# Json.ignore\_decoding\_error: true automatically enables json processing for everything?

**URL:** <https://discuss.elastic.co/t/json-ignore-decoding-error-true-automatically-enables-json-processing-for-everything/311721>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [August 9, 2022, 12:06pm UTC](https://discuss.elastic.co/t/json-ignore-decoding-error-true-automatically-enables-json-processing-for-everything/311721 "2022-08-09T12:06:20Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Kosodrom](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kosodrom/32/99278_2.png) [@Kosodrom](https://discuss.elastic.co/u/Kosodrom)\
**Post date:** [August 9, 2022, 12:06pm UTC](https://discuss.elastic.co/t/json-ignore-decoding-error-true-automatically-enables-json-processing-for-everything/311721/1 "2022-08-09T12:06:20Z")

</div>

Hi folks,

On our openshift clusters we have a wide range of applications and workloads running, which write logs in different ways.

If some developers write logs in json we want to enable them to annotate their workloads and to indicate that they want to have their json logs parsed into fields. At the same time, we don't want to know and to be involved in this configuration. Therefore we want to use hint based autodiscover. As far as I understand this is exactly what it is made for.

The reality is just: It does happen that some pods are still annotated with json annotations, but do not write json logs anymore for some reason. This results in spamming errors:

`ERROR [reader_json] readjson/json.go:74 Error decoding JSON`

You can suppress this error by giving: `json.ignore_decoding_error: true` but it seems that once you set it, Filebeat starts to parse **ALL** json logs that are coming, even from pods that are not annotated. This leads to mapping explosions, mapping conflicts and crazy management overhead.

1. Question: Do I understand correct that json.ignore\_decoding\_error: true, enabled json processor for all logs?
2. Question: Is it possible to suppress `ERROR [reader_json] readjson/json.go:74 Error decoding JSON` without enabling json processor for everything and just let hint based autodiscover work.

Thanks

---

<div class="post-metadata">

**Author:** ![jsoriano](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jsoriano/32/27920_2.png) [@jsoriano](https://discuss.elastic.co/u/jsoriano)\
**Post date:** [August 22, 2022, 2:59pm UTC](https://discuss.elastic.co/t/json-ignore-decoding-error-true-automatically-enables-json-processing-for-everything/311721/2 "2022-08-22T14:59:13Z")

</div>

Hey @Kosodrom,

What is the input configuration you are using? Would it be possible to use two different inputs, one for the json files and another one for the rest?

---

<div class="post-metadata">

**Author:** ![Kosodrom](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kosodrom/32/99278_2.png) [@Kosodrom](https://discuss.elastic.co/u/Kosodrom)\
**Post date:** [September 5, 2022, 10:15am UTC](https://discuss.elastic.co/t/json-ignore-decoding-error-true-automatically-enables-json-processing-for-everything/311721/3 "2022-09-05T10:15:53Z")

</div>

Hi,

Thanks for the response. Yes it would be possible of course. What I am doing now is: I drop all logs from my container, which contain this message:

```auto
  - drop_event:
      when:
        contains:
          message: "Error decoding JSON"

```

I was just curious if the described behavior is an expected one.

From my point of view setting `json.ignore_decoding_error: true` should not enable `decode_json_fields` processor.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 3, 2022, 12:16pm UTC](https://discuss.elastic.co/t/json-ignore-decoding-error-true-automatically-enables-json-processing-for-everything/311721/4 "2022-10-03T12:16:50Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
