# Logstash config - JSON filter results with "\_jsonparsefailure"

**URL:** <https://discuss.elastic.co/t/logstash-config-json-filter-results-with-jsonparsefailure/149281>\
**Category:** Logstash\
**Created:** [September 20, 2018, 11:46am UTC](https://discuss.elastic.co/t/logstash-config-json-filter-results-with-jsonparsefailure/149281 "2018-09-20T11:46:36Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![Ira](https://avatars.discourse-cdn.com/v4/letter/i/9fc348/32.png) [@Ira](https://discuss.elastic.co/u/Ira)\
**Post date:** [September 20, 2018, 11:46am UTC](https://discuss.elastic.co/t/logstash-config-json-filter-results-with-jsonparsefailure/149281/1 "2018-09-20T11:46:37Z")

</div>

Hi,

My log file is in JSON format.  
An example of a log line:

{"@timestamp":"2018-09-18T10:36:27.135+03:00","@version":1,"message":{"apiMethodType": "GET","elapsedTime": 1136},"caller\_line\_number":94}

I'm using Filebeat with the following prospectors settings:

filebeat.prospectors:

- paths:
  - C:\Users\abc\Desktop\E.L.K\Log\*.json  
input\_type: log  
json.keys\_under\_root: true  
json.add\_error\_key: true

I'd like to get the values of the two fields withing the message: apiMethodType, elapsedTime.

My logstash config file is:  
input {  
beats {  
port =\> "5044"  
}  
}

filter{  
json{  
source =\> "message"  
target =\> "JsonMessage"  
}  
mutate {  
add\_field =\> {  
"apiMethodType" =\> "%{[JsonMessage][apiMethodType]}"  
"elapsedTime" =\> "%{[JsonMessage][elapsedTime]}"  
}  
}  
}  
output {  
elasticsearch {  
hosts =\> ["localhost:9200"]  
index =\> ["logs-%{+YYYY.MM.dd}"]  
}  
}

The result looks as follows:

```
  {
    "_index" : "logs-2018.09.20",
    "_type" : "doc",
    "_id" : "hW2K9mUB55jPhmkgUZyh",
    "_score" : 1.0,
    "_source" : {
      "caller_line_number" : 94,
      "source" : "C:\\Users\\abc\\Desktop\\E.L.K\\Log\\Sample.json",
      "message" : "{\"apiMethodType\"=>\"GET\", \"elapsedTime\"=>1136}",
      "beat" : {
        "version" : "6.4.0",
        "name" : "IRA",
        "hostname" : "IRA"
      },
      "@timestamp" : "2018-09-20T10:28:02.342Z",
      "@version" : 1,
      "host" : {
        "name" : "IRA"
      },
      "apiMethodType" : "%{[JsonMessage][apiMethodType]}",
      "elapsedTime" : "%{[JsonMessage][elapsedTime]}",
      "offset" : 508,
      "tags" : [
        "beats_input_codec_plain_applied",
        "_jsonparsefailure"
      ]
    }
  }

```

Could you, please, assist me with understanding why am I getting the "\_jsonparsefailure"?  
What should I do in order to fetch the values of apiMethodType and elapsedTime correctly?

Thanks.

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [September 20, 2018, 1:25pm UTC](https://discuss.elastic.co/t/logstash-config-json-filter-results-with-jsonparsefailure/149281/2 "2018-09-20T13:25:04Z")

</div>

`{"apiMethodType"=>"GET", "elapsedTime"=>1136}` isn't a valid JSON string. Given the log example at the top and the configuration you've given it's very hard to understand how that ended up in your `message` field.

---

<div class="post-metadata">

**Author:** ![Ira](https://avatars.discourse-cdn.com/v4/letter/i/9fc348/32.png) [@Ira](https://discuss.elastic.co/u/Ira)\
**Post date:** [September 20, 2018, 2:05pm UTC](https://discuss.elastic.co/t/logstash-config-json-filter-results-with-jsonparsefailure/149281/3 "2018-09-20T14:05:11Z")

</div>

Even when I'm removing the filter the result looks like this:

{  
"\_index" : "logs-2018.09.20",  
"\_type" : "doc",  
"\_id" : "lG1J92UB55jPhmkgBpyJ",  
"\_score" : 1.0,  
"\_source" : {  
"@timestamp" : "2018-09-20T14:01:18.541Z",  
"caller\_line\_number" : 94,  
"host" : {  
"name" : "IRA"  
},  
"beat" : {  
"name" : "IRA",  
"hostname" : "IRA",  
"version" : "6.4.0"  
},  
"source" : "C:\Users\abc\Desktop\E.L.K\Log\Sample.json",  
"message" : "{"apiMethodType"=\>"GET", "elapsedTime"=\>1136}",  
"tags" : [  
"beats\_input\_codec\_plain\_applied"  
],  
"offset" : 0,  
"@version" : 1  
}  
}  
What am I missing?

Thanks.

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [September 20, 2018, 2:31pm UTC](https://discuss.elastic.co/t/logstash-config-json-filter-results-with-jsonparsefailure/149281/4 "2018-09-20T14:31:41Z")

</div>

What does the first line of Sample.json look like?

---

<div class="post-metadata">

**Author:** ![Ira](https://avatars.discourse-cdn.com/v4/letter/i/9fc348/32.png) [@Ira](https://discuss.elastic.co/u/Ira)\
**Post date:** [September 20, 2018, 3:52pm UTC](https://discuss.elastic.co/t/logstash-config-json-filter-results-with-jsonparsefailure/149281/5 "2018-09-20T15:52:22Z")

</div>

The log line looks like this:

{"@timestamp":"2018-09-18T10:36:27.135+03:00","@version":1,"message":{"apiMethodType": "GET","elapsedTime": 1136},"caller\_line\_number":94}

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [September 20, 2018, 5:17pm UTC](https://discuss.elastic.co/t/logstash-config-json-filter-results-with-jsonparsefailure/149281/6 "2018-09-20T17:17:01Z")

</div>

Okay. Then I have no idea how that line could possibly end up as the `message` field in a previous post.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 18, 2018, 5:17pm UTC](https://discuss.elastic.co/t/logstash-config-json-filter-results-with-jsonparsefailure/149281/7 "2018-10-18T17:17:12Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
