# Json processor fails when processing some fields without quotes

**URL:** <https://discuss.elastic.co/t/json-processor-fails-when-processing-some-fields-without-quotes/324891>\
**Category:** Kibana\
**Tags:** ingest-pipeline\
**Created:** [February 7, 2023, 11:35am UTC](https://discuss.elastic.co/t/json-processor-fails-when-processing-some-fields-without-quotes/324891 "2023-02-07T11:35:05Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![mmartinez](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mmartinez/32/106337_2.png) [@mmartinez](https://discuss.elastic.co/u/mmartinez)\
**Post date:** [February 7, 2023, 11:35am UTC](https://discuss.elastic.co/t/json-processor-fails-when-processing-some-fields-without-quotes/324891/1 "2023-02-07T11:35:05Z")

</div>

Hello,

We are sending logs to escloud using fluentbit 2.0.6 with the field `message` in JSON format but when we use the JSON processor in that field it fails in different ways.

1. As some field values come without quotes and starting with 0 it throws an error.  
`"time_local": 06/Feb/2023:16:29:43 +0000,`  
`Invalid numeric value: Leading zeroes not allowed`

2. Other fields with empty values and without quotes also fail  
`"remote_user": ,`  
`failed with message Unexpected character (',' (code 44)): expected a value`

Is there a way to process those type of json logs? Or do you know if it's possible to add quotes to all fields?

regards

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [February 7, 2023, 1:49pm UTC](https://discuss.elastic.co/t/json-processor-fails-when-processing-some-fields-without-quotes/324891/2 "2023-02-07T13:49:16Z")

</div>

Can you share a sample of your message?

It doesn't seem to be a valid JSON as the values do not have double quotes, which is needed by the JSON processor.

For example, if you have something like this:

```auto
{ "remote_user": ,"time_local": 06/Feb/2023:16:29:43 +0000 }

```

Then the processor will not work as this is not a valid JSON.

The best option is to fix the message before sending to elasticsearch, I do not use fluentbit, but have you checked if there is any option in the output to send it as a valid json?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 7, 2023, 1:50pm UTC](https://discuss.elastic.co/t/json-processor-fails-when-processing-some-fields-without-quotes/324891/3 "2023-03-07T13:50:00Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
