# JSON Parsing Error - Logstash

**URL:** <https://discuss.elastic.co/t/json-parsing-error-logstash/210768>\
**Category:** Logstash\
**Created:** [December 5, 2019, 6:47pm UTC](https://discuss.elastic.co/t/json-parsing-error-logstash/210768 "2019-12-05T18:47:56Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Booooooo](https://avatars.discourse-cdn.com/v4/letter/b/ecccb3/32.png) [@Booooooo](https://discuss.elastic.co/u/Booooooo)\
**Post date:** [December 5, 2019, 6:47pm UTC](https://discuss.elastic.co/t/json-parsing-error-logstash/210768/1 "2019-12-05T18:47:56Z")

</div>

Hi,

I am trying to ingest a JSON file but I'm getting errors and none of the key value pairs are being extrated to any fields.

I currently have this configuration:

```
input {
    file {
        path => "/home/path_to_json/test.json"
        start_position => "beginning"
        sincedb_path => "/dev/null"
    }
}

filter {
     json {
       source => "message"
     }
   }

output {
    elasticsearch {
        hosts => "http://localhost:9200"
        index => "logs"
    }
    stdout { codec => rubydebug}
}

```

And here is a sample the application in question provides of the response it will return to the request passed via the API:

```
{
  "events": [
    {
      "sourceIP": "1.1.1.1",
      "destinationIP": "127.0.0.1",
      "qid": 1004
    },
    {
      "sourceIP": "1.1.1.1",
      "destinationIP": "127.0.0.1",
      "qid": 1005
    }
  ]
}

```

The above is just a sample, so the real results will contain a lot more data with a large number of key value pairs, which I am hoping logstash could parse so once they arrive at Elasticsearch I would expect to have those extracted to fields, like:

sourceIP: 1.1.1.1  
destinationIP: 127.0.0.1

Etc, etc,...

Any ideas as to what could be going wrong here?

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [December 5, 2019, 8:52pm UTC](https://discuss.elastic.co/t/json-parsing-error-logstash/210768/2 "2019-12-05T20:52:31Z")

</div>

A file filter, by default, creates one event for each line of the file. If your JSON is spread across multiple lines you will need a multiline codec to combine lines.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 2, 2020, 8:52pm UTC](https://discuss.elastic.co/t/json-parsing-error-logstash/210768/3 "2020-01-02T20:52:38Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
