# JSON parser error

**URL:** <https://discuss.elastic.co/t/json-parser-error/271283>\
**Category:** Logstash\
**Created:** [April 26, 2021, 5:35pm UTC](https://discuss.elastic.co/t/json-parser-error/271283 "2021-04-26T17:35:48Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![Pacous](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/pacous/32/86117_2.png) [@Pacous](https://discuss.elastic.co/u/Pacous)\
**Post date:** [April 26, 2021, 5:35pm UTC](https://discuss.elastic.co/t/json-parser-error/271283/1 "2021-04-26T17:35:48Z")

</div>

Hello,

This is my logstash configuration below:

filter {  
grok {  
match =\> { "message" =\> "%{SYSLOG5424PRI:syslog\_index}-\s\*%{SYSLOGHOST:syslog\_hostname} %{GREEDYDATA:syslog\_message}" }  
}  
json {  
source =\> "syslog\_message"  
}

Here is below the error displayed :

[2021-04-26T17:38:20,855][WARN][logstash.codecs.jsonlines][main][533b154c49ba0c3c537b0d48bd34f3c6f861d2d2a4d8cd6ed52e613545983ddf] JSON parse error, original data now in message field {:error=\>#\<LogStash::Json::ParserError: Unexpected character ('\<' (code 60)): expected a valid value (number, String, array, object, 'true', 'false' or 'null')  
at [Source: (String)"\<01\>- hostname {"name":"ELK","version":"1.0","isoTimeFormat":"yyyy-MM-dd'T'HH:mm:ss.SSSZ","type":"traffic","category":"accept","protocolID":"17","sev":"0","src":"192.168.30.2","dst":"10.167.254.5","srcPort":"42494","dstPort":"161","relevance":"5","credibility":"5","startTimeEpoch":"1619451526888","startTimeISO":"2021-04-26T17:38:46.888+02:00","storageTimeEpoch":"1619451526888","storageTimeISO":"2021-04-26T17:38:46.888+02:00","deploymentID":"5c15c102-a647-11ea-8226-00505601062b","devTimeEpoch":"1"[truncated 1541 chars]; line: 1, column: 2]\>, :data=\>"\<01\>- hostname {"name":"ELK","version":"1.0","isoTimeFormat":"yyyy-MM-dd'T'HH:mm:ss.SSSZ","type":"traffic","category":"accept","protocolID":"17","sev":"0","src":"192.168.30.2","dst":"10.167.254.5","srcPort":"42494","dstPort":"161","relevance":"5","credibility":"5","startTimeEpoch":"1619451526888","startTimeISO":"2021-04-26T17:38:46.888+02:00","storageTimeEpoch":"1619451526888","storageTimeISO":"2021-04-26T17:38:46.888+02:00","deploymentID":"5c15c102-a647-11ea-8226-00505601062b","devTimeEpoch":"1619451441000","devTimeISO":"2021-04-26T17:37:21.000+02:00","srcPreNATPort":"0","dstPreNATPort":"0","srcPostNATPort":"0","dstPostNATPort":"0","hasIdentity":"false","payload":"\<189\>logver=604055651 timestamp=1619451441 tz=\"UTC+2:00\" devname=\"DCL0001FW\" devid=\"FG100FTK20004077\" vd=\"VPN-PARTNER\" date=2021-04-26 time=17:37:21 eventtime=1619451441728721200 tz=\"+0200\" logid=\"0000000013\" type=\"traffic\" subtype=\"forward\" level=\"notice\" srcip=192.168.30.2 srcport=42494 srcintf=\"To-SUP\_SFR\" srcintfrole=\"undefined\" dstip=10.167.254.5 dstport=161 dstintf=\"MPLS\" dstintfrole=\"wan\" srccountry=\"Reserved\" dstcountry=\"Reserved\" sessionid=1300708441 proto=17 action=\"accept\" policyid=245 policytype=\"policy\" poluuid=\"f12a6f26-2983-51eb-5b11-8c3c06c9abb6\" policyname=\"Supervision\_CES\" service=\"SNMP\" trandisp=\"noop\" duration=180 sentbyte=146 rcvdbyte=191 sentpkt=1 rcvdpkt=1 vpn=\"To-SUP\_SFR\" vpntype=\"ipsec-static\" appcat=\"unscanned\"\n","eventCnt":"1","domainID":"4","domainName":"Decathlon\_N1","eventName":"Firewall Permit","lowLevelCategory":"Firewall Permit","highLevelCategory":"Access","eventDescription":"Firewall Permit","protocolName":"udp","logSource":"FortiGate @ 192.168.0.3","srcNetName":"Net-10-172-192.Net\_192\_168\_0\_0","dstNetName":"Net-10-172-192.Net\_10\_0\_0\_0","logSourceType":"Fortinet FortiGate Security Gateway","logSourceGroup":"1H,Production,SUPERVISION","logSourceIdentifier":"192.168.0.3","BytesReceived":"191","BytesSent":"146","Application Category":"unscanned","Subtype":"forward"}"}

I need help setting up logstash parsing  
Regards,

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [April 26, 2021, 5:44pm UTC](https://discuss.elastic.co/t/json-parser-error/271283/2 "2021-04-26T17:44:42Z")

</div>

> [@Pacous](#):
>
> [WARN][logstash.codecs.jsonlines]

The error is coming from the json\_lines codec, not the json filter. A codec on the input will be trying to parse [message], not [syslog\_message], which does not exist until after the grok filter has executed.

---

<div class="post-metadata">

**Author:** ![Pacous](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/pacous/32/86117_2.png) [@Pacous](https://discuss.elastic.co/u/Pacous)\
**Post date:** [April 26, 2021, 5:55pm UTC](https://discuss.elastic.co/t/json-parser-error/271283/3 "2021-04-26T17:55:47Z")

</div>

This is below my input:

input {  
tcp {  
port =\> "5141"  
codec =\> json  
type =\> "syslog"  
}  
}

I don't know where the problem is coming from.

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [April 26, 2021, 6:07pm UTC](https://discuss.elastic.co/t/json-parser-error/271283/4 "2021-04-26T18:07:53Z")

</div>

> [@Pacous](#):
>
> codec =\> json

Remove this.

---

<div class="post-metadata">

**Author:** ![Pacous](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/pacous/32/86117_2.png) [@Pacous](https://discuss.elastic.co/u/Pacous)\
**Post date:** [April 26, 2021, 6:12pm UTC](https://discuss.elastic.co/t/json-parser-error/271283/5 "2021-04-26T18:12:27Z")

</div>

I will remove the codec. And I will observe the result by tomorrow.

---

<div class="post-metadata">

**Author:** ![Pacous](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/pacous/32/86117_2.png) [@Pacous](https://discuss.elastic.co/u/Pacous)\
**Post date:** [April 30, 2021, 3:50pm UTC](https://discuss.elastic.co/t/json-parser-error/271283/6 "2021-04-30T15:50:17Z")

</div>

Thank you Badger.  
Its good

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 28, 2021, 3:51pm UTC](https://discuss.elastic.co/t/json-parser-error/271283/7 "2021-05-28T15:51:09Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
