# Json Parser failure when the message contains emoji unicodes

**URL:** <https://discuss.elastic.co/t/json-parser-failure-when-the-message-contains-emoji-unicodes/175224>\
**Category:** Logstash\
**Created:** [April 3, 2019, 2:31pm UTC](https://discuss.elastic.co/t/json-parser-failure-when-the-message-contains-emoji-unicodes/175224 "2019-04-03T14:31:21Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![Denis\_Galvao](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/denis_galvao/32/43409_2.png) [@Denis\_Galvao](https://discuss.elastic.co/u/Denis_Galvao)\
**Post date:** [April 3, 2019, 2:31pm UTC](https://discuss.elastic.co/t/json-parser-failure-when-the-message-contains-emoji-unicodes/175224/1 "2019-04-03T14:31:21Z")

</div>

```
Hi there.

Logstash log a _jasonparsefailure when the message contains some emojis..

{
    "@timestamp" => 2019-04-03T14:22:08.147Z,
      "@version" => "1",
       "message" => "{\\\"event\\\":\\\"WhatsAppMessagesLog\\\",\\\"body\\\":{\\\"protocol\\\":\\\"155430118273\\\",\\\"route_number\\\":\\\"554197697084\\\",\\\"created_at\\\":\\\"2019-04-03 11:21:26\\\",\\\"from\\\":\\\"554197697084\\\",\\\"message_type\\\":\\\"text\\\",\\\"to\\\":\\\"554188220551\\\",\\\"event\\\":\\\"WEON_SEND\\\",\\\"type\\\":\\\"send\\\",\\\"uniqueid\\\":\\\"201904031554301286584.40320\\\",\\\"content\\\":\\\"\\xED\\xA0\\xBE\\xED\\xB4\\xB1\\xED\\xA0\\xBC\\xED\\xBF\\xBB \\xED\\xA0\\xBD\\xED\\xB1\\xAE\\xED\\xA0\\xBC\\xED\\xBF\\xBB‍♀️ \\xED\\xA0\\xBD\\xED\\xB1\\xAE\\xED\\xA0\\xBC\\xED\\xBF\\xBB‍♀️ \\xED\\xA0\\xBD\\xED\\xB1\\xAE\\xED\\xA0\\xBC\\xED\\xBF\\xBB‍♀️\\\"}}",
          "tags" => [
        [0] "_jsonparsefailure"
    ]
}

My logstash conf:
input {
        stomp {
                id => "idPrimeiro"
                host => "10.158.0.4"
                destination => "WEL"
		codec => "json"
        }
}
output {
        elasticsearch {
                hosts => ["localhost:9200"]
                index => "qualifications"
        }
        stdout {
                codec => rubydebug
        }
	file {
                path => "/var/log/logstash/stomp.log"
                codec => rubydebug
        }

}

I've tried several different codecs and charsets on the input chain, no success at all.

The messages come from ActiveMQ that correctly post the message on the logstash queue.
```

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [April 3, 2019, 3:19pm UTC](https://discuss.elastic.co/t/json-parser-failure-when-the-message-contains-emoji-unicodes/175224/2 "2019-04-03T15:19:40Z")

</div>

Having the wrong charset could be the issue. There should be an "exception=\>#\<LogStash::Json::ParserError:" with a more specific error message in the logstash log. What is the error message?

---

<div class="post-metadata">

**Author:** ![Denis\_Galvao](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/denis_galvao/32/43409_2.png) [@Denis\_Galvao](https://discuss.elastic.co/u/Denis_Galvao)\
**Post date:** [April 3, 2019, 6:56pm UTC](https://discuss.elastic.co/t/json-parser-failure-when-the-message-contains-emoji-unicodes/175224/3 "2019-04-03T18:56:46Z")

</div>

```
[2019-04-03T15:56:12,505][WARN][logstash.codecs.json] Received an event that has a different character encoding than you configured. {:text=&gt;"{\\\"event\\\":\\\"WhatsAppMessagesLog\\\",\\\"body\\\":{\\\"protocol\\\":\\\"155429559695\\\",\\\"route_number\\\":\\\"554197780247\\\",\\\"created_at\\\":\\\"2019-04-03 15:56:12\\\",\\\"from\\\":\\\"554192078513\\\",\\\"message_type\\\":\\\"text\\\",\\\"to\\\":\\\"554197780247\\\",\\\"event\\\":\\\"INBOX\\\",\\\"type\\\":\\\"receipt\\\",\\\"uniqueid\\\":\\\"201904031554317772385.43090\\\",\\\"content\\\":\\\"\\xED\\xA0\\xBD\\xED\\xB8\\x80\\xED\\xA0\\xBD\\xED\\xB8\\x80\\xED\\xA0\\xBD\\xED\\xB8\\x80\\xED\\xA0\\xBD\\xED\\xB8\\x80\\\"}}", :expected_charset=&gt;"UTF-8"}

[2019-04-03T15:56:12,631][ERROR][logstash.codecs.json] JSON parse error, original data now in message field {:error=&gt;#&lt;LogStash::Json::ParserError: Unexpected character ('\' (code 92)): was expecting double-quote to start field name

 at [Source: (String)"{\"event\":\"WhatsAppMessagesLog\",\"body\":{\"protocol\":\"155429559695\",\"route_number\":\"554197780247\",\"created_at\":\"2019-04-03 15:56:12\",\"from\":\"554192078513\",\"message_type\":\"text\",\"to\":\"554197780247\",\"event\":\"INBOX\",\"type\":\"receipt\",\"uniqueid\":\"201904031554317772385.43090\",\"content\":\"\xED\xA0\xBD\xED\xB8\x80\xED\xA0\xBD\xED\xB8\x80\xED\xA0\xBD\xED\xB8\x80\xED\xA0\xBD\xED\xB8\x80\"}}"; line: 1, column: 3]&gt;, :data=&gt;"{\\\"event\\\":\\\"WhatsAppMessagesLog\\\",\\\"body\\\":{\\\"protocol\\\":\\\"155429559695\\\",\\\"route_number\\\":\\\"554197780247\\\",\\\"created_at\\\":\\\"2019-04-03 15:56:12\\\",\\\"from\\\":\\\"554192078513\\\",\\\"message_type\\\":\\\"text\\\",\\\"to\\\":\\\"554197780247\\\",\\\"event\\\":\\\"INBOX\\\",\\\"type\\\":\\\"receipt\\\",\\\"uniqueid\\\":\\\"201904031554317772385.43090\\\",\\\"content\\\":\\\"\\xED\\xA0\\xBD\\xED\\xB8\\x80\\xED\\xA0\\xBD\\xED\\xB8\\x80\\xED\\xA0\\xBD\\xED\\xB8\\x80\\xED\\xA0\\xBD\\xED\\xB8\\x80\\\"}}"}
```

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [April 3, 2019, 7:18pm UTC](https://discuss.elastic.co/t/json-parser-failure-when-the-message-contains-emoji-unicodes/175224/4 "2019-04-03T19:18:48Z")

</div>

> [@Denis\_Galvao](#):
>
> Unexpected character ('' (code 92)): was expecting double-quote to start field name

Code 92 is a backslash. So it seems that instead of something like

```
{ "foo": "bar" }

```

you have

```
{ \"foo\": \"bar\" }

```

Can you edit your post, select the text of the message and the sample data and click on \</\> in the toolbar above the edit panel. That will blockquote the text and preserve the escaping etc.

---

<div class="post-metadata">

**Author:** ![Denis\_Galvao](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/denis_galvao/32/43409_2.png) [@Denis\_Galvao](https://discuss.elastic.co/u/Denis_Galvao)\
**Post date:** [April 3, 2019, 7:45pm UTC](https://discuss.elastic.co/t/json-parser-failure-when-the-message-contains-emoji-unicodes/175224/5 "2019-04-03T19:45:13Z")

</div>

Thanks Badger, done.

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [April 3, 2019, 8:42pm UTC](https://discuss.elastic.co/t/json-parser-failure-when-the-message-contains-emoji-unicodes/175224/6 "2019-04-03T20:42:56Z")

</div>

The input is clearly not UTF-8. Try charset ASCII-8BIT, see if that helps.

You JSON is not valid JSON, because all the quotes are escaped. This is a rather blunt approach, but you could try

```
mutate { gsub => ["message", '\\"', '"'] }
```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 1, 2019, 8:42pm UTC](https://discuss.elastic.co/t/json-parser-failure-when-the-message-contains-emoji-unicodes/175224/7 "2019-05-01T20:42:57Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
