# JSON parse error, original data now in message field

**URL:** <https://discuss.elastic.co/t/json-parse-error-original-data-now-in-message-field/242459>\
**Category:** Logstash\
**Created:** [July 24, 2020, 6:20am UTC](https://discuss.elastic.co/t/json-parse-error-original-data-now-in-message-field/242459 "2020-07-24T06:20:31Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![nisaxena](https://avatars.discourse-cdn.com/v4/letter/n/ebca7d/32.png) [@nisaxena](https://discuss.elastic.co/u/nisaxena)\
**Post date:** [July 24, 2020, 6:20am UTC](https://discuss.elastic.co/t/json-parse-error-original-data-now-in-message-field/242459/1 "2020-07-24T06:20:32Z")

</div>

Hi There,

I am new to ELK, and need support. I have deployed a new ELK stack [7.8.0] & I am trying to ingest my rsyslogs to logstash. I am able to retrieve the logs to logstash but with following errors,

## logstash-plain.log ::

`[2020-07-24T06:10:53,644][WARN][logstash.codecs.jsonlines][main][e6516d264562b138b4d2764ccabf8f84f9868ff0172f7c414529beb343cb84d2] JSON parse error, original data now in message field {:error=\>#\<LogStash::Json::ParserError: Unexpected character ('' (code 92)): expected a valid value (number, String, array, object, 'true', 'false' or 'null')

## at [Source: (String)"\u0000\u0005\u0000\u0004\u0000\x9E\u0000\x9F\xC0|\xC0}\u00003\u0000g\u00009\u0000k\u0000E\u0000\xBE\u0000\x88\u0000\xC4\u0000\u0016\u0000\xA2\u0000\xA3\xC0\x80\xC0\x81\u00002\u0000@\u00008\u0000j\u0000D\u0000\xBD\u0000\x87\u0000\xC3\u0000\u0013\u0000f\u0001\u0000\u0000D\u0000\u0005\u0000\u0005\u0001\u0000\u0000\u0000\u0000\xFF\u0001\u0000\u0001\u0000\u0000#\u0000\u0000\u0000"; line: 1, column: 2]\>, :data=\>"\u0000\u0005\u0000\u0004\u0000\x9E\u0000\x9F\xC0|\xC0}\u00003\u0000g\u00009\u0000k\u0000E\u0000\xBE\u0000\x88\u0000\xC4\u0000\u0016\u0000\xA2\u0000\xA3\xC0\x80\xC0\x81\u00002\u0000@\u00008\u0000j\u0000D\u0000\xBD\u0000\x87\u0000\xC3\u0000\u0013\u0000f\u0001\u0000\u0000D\u0000\u0005\u0000\u0005\u0001\u0000\u0000\u0000\u0000\xFF\u0001\u0000\u0001\u0000\u0000#\u0000\u0000\u0000"}`

On Kibana Console ::

tags :: \_jsonparsefailure, \_grokparsefailure

logstash.conf ::

## Input

input {  
tcp {  
host =\> "X.X.X.X"  
port =\> 10514  
codec =\> "json"  
type =\> "syslog"  
}  
}

## Fileter

filter {  
if [type] == "syslog" {  
grok {  
match =\> { "message" =\> "%{SYSLOGTIMESTAMP:syslog\_timestamp} %{SYSLOGHOST:syslog\_hostname} %{DATA:syslog\_program}(?:[%{POSINT:syslog\_pid}])?: %{GREEDYDATA:syslog\_message}" }  
add\_field =\> ["received\_at", "%{@timestamp}"]  
add\_field =\> ["received\_from", "%{host}"]  
}  
date {  
match =\> ["syslog\_timestamp", "MMM d HH:mm:ss", "MMM dd HH:mm:ss"]  
}  
}  
}

## Output

output {  
if [type] == "syslog" {  
elasticsearch {  
hosts =\> ["127.0.0.1:9200"]  
index =\> "livelogs1"  
}  
}  
stdout { codec =\> rubydebug }  
}

Rsyslog Client Conf ::

## 70-output.conf

_._ @@X.X.X.X:10514;json-template

## 01-json-template.conf

template(name="json-template" type="list" option.json="on") {  
constant(value="{")  
constant(value=""@timestamp":"") property(name="timereported" dateFormat="rfc3339")  
constant(value="","@version":"1")  
constant(value="","message":"") property(name="msg")  
constant(value="","host":"") property(name="hostname")  
constant(value="","severity":"") property(name="syslogseverity-text")  
constant(value="","facility":"") property(name="syslogfacility-text")  
constant(value="","programname":"") property(name="programname")  
constant(value="","procid":"") property(name="procid")  
constant(value=""}\n")  
}

## /var/log/message ::

Jul 24 06:10:29 omcscefnbuycxm rsyslogd: unexpected GnuTLS error -110 in nsdsel\_gtls.c:178: The TLS connection was non-properly terminated. [v8.24.0-52.el7\_8.2 try [http://www.rsyslog.com/e/2078](http://www.rsyslog.com/e/2078) ]  
Jul 24 06:10:29 abc rsyslogd: netstream session 0x7fc9e00e4700 from 140.87.151.146 will be closed due to error [v8.24.0-52.el7\_8.2 try [http://www.rsyslog.com/e/2089](http://www.rsyslog.com/e/2089) ]  
Jul 24 06:10:34 xyz salt-minion: [ERROR] Error while bringing up minion for multi-master. Is master at [omcsceforvmjfz-pub.opc.oracleoutsourcing.com](http://omcsceforvmjfz-pub.opc.oracleoutsourcing.com) responding?  
Jul 24 06:10:39 pqr salt-minion: [ERROR] Error while bringing up minion for multi-master. Is master at [omcscefwqmianu-pub.opc.oracleoutsourcing.com](http://omcscefwqmianu-pub.opc.oracleoutsourcing.com) responding?`

---

<div class="post-metadata">

**Author:** ![kelk](https://avatars.discourse-cdn.com/v4/letter/k/13edae/32.png) [@kelk](https://discuss.elastic.co/u/kelk)\
**Post date:** [July 27, 2020, 7:26am UTC](https://discuss.elastic.co/t/json-parse-error-original-data-now-in-message-field/242459/2 "2020-07-27T07:26:50Z")

</div>

Are you using Beats to ingest into Logstash?

Try rsyslog to log it as file. Let's say you log into file `/var/log/ryslog/` for example

In Beats try

```auto
- type: log
  paths:
    - "/var/log/rsyslog/*.log"
  tags: ["syslog"]
  fields_under_root: true

```

Then try below setting in logstash

```auto
input {
  beats {
    port => 5000
    type => syslog
  }
}

```

---

<div class="post-metadata">

**Author:** ![nisaxena](https://avatars.discourse-cdn.com/v4/letter/n/ebca7d/32.png) [@nisaxena](https://discuss.elastic.co/u/nisaxena)\
**Post date:** [July 27, 2020, 9:09am UTC](https://discuss.elastic.co/t/json-parse-error-original-data-now-in-message-field/242459/3 "2020-07-27T09:09:03Z")

</div>

Hi Kin,

Thanks for your response.

I am not using filebeat for shipping logs data. I had configured rsyslog OS daemon to forward logs to logstash at 10514 (TCP) in json format using template.

---

<div class="post-metadata">

**Author:** ![kelk](https://avatars.discourse-cdn.com/v4/letter/k/13edae/32.png) [@kelk](https://discuss.elastic.co/u/kelk)\
**Post date:** [July 27, 2020, 10:00am UTC](https://discuss.elastic.co/t/json-parse-error-original-data-now-in-message-field/242459/4 "2020-07-27T10:00:54Z")

</div>

hmm.. never tried directly as I always used to write to file using rsyslog and collect inwards using beats.

Have a try by putting within inputs

```auto
        codec => line {
         charset => "UTF-8"
         }  

```

if still doesn't work, try with a higher log level (use `--log.level debug` on the command line or its equivalent) and posting several of the logging lines before and after the error you're encountering.

---

<div class="post-metadata">

**Author:** ![Fabio-sama](https://avatars.discourse-cdn.com/v4/letter/f/b9e5f3/32.png) [@Fabio-sama](https://discuss.elastic.co/u/Fabio-sama)\
**Post date:** [July 27, 2020, 3:22pm UTC](https://discuss.elastic.co/t/json-parse-error-original-data-now-in-message-field/242459/5 "2020-07-27T15:22:17Z")

</div>

Hi there,

first of all please try to use the code formatter tool `</>` when pasting something which is not plain text, otherwise your message will be difficult to read and understand.

Anyway, can you paste here the results of the following pipeline?

```
input {
  tcp {
    host => "X.X.X.X"
    port => 10514
    codec => "json"
    type => "syslog"
  }
}

filter {}

output {
  stdout{}
}

```

This way we should be able to see exactly what logstash is receiving.

---

<div class="post-metadata">

**Author:** ![nisaxena](https://avatars.discourse-cdn.com/v4/letter/n/ebca7d/32.png) [@nisaxena](https://discuss.elastic.co/u/nisaxena)\
**Post date:** [July 29, 2020, 5:07am UTC](https://discuss.elastic.co/t/json-parse-error-original-data-now-in-message-field/242459/6 "2020-07-29T05:07:04Z")

</div>

> [@kelk](#):
>
> `charset => "UTF-8"`

Had tried this option, but did't worked for me.

---

<div class="post-metadata">

**Author:** ![nisaxena](https://avatars.discourse-cdn.com/v4/letter/n/ebca7d/32.png) [@nisaxena](https://discuss.elastic.co/u/nisaxena)\
**Post date:** [July 29, 2020, 5:09am UTC](https://discuss.elastic.co/t/json-parse-error-original-data-now-in-message-field/242459/7 "2020-07-29T05:09:26Z")

</div>

Will try it, and come back with logs.

---

<div class="post-metadata">

**Author:** ![nisaxena](https://avatars.discourse-cdn.com/v4/letter/n/ebca7d/32.png) [@nisaxena](https://discuss.elastic.co/u/nisaxena)\
**Post date:** [August 4, 2020, 2:12pm UTC](https://discuss.elastic.co/t/json-parse-error-original-data-now-in-message-field/242459/9 "2020-08-04T14:12:13Z")

</div>

Hi Fabio,

Here is output,

{  
"message" =\> "\u0016\u0003\u0001\u0000\xED\u0001\u0000\u0000\xE9\u0003\u0003\_)k\u0015:\xE5w\x9B\*\xC1W\xA9\u000E\xD5\u0011\et\xA0͖\xD8粣Q\xE40\x8E0E\xF9\x99\u0000\u0000|\xC0+\xC0,\xC0\x86\xC0\x87\xC0\t\xC0#\xC0",  
"@version" =\> "1",  
"port" =\> 53246,  
"@timestamp" =\> 2020-08-04T14:05:06.887Z,  
"type" =\> "syslog",  
"tags" =\> [  
[0] "\_jsonparsefailure"  
],  
"host" =\> "130.61.40.7"  
}  
{  
"message" =\> "\u0000\u0005\u0000\u0004\u0000\x9E\u0000\x9F\xC0|\xC0}\u00003\u0000g\u00009\u0000k\u0000E\u0000\xBE\u0000\x88\u0000\xC4\u0000\u0016\u0000\xA2\u0000\xA3\xC0\x80\xC0\x81\u00002\u0000@\u00008\u0000j\u0000D\u0000\xBD\u0000\x87\u0000\xC3\u0000\u0013\u0000f\u0001\u0000\u0000D\u0000\u0005\u0000\u0005\u0001\u0000\u0000\u0000\u0000\xFF\u0001\u0000\u0001\u0000\u0000#\u0000\u0000\u0000",  
"@version" =\> "1",  
"port" =\> 53246,  
"@timestamp" =\> 2020-08-04T14:05:06.913Z,  
"type" =\> "syslog",  
"tags" =\> [  
[0] "\_jsonparsefailure"  
],  
"host" =\> "130.61.40.7"  
}

Thanks,

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 1, 2020, 2:12pm UTC](https://discuss.elastic.co/t/json-parse-error-original-data-now-in-message-field/242459/10 "2020-09-01T14:12:14Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
