana-5-5/193812/7 "2019-08-12T21:32:49Z")

</div>

Okay - I would start with the filebeat configuration here. Using multiline regexes and json parsing sounds like a decent recipe for parse errors. Do you have an example log of one of the failing errors?

---

<div class="post-metadata">

**Author:** ![irobot678](https://avatars.discourse-cdn.com/v4/letter/i/54ee81/32.png) [@irobot678](https://discuss.elastic.co/u/irobot678)\
**Post date:** [August 13, 2019, 5:52am UTC](https://discuss.elastic.co/t/json-errors-in-kibana-5-5/193812/8 "2019-08-13T05:52:21Z")

</div>

Thanks for the reply @jbudz ,

The requested failing logs are the following:

These logs are coming properly but the writing speed for these logs are so rapid.

Sometimes i am able get the log properly and few logs of these kind are getting into kibana with json\_errors.

Please help me solve it.

```
2019-08-13 05:44:13:581*[DEBUG]*CoapServer#11*org.eclipse.leshan.core.node.codec.DefaultLwM2mNodeDecoder*decodeTimestampedDataDecoding value for path /2050/0 and format ContentFormat [name=TLV, code=11542]: [-120, 2, 28, 72, 0, 25, -123, 1, 5, 57, -8, -37, 27, 0, 0, 1, 108, -120, 110, 102, -6, -125, 0, 2, -65, 0, 67, 37, 3, 0, -1]
2019-08-13 05:40:46:720*[DEBUG]*CoapServer#23*org.eclipse.leshan.server.cluster.RedisSecurityStore*getByEndpoint*990009621258709**
2019-08-13 05:38:15:936*[DEBUG]*pool-3-thread-1*org.eclipse.leshan.server.cluster.CassandraRegistrationStore*run*990009624192038**client cleaning regId:kswXQvQvOG check isAlive:true
2019-08-13 05:38:15:936*[DEBUG]*CoapServer#9*org.eclipse.leshan.server.californium.impl.RegisterResource*handlePOSTPOST received : CON-POST MID=47664, Token=30bae3e1, OptionSet={"Uri-Path":["rd","Xpjrs5wHN2"]}, no payload
```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 10, 2019, 5:52am UTC](https://discuss.elastic.co/t/json-errors-in-kibana-5-5/193812/9 "2019-09-10T05:52:23Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
