# JSON parse error - Suricata

**URL:** <https://discuss.elastic.co/t/json-parse-error-suricata/248997>\
**Category:** Logstash\
**Created:** [September 17, 2020, 2:54pm UTC](https://discuss.elastic.co/t/json-parse-error-suricata/248997 "2020-09-17T14:54:46Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Paulogbr](https://avatars.discourse-cdn.com/v4/letter/p/b5a626/32.png) [@Paulogbr](https://discuss.elastic.co/u/Paulogbr)\
**Post date:** [September 17, 2020, 2:54pm UTC](https://discuss.elastic.co/t/json-parse-error-suricata/248997/1 "2020-09-17T14:54:46Z")

</div>

Hello Team,

I mounted my lab with suricata and web servers. I tried send log suricata to ELK. But I received error when i did the parse

My conf:

input {  
udp {  
port =\> "514"  
type =\> "syslog"  
}  
}

filter {  
json {  
source =\> "message"  
}  
}

output {  
stdout {}  
}

But I received this error:

[2020-09-17T11:42:25,613][WARN][logstash.filters.json][main][c3ae95835f9d11e27a9b4e7c14651433b6767ca87df67a270462822942fd6c02] Error parsing json {:source=\>"message", :raw=\>"\<13\>Sep 16 18:07:59 proapps-security suricata-halfling: {"timestamp":"2020-09-17T11:42:04.985994-0300","flow\_id":738087809626408,"in\_iface":"ix1","event\_type":"alert","src\_ip":"99.125.125.125","src\_port":9999,"dest\_ip":"192.168.0.1","dest\_port":389,"proto":"UDP","alert":{"action":"allowed","gid":1,"signature\_id":2016150,"rev":2,"signature":"ET INFO Session Traversal Utilities for NAT (STUN Binding Response)","category":"Attempted User Privilege Gain","severity":1,"metadata":{"updated\_at":["2013\_01\_04"],"created\_at":["2013\_01\_04"]}},"app\_proto":"failed","flow":{"pkts\_toserver":5,"pkts\_toclient":0,"bytes\_toserver":569,"bytes\_toclient":0,"start":"2020-09-17T11:41:56.110888-0300"}}\n", :exception=\>#\<LogStash::Json::ParserError: Unexpected character ('\<' (code 60)): expected a valid value (number, String, array, object, 'true', 'false' or 'null')  
at [Source: (byte)"

Please can you help me ?

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [September 17, 2020, 3:03pm UTC](https://discuss.elastic.co/t/json-parse-error-suricata/248997/2 "2020-09-17T15:03:23Z")

</div>

You need to parse the JSON out of the syslog message before trying to use a json filter. Something like

```
dissect { mapping => { "message" => "<%{syslog_pri}>%{timestamp} %{+timestamp} %{+timestamp} %{} %{}: %{jsonMessage}" } }
json { source => "jsonMessage" }
```

---

<div class="post-metadata">

**Author:** ![Paulogbr](https://avatars.discourse-cdn.com/v4/letter/p/b5a626/32.png) [@Paulogbr](https://discuss.elastic.co/u/Paulogbr)\
**Post date:** [September 17, 2020, 4:02pm UTC](https://discuss.elastic.co/t/json-parse-error-suricata/248997/3 "2020-09-17T16:02:30Z")

</div>

Thanks !

I will do this.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 15, 2020, 4:02pm UTC](https://discuss.elastic.co/t/json-parse-error-suricata/248997/4 "2020-10-15T16:02:39Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
