# Json import error on elasticsearch with curl command

**URL:** <https://discuss.elastic.co/t/json-import-error-on-elasticsearch-with-curl-command/129668>\
**Category:** Elasticsearch\
**Created:** [April 26, 2018, 12:48pm UTC](https://discuss.elastic.co/t/json-import-error-on-elasticsearch-with-curl-command/129668 "2018-04-26T12:48:53Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![Enonimous8](https://avatars.discourse-cdn.com/v4/letter/e/c37758/32.png) [@Enonimous8](https://discuss.elastic.co/u/Enonimous8)\
**Post date:** [April 26, 2018, 12:48pm UTC](https://discuss.elastic.co/t/json-import-error-on-elasticsearch-with-curl-command/129668/1 "2018-04-26T12:48:53Z")

</div>

Hi, I have a problem when load a json file on elasticsearch with curl command.  
The json file is this:  
[https://drive.google.com/file/d/13nCXdIY1n096SSWcL36TEtqkGTVhn28o/view?usp=sharing](https://drive.google.com/file/d/13nCXdIY1n096SSWcL36TEtqkGTVhn28o/view?usp=sharing)

When I launch this command:  
`curl -H 'Content-Type:application/json' -XPOST "localhost:9200/pacchetti3/doc/_bulk?pretty" --data-binary @C:\Users\Thebe\Desktop\singolopacchetto.json`

I received this error:  
{  
"error" : {  
"root\_cause" : [  
{  
"type" : "json\_e\_o\_f\_exception",  
"reason" : "Unexpected end-of-input: expected close marker for Object (start marker at [Source: org.elasticsearch.transport.netty4.ByteBufStreamInput@3c861e6a; line: 1, column: 1])\n at [Source: org.elasticsearch.transport.netty4.ByteBufStreamInput@3c861e6a; line: 2, column: 3]"  
}  
],  
"type" : "json\_e\_o\_f\_exception",  
"reason" : "Unexpected end-of-input: expected close marker for Object (start marker at [Source: org.elasticsearch.transport.netty4.ByteBufStreamInput@3c861e6a; line: 1, column: 1])\n at [Source: org.elasticsearch.transport.netty4.ByteBufStreamInput@3c861e6a; line: 2, column: 3]"  
},  
"status" : 500  
}

I checked if the json is well formatted on the site [https://jsonformatter.curiousconcept.com/](https://jsonformatter.curiousconcept.com/) and the answer is positive.

The version of elasticsearch and kibana I'm using is 5.6.9  
What is the problem? And how can I solve?

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [April 26, 2018, 12:56pm UTC](https://discuss.elastic.co/t/json-import-error-on-elasticsearch-with-curl-command/129668/2 "2018-04-26T12:56:04Z")

</div>

As you are using the bulk API, have you formatted the file according to the [requirements of this API](https://www.elastic.co/guide/en/elasticsearch/reference/6.2/docs-bulk.html)?

---

<div class="post-metadata">

**Author:** ![Enonimous8](https://avatars.discourse-cdn.com/v4/letter/e/c37758/32.png) [@Enonimous8](https://discuss.elastic.co/u/Enonimous8)\
**Post date:** [April 26, 2018, 1:43pm UTC](https://discuss.elastic.co/t/json-import-error-on-elasticsearch-with-curl-command/129668/3 "2018-04-26T13:43:15Z")

</div>

Yes, I tried to format it according to the Bulk API (at least I think). The result is this:

```
{"index":{"_index":"pacchetti3"}}
{
  "_type": "pcap_file",
  "_score": null,
  "_source": {
    "layers": {
      "frame": {
        "frame.interface_id": "0",
        "frame.interface_id_tree": {
          "frame.interface_name": "any"
        },
        "frame.encap_type": "25",
             ....
             ....
        }
      }
    }
  }
}

```

This time the error is this:

```
{
  "error" : {
    "root_cause" : [
      {
        "type" : "illegal_argument_exception",
        "reason" : "Malformed action/metadata line [3], expected START_OBJECT but found [VALUE_STRING]"
      }
    ],
    "type" : "illegal_argument_exception",
    "reason" : "Malformed action/metadata line [3], expected START_OBJECT but found [VALUE_STRING]"
  },
  "status" : 400
}

```

What am I doing wrong?

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [April 26, 2018, 1:51pm UTC](https://discuss.elastic.co/t/json-import-error-on-elasticsearch-with-curl-command/129668/4 "2018-04-26T13:51:42Z")

</div>

Each header and document must be on a single line and the document should not contain `_type`, `_score` or `_source` fields. You may also run into problems as you have dots in your field names.

---

<div class="post-metadata">

**Author:** ![Enonimous8](https://avatars.discourse-cdn.com/v4/letter/e/c37758/32.png) [@Enonimous8](https://discuss.elastic.co/u/Enonimous8)\
**Post date:** [April 26, 2018, 2:11pm UTC](https://discuss.elastic.co/t/json-import-error-on-elasticsearch-with-curl-command/129668/5 "2018-04-26T14:11:31Z")

</div>

I followed the advice, the json file I formatted it as follows:  
`{"index":{"_index":"pacchetti3"}} {"layers":{"frame":{"frame.interface_id":"0","frame.interface_id_tree":{ ... }}}}`

However the problem persists with a new error:  
{  
"error" : {  
"root\_cause" : [  
{  
"type" : "action\_request\_validation\_exception",  
"reason" : "Validation Failed: 1: no requests added;"  
}  
],  
"type" : "action\_request\_validation\_exception",  
"reason" : "Validation Failed: 1: no requests added;"  
},  
"status" : 400  
}

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [April 26, 2018, 2:33pm UTC](https://discuss.elastic.co/t/json-import-error-on-elasticsearch-with-curl-command/129668/6 "2018-04-26T14:33:34Z")

</div>

That does not seem to be the format specified in the documentation. The file should look something like this, with a newline after each line:

```auto
{ "index" : { "_index" : "pacchetti3", "_type" : "doc" } }
{ "field1" : "value1" }
{ "index" : { "_index" : "pacchetti3", "_type" : "doc" } }
{ "field1" : "value2" }

```

---

<div class="post-metadata">

**Author:** ![Enonimous8](https://avatars.discourse-cdn.com/v4/letter/e/c37758/32.png) [@Enonimous8](https://discuss.elastic.co/u/Enonimous8)\
**Post date:** [April 26, 2018, 3:01pm UTC](https://discuss.elastic.co/t/json-import-error-on-elasticsearch-with-curl-command/129668/7 "2018-04-26T15:01:40Z")

</div>

Thanks!  
I did a test by formatting only a couple of lines of my json:  
{"index":{"\_index":"pacchetti4", "\_type": "doc"}}  
{"frame.interface\_id": "0", "frame.interface\_name": "any", "frame.encap\_type": "25", "frame.time": "Apr 20, 2018 15:30:52.669797277 ora legale Europa occidentale", "frame.number": "1", "frame.len": "649", "frame.cap\_len": "649", "frame.marked": "0", "frame.ignored": "0", "frame.protocols": "sll:ethertype:ip:tcp:http:json", "frame.coloring\_rule.name": "HTTP", "frame.coloring\_rule.string": "http || tcp.port == 80 || http2"}  
{"index":{"\_index":"pacchetti4", "\_type": "doc"}}  
{"sll.pkttype": "0", "sll.hatype": "772", "sll.halen": "6"}  
{"index":{"\_index":"pacchetti4", "\_type": "doc"}}  
{"ip.version": "4", "ip.hdr\_len": "20", "ip.dsfield": "0x00000000", "ip.dsfield.dscp": "0", "ip.dsfield.ecn": "0", "ip.len": "633", "ip.id": "0x0000b60a", "ip.flags": "0x00000002", "ip.frag\_offset": "0", "ip.ttl": "64", "ip.proto": "6", "ip.checksum": "0x00008472", "ip.checksum.status": "2", "ip.src": "127.0.0.1", "ip.addr": "127.0.0.1", "ip.src\_host": "127.0.0.1", "ip.host": "127.0.0.1", "ip.dst": "127.0.0.1", "ip.dst\_host": "127.0.0.1", "Source GeoIP: Unknown": "", "Destination GeoIP: Unknown": ""}

It was finally loaded. Once this problem is solved, I would like to know if there is a simple way to quickly format a much larger json (at the beginning of the topic I have only shown one, but in reality there are about 400.000).

How can I do?

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [April 26, 2018, 3:42pm UTC](https://discuss.elastic.co/t/json-import-error-on-elasticsearch-with-curl-command/129668/8 "2018-04-26T15:42:49Z")

</div>

If you have the data formatted as a JSON object per line, you can use Logstash or one of the language to script the ingestion. You generally want to limit the size of each bulk request to around 5MB or so, and then send multiple requests to Elasticsearch in parallel.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 24, 2018, 3:42pm UTC](https://discuss.elastic.co/t/json-import-error-on-elasticsearch-with-curl-command/129668/9 "2018-05-24T15:42:55Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
