# Json file not parsing getting error unexpected character (':'' (code 58))

**URL:** <https://discuss.elastic.co/t/json-file-not-parsing-getting-error-unexpected-character-code-58/309323>\
**Category:** Logstash\
**Created:** [July 11, 2022, 1:10pm UTC](https://discuss.elastic.co/t/json-file-not-parsing-getting-error-unexpected-character-code-58/309323 "2022-07-11T13:10:41Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![Mary2022](https://avatars.discourse-cdn.com/v4/letter/m/e8c25b/32.png) [@Mary2022](https://discuss.elastic.co/u/Mary2022)\
**Post date:** [July 11, 2022, 1:10pm UTC](https://discuss.elastic.co/t/json-file-not-parsing-getting-error-unexpected-character-code-58/309323/1 "2022-07-11T13:10:41Z")

</div>

I have json files coming in the following format:

```auto
[
	{
		"user": "Beta",
		"percent": 28,
		"startTime": "2022-07-07T11:31:45",
		"type": "CPU",
		"total": 1072987793,
		"Location": "locationB",
		"desk": "MAC"
	},
	{
		"user": "Alpha",
		"percent": 86,
		"startTime": "2022-07-07T11:31:45",
		"type": "CPU",
		"total": 1072987733,
		"Location": "locationA",
		"desk": "LIN"
	},

	{
		"user": "Charlie",
		"percent": 03,
		"startTime": "2022-07-07T11:31:45",
		"type": "CPU",
		"total": 1072987724,
		"Location": "locationA",
		"desk": "LIN"
	},

	{
		"user": "test",
		"percent": 15,
		"startTime": "2022-07-07T11:31:45",
		"type": "CPU",
		"total": 1072987778,
		"Location": "locationB",
		"desk": "MAC"
	},

	{
		"user": "Delta",
		"percent": 28,
		"startTime": "2022-07-07T11:31:45",
		"type": "CPU",
		"total": 1072987793,
		"Location": "location1",
		"desk": "MAC"
	},

	{
		"user": "Juliana",
		"percent": 28,
		"startTime": "2022-07-07T11:31:45",
		"type": "CPU",
		"total": 1072987793,
		"Location": "location1",
		"desk": "MAC"
	}
]

```

This is my input:

```auto
input {
	http {
		port => 8287
		ssl => true
		ssl_certificate_authorities => ["xxxxxxxxxxxxxxxx.crt"]
		ssl_certificate => "path.crt"
		ssl_key => "xxxxxxxxxxxxxxxxxx"
		ssl_verify_mode => peer
	}
}

filter {
	grok {
	match => { "desktop" => "(?<site>^.{2}%{DATA}-%{DATA}%{INT:pod}%{GREEDYDATA}" }
	}
	json {source => "message"}
	
	mutate {
	add_field => { 'processed_at' => "%{@timestamp}" }
	remove_field => ["headers"]
	}

	date {
		match => ['startTime', "yyyy-MM-dd'T'HH:mm:ss", "ISO8601"]
		remove_field => ['startTime']
	}
}

output {

elasticsearch {
	hosts=>["https:xxxxxx:9200, "https:xxxxxx:9200]
	index => "testCM"
	user => XXXX
	password => "xxxxxxxxx"
	keystore => "xxxx.jks"
	keystore_password => "xxxxxx"
	cacert => "xxxxxxxxxxxxx.crt"
	}
}

```

---

<div class="post-metadata">

**Author:** ![Rios](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rios/32/95745_2.png) [@Rios](https://discuss.elastic.co/u/Rios)\
**Post date:** [July 11, 2022, 3:05pm UTC](https://discuss.elastic.co/t/json-file-not-parsing-getting-error-unexpected-character-code-58/309323/2 "2022-07-11T15:05:19Z")

</div>

> [@Mary2022](#):
>
> `hosts=>["https:xxxxxx:9200, "https:xxxxxx:9200]`

Quote at the end is missing by copy+paste or in the original configuration?

---

<div class="post-metadata">

**Author:** ![Mary2022](https://avatars.discourse-cdn.com/v4/letter/m/e8c25b/32.png) [@Mary2022](https://discuss.elastic.co/u/Mary2022)\
**Post date:** [July 11, 2022, 3:18pm UTC](https://discuss.elastic.co/t/json-file-not-parsing-getting-error-unexpected-character-code-58/309323/3 "2022-07-11T15:18:28Z")

</div>

I had to re-typed the config here but the original has the double quotes. The file gets to Elastic and Kibana but it doesntparse right. When I query the index this one dont have the objects and/or values.

---

<div class="post-metadata">

**Author:** ![Rios](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rios/32/95745_2.png) [@Rios](https://discuss.elastic.co/u/Rios)\
**Post date:** [July 11, 2022, 3:26pm UTC](https://discuss.elastic.co/t/json-file-not-parsing-getting-error-unexpected-character-code-58/309323/4 "2022-07-11T15:26:26Z")

</div>

Few tips:  
Check how does your json arrive, usually should be in the message field.  
Are you sure that the field named desktop is OK?  
grok { match =\> { " **desktop**" ?  
As fair as I can remember, you should remove square brackets _[]_ from JSON message.  
Use only debug in output:

```auto
output {
   stdout { codec => rubydebug{} }
}

```

---

<div class="post-metadata">

**Author:** ![Mary2022](https://avatars.discourse-cdn.com/v4/letter/m/e8c25b/32.png) [@Mary2022](https://discuss.elastic.co/u/Mary2022)\
**Post date:** [July 11, 2022, 4:28pm UTC](https://discuss.elastic.co/t/json-file-not-parsing-getting-error-unexpected-character-code-58/309323/5 "2022-07-11T16:28:29Z")

</div>

```auto
type or paste code here

[
	{
		"user": "Beta",
		"percent": 28,
		"startTime": "2022-07-07T11:31:45",
		"type": "CPU",
		"total": 1072987793,
		"Location": "locationB",
		"desktopGR": "MAC"
	},
	{
		"user": "Alpha",
		"percent": 86,
		"startTime": "2022-07-07T11:31:45",
		"type": "CPU",
		"total": 1072987733,
		"Location": "locationA",
		"desktopGR": "LIN"
	},

	{
		"user": "Charlie",
		"percent": 03,
		"startTime": "2022-07-07T11:31:45",
		"type": "CPU",
		"total": 1072987724,
		"Location": "locationA",
		"desktopGR": "LIN"
	},

	{
		"user": "test",
		"percent": 15,
		"startTime": "2022-07-07T11:31:45",
		"type": "CPU",
		"total": 1072987778,
		"Location": "locationB",
		"desktopGR": "MAC"
	},

	{
		"user": "Delta",
		"percent": 28,
		"startTime": "2022-07-07T11:31:45",
		"type": "CPU",
		"total": 1072987793,
		"Location": "location1",
		"desktopGR": "MAC"
	},

	{
		"user": "Juliana",
		"percent": 28,
		"startTime": "2022-07-07T11:31:45",
		"type": "CPU",
		"total": 1072987793,
		"Location": "location1",
		"desktopGR": "MAC"
	}
]

```

I fixed the jsonfile I forgot to put the whole name.

I previously removed the brackets manually and try to test it using another input (file) but still the same. The message appears has it but it is not storing the objects.

---

<div class="post-metadata">

**Author:** ![Mary2022](https://avatars.discourse-cdn.com/v4/letter/m/e8c25b/32.png) [@Mary2022](https://discuss.elastic.co/u/Mary2022)\
**Post date:** [July 21, 2022, 10:58am UTC](https://discuss.elastic.co/t/json-file-not-parsing-getting-error-unexpected-character-code-58/309323/6 "2022-07-21T10:58:09Z")

</div>

The whole array is ending in the message field.  
What exactly will the codec rubydebug will do for the output?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 18, 2022, 10:58am UTC](https://discuss.elastic.co/t/json-file-not-parsing-getting-error-unexpected-character-code-58/309323/7 "2022-08-18T10:58:18Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
