# JSON parse error, original data now in message field, even though its a valid json

**URL:** <https://discuss.elastic.co/t/json-parse-error-original-data-now-in-message-field-even-though-its-a-valid-json/149033>\
**Category:** Logstash\
**Created:** [September 18, 2018, 11:57pm UTC](https://discuss.elastic.co/t/json-parse-error-original-data-now-in-message-field-even-though-its-a-valid-json/149033 "2018-09-18T23:57:52Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![gopalkakularam](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/gopalkakularam/32/35649_2.png) [@gopalkakularam](https://discuss.elastic.co/u/gopalkakularam)\
**Post date:** [September 18, 2018, 11:57pm UTC](https://discuss.elastic.co/t/json-parse-error-original-data-now-in-message-field-even-though-its-a-valid-json/149033/1 "2018-09-18T23:57:52Z")

</div>

This is the json log posting to logstash:

{  
"@version" : 1,  
"source\_host" : "Gopals-MacBook-Pro-3.local",  
"message" : "Loading source class org.springframework.cloud.bootstrap.config.PropertySourceBootstrapConfiguration,class org.springframework.cloud.bootstrap.encrypt.EncryptionBootstrapConfiguration,class org.springframework.cloud.autoconfigure.ConfigurationPropertiesRebinderAutoConfiguration,class org.springframework.boot.autoconfigure.context.PropertyPlaceholderAutoConfiguration, org.springframework.cloud.config.client.ConfigServiceBootstrapConfiguration,class org.springframework.cloud.config.client.DiscoveryClientConfigServiceBootstrapConfiguration",  
"thread\_name" : "main",  
"@timestamp" : "2018-09-18T15:10:01.125-07:00",  
"level" : "DEBUG",  
"logger\_name" : "org.springframework.boot.SpringApplication"  
}

But in logstash logs, I could see below parsing error, even though its a valid json.

[2018-09-18T15:10:01,140][WARN][logstash.codecs.jsonlines] JSON parse error, original data now in message field {:error=\>#\<LogStash::Json::ParserError: Unexpected end-of-input: expected close marker for Object (start marker at [Source: (String)"{"; line: 1, column: 1])

at [Source: (String)"{"; line: 1, column: 3]\>, :data=\>"{"}

[2018-09-18T15:10:01,141][WARN][logstash.codecs.jsonlines] JSON parse error, original data now in message field {:error=\>#\<LogStash::Json::ParserError: incompatible json object type=java.lang.String , only hash map or arrays are supported\>, :data=\>" "@version" : 1,"}

[2018-09-18T15:10:01,146][WARN][logstash.codecs.jsonlines] JSON parse error, original data now in message field {:error=\>#\<LogStash::Json::ParserError: incompatible json object type=java.lang.String , only hash map or arrays are supported\>, :data=\>" "source\_host" : "Gopals-MacBook-Pro-3.local","}

[2018-09-18T15:10:01,147][WARN][logstash.codecs.jsonlines] JSON parse error, original data now in message field {:error=\>#\<LogStash::Json::ParserError: incompatible json object type=java.lang.String , only hash map or arrays are supported\>, :data=\>" "message" : "Loading source class org.springframework.cloud.bootstrap.config.PropertySourceBootstrapConfiguration,class org.springframework.cloud.bootstrap.encrypt.EncryptionBootstrapConfiguration,class org.springframework.cloud.autoconfigure.ConfigurationPropertiesRebinderAutoConfiguration,class org.springframework.boot.autoconfigure.context.PropertyPlaceholderAutoConfiguration,class, org.springframework.cloud.config.client.ConfigServiceBootstrapConfiguration,class org.springframework.cloud.config.client.DiscoveryClientConfigServiceBootstrapConfiguration","}

[2018-09-18T15:10:01,148][WARN][logstash.codecs.jsonlines] JSON parse error, original data now in message field {:error=\>#\<LogStash::Json::ParserError: incompatible json object type=java.lang.String , only hash map or arrays are supported\>, :data=\>" "thread\_name" : "main","}

[2018-09-18T15:10:01,149][WARN][logstash.codecs.jsonlines] JSON parse error, original data now in message field {:error=\>#\<LogStash::Json::ParserError: incompatible json object type=java.lang.String , only hash map or arrays are supported\>, :data=\>" "@timestamp" : "2018-09-18T15:10:01.125-07:00","}

[2018-09-18T15:10:01,150][WARN][logstash.codecs.jsonlines] JSON parse error, original data now in message field {:error=\>#\<LogStash::Json::ParserError: incompatible json object type=java.lang.String , only hash map or arrays are supported\>, :data=\>" "level" : "DEBUG","}

[2018-09-18T15:10:01,150][WARN][logstash.codecs.jsonlines] JSON parse error, original data now in message field {:error=\>#\<LogStash::Json::ParserError: incompatible json object type=java.lang.String , only hash map or arrays are supported\>, :data=\>" "logger\_name" : "org.springframework.boot.SpringApplication""}

[2018-09-18T15:10:01,151][WARN][logstash.codecs.jsonlines] JSON parse error, original data now in message field {:error=\>#\<LogStash::Json::ParserError: Unexpected close marker '}': expected ']' (for root starting at [Source: (String)"}"; line: 1, column: 0])

at [Source: (String)"}"; line: 1, column: 2]\>, :data=\>"}"}

logstash-simple.conf:

input {

tcp {

port =\> 4560

codec =\> json\_lines

}

}

output {

elasticsearch { hosts =\> ['localhost:9200'] }

}

output {

stdout {

codec =\> rubydebug

}

}

I have tried with codec json, json\_line and filter with json.

---

<div class="post-metadata">

**Author:** ![guyboertje](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/guyboertje/32/31592_2.png) [@guyboertje](https://discuss.elastic.co/u/guyboertje)\
**Post date:** [September 25, 2018, 1:26pm UTC](https://discuss.elastic.co/t/json-parse-error-original-data-now-in-message-field-even-though-its-a-valid-json/149033/2 "2018-09-25T13:26:57Z")

</div>

You are trying to parse pretty printed JSON.

The default codec for the tcp input is `lines`, this will create an event for every line in the tcp payload as will the json and json\_lines codecs. The json parser itself cannot parse one line from a pretty printed JSON string e.g. `{` or `"source_host" : "Gopals-MacBook-Pro-3.local",`

**Use the plain codec in the tcp input to capture the full payload into one message field and then the json filter to parse the full payload message.**

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 23, 2018, 1:27pm UTC](https://discuss.elastic.co/t/json-parse-error-original-data-now-in-message-field-even-though-its-a-valid-json/149033/3 "2018-10-23T13:27:10Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
