# Json parsing problem tcp input

**URL:** <https://discuss.elastic.co/t/json-parsing-problem-tcp-input/169562>\
**Category:** Logstash\
**Created:** [February 22, 2019, 10:59am UTC](https://discuss.elastic.co/t/json-parsing-problem-tcp-input/169562 "2019-02-22T10:59:18Z")\
**Posts on this page:** 10\
**Page:** 1

<div class="post-metadata">

**Author:** ![hoff](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/hoff/32/30963_2.png) [@hoff](https://discuss.elastic.co/u/hoff)\
**Post date:** [February 22, 2019, 10:59am UTC](https://discuss.elastic.co/t/json-parsing-problem-tcp-input/169562/1 "2019-02-22T10:59:18Z")

</div>

I have a problem with logs in syslog.  
Logstash logging warn like a `[WARN][logstash.codecs.jsonlines] JSON parse error, original data now in message field {:error=>#<LogStash::Json::ParserError: No message available>, :data=>"null\r"}`  
per milisecond.

My configuration :

```
    input {
  tcp {
    port => 5044
    codec => json
  }
}

filter {
    if "_jsonparsefailure" in [tags] {
	drop { }
	}
    else {
        json {	source => "message"
        	target => "log"
	    }
	}
    }

output {
  elasticsearch {
   hosts => "127.0.0.1:9200"
   manage_template => false
   index => "%{test}-%{+YYYY.MM.dd}"
   }
}

```

Logs are growing very fast and the elasticsearch service hangs after a long time, which requires a restart.

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [February 22, 2019, 1:38pm UTC](https://discuss.elastic.co/t/json-parsing-problem-tcp-input/169562/2 "2019-02-22T13:38:01Z")

</div>

> [@hoff](#):
>
> [WARN][logstash.codecs.jsonlines] JSON parse error, original data now in message field {:error=\>#\<LogStash::Json::ParserError: No message available\>, :data=\>"null\r"}

That is telling you that it received a message containing "null\r", which will have resulted in a \_jsonparsefailure tag being added and the event being dropped.

---

<div class="post-metadata">

**Author:** ![hoff](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/hoff/32/30963_2.png) [@hoff](https://discuss.elastic.co/u/hoff)\
**Post date:** [February 22, 2019, 2:17pm UTC](https://discuss.elastic.co/t/json-parsing-problem-tcp-input/169562/3 "2019-02-22T14:17:52Z")

</div>

Does this mean that logstash expects a value other than null?  
The data is correctly displayed in the visualizations, however, the occurrence of such an warnings in the logs is irritating and uses a lot of space.  
Changing log.level is not what I am expecting at the moment.

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [February 22, 2019, 2:30pm UTC](https://discuss.elastic.co/t/json-parsing-problem-tcp-input/169562/4 "2019-02-22T14:30:11Z")

</div>

You have configured the tcp input with a json codec. It expects valid json, which "null\r" is assuredly not.

---

<div class="post-metadata">

**Author:** ![hoff](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/hoff/32/30963_2.png) [@hoff](https://discuss.elastic.co/u/hoff)\
**Post date:** [February 26, 2019, 10:36am UTC](https://discuss.elastic.co/t/json-parsing-problem-tcp-input/169562/5 "2019-02-26T10:36:41Z")

</div>

OK, I removed the codec from the input and changed the configuration to the following.

```
filter {
        if [message] =~ /^\s*$/ {
            drop { }
            }
        json {
            source => "message"
            skip_on_invalid_json => true
            remove_field => ["message"]
            }
        }

```

However, I still have the same problem. Below is a rubydebug dump.

```
{
   "@version" => "1",
      "port" => xxxx,
 "@timestamp" => 2019-02-26T10:04:45.537Z,
    "message" => "null\r",
      "host" => "x.x.x.x",
      "tags" => [
    [0] "_jsonparsefailure"
 ]
 }
```

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [February 26, 2019, 12:22pm UTC](https://discuss.elastic.co/t/json-parsing-problem-tcp-input/169562/6 "2019-02-26T12:22:25Z")

</div>

Which is what I would expect. Something is still sending messages containing 'null\r', and a json filter will fail to parse them.

---

<div class="post-metadata">

**Author:** ![hoff](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/hoff/32/30963_2.png) [@hoff](https://discuss.elastic.co/u/hoff)\
**Post date:** [February 26, 2019, 12:40pm UTC](https://discuss.elastic.co/t/json-parsing-problem-tcp-input/169562/7 "2019-02-26T12:40:22Z")

</div>

Can I do something this without changing the messages? Probably I will get similar messages from other servers which I probably will not be able to influence.

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [February 26, 2019, 12:54pm UTC](https://discuss.elastic.co/t/json-parsing-problem-tcp-input/169562/8 "2019-02-26T12:54:01Z")

</div>

Drop them?

```
if "_jsonparsefailure" in [tags] { drop {} }
```

---

<div class="post-metadata">

**Author:** ![hoff](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/hoff/32/30963_2.png) [@hoff](https://discuss.elastic.co/u/hoff)\
**Post date:** [February 27, 2019, 7:59am UTC](https://discuss.elastic.co/t/json-parsing-problem-tcp-input/169562/9 "2019-02-27T07:59:17Z")

</div>

Ok, I remove json coden in the input and configure it in filter with `if "_jsonparsefailure" in [tags] { drop {} }`and also managed to change the transmitted frames so that they do not generate so many errors. Problem is solved. Thank you for your advices Badger 🙂

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 27, 2019, 7:59am UTC](https://discuss.elastic.co/t/json-parsing-problem-tcp-input/169562/10 "2019-03-27T07:59:19Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
