# JSON parse error, original data now in message field

**URL:** <https://discuss.elastic.co/t/json-parse-error-original-data-now-in-message-field/93163>\
**Category:** Logstash\
**Created:** [July 14, 2017, 10:08am UTC](https://discuss.elastic.co/t/json-parse-error-original-data-now-in-message-field/93163 "2017-07-14T10:08:36Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![runtman](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/runtman/32/18136_2.png) [@runtman](https://discuss.elastic.co/u/runtman)\
**Post date:** [July 14, 2017, 10:08am UTC](https://discuss.elastic.co/t/json-parse-error-original-data-now-in-message-field/93163/1 "2017-07-14T10:08:36Z")

</div>

Hello, I am getting the following error with looking at edgemax router logs:

```
[2017-07-14T09:52:00,502][ERROR][logstash.codecs.json] JSON parse error, original data now in message field {:error=>#<LogStash::Json::ParserError: Unexpected character ('<' (code 60)): expected a valid value (number, String, array, object, 'true', 'false' or 'null')
 at [Source: <4>Jul 14 09:52:00 192.168.1.10 ("U7PG2,44d9e7fc1de2,v3.4.18.346 kernel: [6292100.680000] [wifi1] FWLOG: [616713] WAL_DBGID_TX_BA_SETUP ( 0x435940, 0x6, 0x0, 0x2, 0x0 ); line: 1, column: 2]>, :data=>"<4>Jul 14 09:52:00 192.168.1.10 (\"U7PG2,44d9e7fc1de2,v3.4.18.346 kernel: [6292100.680000] [wifi1] FWLOG: [616713] WAL_DBGID_TX_BA_SETUP ( 0x435940, 0x6, 0x0, 0x2, 0x0 )"}

```

However when I use a grok debugger:

[https://grokdebug.herokuapp.com/](https://grokdebug.herokuapp.com/)

I get no reported errors?

My config for the logs are as follows:

```
input {
  udp {
    host => "xxx"
    port => 10514
    codec => "json"
    type => "rsyslog"
  }
}

filter {
  if [type] == "rsyslog" {
    grok {
      match => { "message" => "<%{POSINT:syslog_pri}>%{SYSLOGTIMESTAMP:syslog_timestamp} %{SYSLOGHOST:syslog_hostname} %{DATA:syslog_program}(?:\[%{POSINT:syslog_pid}\])?: %{GREEDYDATA:syslog_message}" }
      add_field => ["received_at", "%{@timestamp}"]
      add_field => ["received_from", "%{host}"]
    }
    grok {
      match => { "message" => "<%{POSINT:syslog_pri}>%{SYSLOGTIMESTAMP:syslog_timestamp} %{SYSLOGHOST:syslog_hostname} %{GREEDYDATA:syslog_message}" }
      add_field => ["received_at", "%{@timestamp}"]
      add_field => ["received_from", "%{host}"]
    }
    syslog_pri { }
    date {
      match => ["syslog_timestamp", "MMM d HH:mm:ss", "MMM dd HH:mm:ss"]
    }
    mutate {
    add_tag => ["syslog_default_filter"]
    }
  }
}

  if [message] =~ /(WAN_OUT|WAN_LOCAL|WAN_IN)/ {
    grok {
    match => { "message" => "\[%{DATA:firewall_rule}\]IN=%{DATA:firewall_in_interface} OUT=%{DATA:firewall_out_interface} MAC=%{DATA:firewall_src_mac} SRC=%{IPV4:firewall_src_ip} DST=%{IPV4:firewall_dst_ip} LEN=%{NUMBER:firewall_len} TOS=%{DATA:firewall_tos} PREC=%{DATA:firewall_prec} TTL=%{NUMBER:firewall_ttl} ID=%{NUMBER:firewall_id} DF PROTO=%{WORD:firewall_protocol} SPT=%{NUMBER:firewall_source_port} DPT=%{NUMBER:firewall_destination_port} WINDOW=%{NUMBER:firewall_window} RES=%{DATA:firewall_res} SYN URGP=%{NUMBER:firewall_urgp}" }
    match => { "message" => "\[%{DATA:firewall_rule}\]IN=%{DATA:firewall_in_interface} OUT=%{DATA:firewall_out_interface} MAC=%{DATA:firewall_src_mac} SRC=%{IPV4:firewall_src_ip} DST=%{IPV4:firewall_dst_ip} LEN=%{NUMBER:firewall_len} TOS=%{DATA:firewall_tos} PREC=%{DATA:firewall_prec} TTL=%{NUMBER:firewall_ttl} ID=%{NUMBER:firewall_id} DF PROTO=%{WORD:firewall_protocol} SPT=%{NUMBER:firewall_source_port} DPT=%{NUMBER:firewall_destination_port} LEN=%{NUMBER:firewall_len}" }
    match => { "message" => "\[%{DATA:firewall_rule}\]IN=%{DATA:firewall_in_interface} OUT=%{DATA:firewall_out_interface} MAC=%{DATA:firewall_src_mac} SRC=%{IPV4:firewall_src_ip} DST=%{IPV4:firewall_dst_ip} LEN=%{NUMBER:firewall_len} TOS=%{DATA:firewall_tos} TTL=%{NUMBER:firewall_ttl} ID=%{NUMBER:firewall_id} PROTO=%{WORD:firewall_protocol} SPT=%{NUMBER:firewall_source_port} DPT=%{NUMBER:firewall_destination_port} LEN=%{NUMBER:firewall_len2}" }
    }
    mutate {
      add_tag => ["router_firewall_filter"]
    }
  }
}

```

Any idea why Logstash doesn't like this? The filter in question is:

`<%{POSINT:syslog_pri}>%{SYSLOGTIMESTAMP:syslog_timestamp} %{SYSLOGHOST:syslog_hostname} %{GREEDYDATA:syslog_message}`

`<4>Jul 14 09:52:00 192.168.1.10 (\"U7PG2,44d9e7fc1de2,v3.4.18.346 kernel: [6292100.680000] [wifi1] FWLOG: [616713] WAL_DBGID_TX_BA_SETUP ( 0x435940, 0x6, 0x0, 0x2, 0x0 )`

---

<div class="post-metadata">

**Author:** ![runtman](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/runtman/32/18136_2.png) [@runtman](https://discuss.elastic.co/u/runtman)\
**Post date:** [July 14, 2017, 10:18am UTC](https://discuss.elastic.co/t/json-parse-error-original-data-now-in-message-field/93163/2 "2017-07-14T10:18:04Z")

</div>

I am assuming it's a JSON error, any ideas how to prvent this.

The log is definitely not in JSON format, can I just drop the codec option?

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [July 14, 2017, 10:21am UTC](https://discuss.elastic.co/t/json-parse-error-original-data-now-in-message-field/93163/3 "2017-07-14T10:21:41Z")

</div>

> The log is definitely not in JSON format, can I just drop the codec option?

If the incoming logs aren't JSON you shouldn't use the json codec, no.

---

<div class="post-metadata">

**Author:** ![runtman](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/runtman/32/18136_2.png) [@runtman](https://discuss.elastic.co/u/runtman)\
**Post date:** [August 10, 2017, 11:09am UTC](https://discuss.elastic.co/t/json-parse-error-original-data-now-in-message-field/93163/4 "2017-08-10T11:09:04Z")

</div>

Yeh, that was exactly it. I have dropped that and the errors are gone.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 7, 2017, 11:09am UTC](https://discuss.elastic.co/t/json-parse-error-original-data-now-in-message-field/93163/5 "2017-09-07T11:09:05Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
