# Log Encoding message incorrect

**URL:** <https://discuss.elastic.co/t/log-encoding-message-incorrect/119546>\
**Category:** Logstash\
**Created:** [February 12, 2018, 8:11pm UTC](https://discuss.elastic.co/t/log-encoding-message-incorrect/119546 "2018-02-12T20:11:30Z")\
**Posts on this page:** 10\
**Page:** 1

<div class="post-metadata">

**Author:** ![shri](https://avatars.discourse-cdn.com/v4/letter/s/e19adc/32.png) [@shri](https://discuss.elastic.co/u/shri)\
**Post date:** [February 12, 2018, 8:11pm UTC](https://discuss.elastic.co/t/log-encoding-message-incorrect/119546/1 "2018-02-12T20:11:30Z")

</div>

Hello,

Im new to elk. I'm using multiple inputs i) tcp ii) beats in my logstash.

i) For tcp , using the spring pattern with in the code itself and simply default value of logstash server IP  
as below

And able to see the messgaes correctly without encoding issue.

ii) filebeats is where i want to forward logs to the same logstash from different instance.  
i have installed the filebeats on the instance and edited the file beats.yml input(/var/log) & output as the logstash ip with 5:044.

My conf looks as below:

#input TCP for Microservices  
#input Beats for the AEM instance server logs.

input {  
tcp {  
port =\> 5044  
}  
beats {  
port =\> 5044  
}  
}

filter {

json {  
source =\> "message"  
}

}  
output {  
if [type] == "syslog" {  
elasticsearch {  
hosts =\> ["localhost"]  
manage\_template =\> false  
index =\> "logstash-%{+YYYY.MM.dd}"  
codec =\> "json"  
}  
}

else if [type][beats][hostname] == "ip-x-x-x-x" {  
elasticsearch {  
hosts =\> ["localhost"]  
manage\_template =\> false  
index =\> "logstash-%{+YYYY.MM.dd}"  
codec =\> "json"  
document\_type =\> "%{[@metadata][type]}"  
}  
}

}

When i see the messages on the kibana discover and search filter with IP address which is coming from beats servers messages looks broken as below.

message:\x81\>L6\x9B\xF3\xF5\xBD\x83\xF1h2\xBB\x9C\xE9\xEC\xCA`\x916f\x87\xA5\xA5\xF5\*\xDAݍ\x8EF\x93\xD1}Ãh\<\x89\xE2,MN7"\x92\u0013\>\rXFȌ\xBCE\f\xCF\u001C\x99"\xEFɛ\x87\x93!\x82Ee\u0013=|8\u0019^\e\u001DE\xF7\xEC\u001D\x8Do̢\xB

can someone please help me with this issue. Not sure if my conf with filter and codec doing right. But the logs comings from tcp input is looking good but not from beats

---

<div class="post-metadata">

**Author:** ![Brandon\_Kobel](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/brandon_kobel/32/14829_2.png) [@Brandon\_Kobel](https://discuss.elastic.co/u/Brandon_Kobel)\
**Post date:** [February 12, 2018, 8:35pm UTC](https://discuss.elastic.co/t/log-encoding-message-incorrect/119546/2 "2018-02-12T20:35:57Z")

</div>

Hey @shri I'm moving this to the Logstash section, as it's more about ingesting your data properly with Logstash than Kibana.

---

<div class="post-metadata">

**Author:** ![shri](https://avatars.discourse-cdn.com/v4/letter/s/e19adc/32.png) [@shri](https://discuss.elastic.co/u/shri)\
**Post date:** [February 12, 2018, 8:41pm UTC](https://discuss.elastic.co/t/log-encoding-message-incorrect/119546/3 "2018-02-12T20:41:47Z")

</div>

Thanks Brandon.

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [February 12, 2018, 8:59pm UTC](https://discuss.elastic.co/t/log-encoding-message-incorrect/119546/4 "2018-02-12T20:59:59Z")

</div>

> input {  
> tcp {  
> port =\> 5044  
> }  
> beats {  
> port =\> 5044  
> }  
> }

Um, what? You can't have two input plugins listening on the same port.

---

<div class="post-metadata">

**Author:** ![shri](https://avatars.discourse-cdn.com/v4/letter/s/e19adc/32.png) [@shri](https://discuss.elastic.co/u/shri)\
**Post date:** [February 13, 2018, 8:32pm UTC](https://discuss.elastic.co/t/log-encoding-message-incorrect/119546/5 "2018-02-13T20:32:55Z")

</div>

ok i removed the beats from my input and only using the tcp to the port 5044. And i'm able to see logs from both. But, the instance logs seem to be still looking incorrrect.

message looking as below :  
\x8F\u0014/#\x95\xFC\t3\x85\aL\x9D\xF8\u001F\t\xEB\u001C\xE6,"\xB1\xB0!\xD0#\u001E\xC5\xE1"\u001Cœ\xEFK\xB2\xEC) tags:\_jsonparsefailure \_id:yJXYkGEBw0V7GrzbeGcy \_type:%{[@metadata][type]} \_index:%{[@metadata][beat]}-2018.02.13

Also, this is what im seeing from logstash stdout

[2018-02-13T20:30:31,117][WARN][logstash.filters.json] Error parsing json {:source=\>"message", :raw=\>"\u000F3\xB2\u007F\xF4\xEC\xC1]\x81/\u0019\xC1\xC1D#t\xB0G\xCF\xE0\xE0\u0010'ܣg\xB8u0c\xAD~Dp`\\xCAj\\xB3\\u0011f\\xE5\\xCC\\xD6Y\\xABVڈ\\xBB\\xF7\\x9F\\xDE}\\xBE\\u0013?N\\x9C\\xB7[;X\\xAD\\xD7Ki\\xD6\\xEB\\x8D\\xFE)\\xA8\\x8C\\xCAg\\u001F\\x8E\\xA8\\xEA\\u0014Ө|\\xE3\\xA3", :exception=>#<LogStash::Json::ParserError: Unexpected character ('\' (code 92)): expected a valid value (number, String, array, object, 'true', 'false' or 'null') at [Source: (byte[])"\u000F3\xB2\u007F\xF4\xEC\xC1]\x81/\u0019\xC1\xC1D#t\xB0G\xCF\xE0\xE0\u0010'Ü£g\xB8u0c\xAD~Dp`î�¶\xCAj\xB3\u0011f\xE5\xCC\xD6Y\xABVÚ�\xBB\xF7\x9F\xDE}\xBE\u0013?N\x9C\xB7[;X\xAD\xD7Ki\xD6\xEB\x8D\xFE)\xA8\x8C\xCAg\u001F\x8E\xA8\xEA\u0014Ó¨|\xE3\xA3"; line: 1, column: 2]\>}

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [February 13, 2018, 9:19pm UTC](https://discuss.elastic.co/t/log-encoding-message-incorrect/119546/6 "2018-02-13T21:19:01Z")

</div>

If you want to collect logs with Filebeat you need a beats input, it's just that it can't use the same port as your tcp input.

---

<div class="post-metadata">

**Author:** ![shri](https://avatars.discourse-cdn.com/v4/letter/s/e19adc/32.png) [@shri](https://discuss.elastic.co/u/shri)\
**Post date:** [February 13, 2018, 9:20pm UTC](https://discuss.elastic.co/t/log-encoding-message-incorrect/119546/7 "2018-02-13T21:20:39Z")

</div>

How do i add another port for the tcp inputs?.

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [February 13, 2018, 9:27pm UTC](https://discuss.elastic.co/t/log-encoding-message-incorrect/119546/8 "2018-02-13T21:27:31Z")

</div>

Re-add the **beats** input but choose another port number. The port number must be unused. Over and out.

---

<div class="post-metadata">

**Author:** ![shri](https://avatars.discourse-cdn.com/v4/letter/s/e19adc/32.png) [@shri](https://discuss.elastic.co/u/shri)\
**Post date:** [February 15, 2018, 8:04pm UTC](https://discuss.elastic.co/t/log-encoding-message-incorrect/119546/9 "2018-02-15T20:04:55Z")

</div>

Thank you. That did help.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 15, 2018, 8:05pm UTC](https://discuss.elastic.co/t/log-encoding-message-incorrect/119546/10 "2018-03-15T20:05:22Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
