# Logstash Exec Curl - cant create valid JSON

**URL:** <https://discuss.elastic.co/t/logstash-exec-curl-cant-create-valid-json/185301>\
**Category:** Logstash\
**Created:** [June 11, 2019, 11:59pm UTC](https://discuss.elastic.co/t/logstash-exec-curl-cant-create-valid-json/185301 "2019-06-11T23:59:10Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![johnwood](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/johnwood/32/78918_2.png) [@johnwood](https://discuss.elastic.co/u/johnwood)\
**Post date:** [June 11, 2019, 11:59pm UTC](https://discuss.elastic.co/t/logstash-exec-curl-cant-create-valid-json/185301/1 "2019-06-11T23:59:10Z")

</div>

I was referred to GutHub by ES Cloud Support in ticket #00344788 but I thought I should check here first before heading over there.

I am trying to get a logstash exec command to work with a curl call that needs JSON payload.

Cloud support got me as far as this:  
command =\> "curl -X POST '[https://api.ontraport.com/1/objects](https://api.ontraport.com/1/objects)' --header 'Content-Type: application/json' --header 'Api-Key: ABCABCABC' --header 'Api-Appid: XYZXYZXYZ' -d '{"objectID": 0}'"

The problem I face is that the JSON payload ( -d '{"objectID": 0}' ) is getting further escaped in the curl command and ends up being sent like this:

```
'{\\\"objectID\\\": 0}' 

```

which is then rejected by the target system as bad json and is confirmed as bad json by [jsonlint.com](http://jsonlint.com)

The debug log in logstash shows this:

[2019-06-07T12:52:06,429][DEBUG][logstash.outputs.exec] running exec command {:command=\>"curl -X POST '[https://api.ontraport.com/1/objects\](https://api.ontraport.com/1/objects%5C)' --header 'Content-Type: application/json' --header 'Api-Key: XYZXYZXYZ' --header 'Api-Appid: ABCABCABCABC' -d '{\"objectID\": 0}'"}

[2019-06-07T12:52:08,034][DEBUG][logstash.outputs.exec] debugging command {:stdout=\>"Invalid request. Could not parse JSON."

Can a Logstash expert please tell me if this is a config problem on my side or a bug?

I have tried this using version 6.2.4 and 7.1.1 and I am running logstash on a Mac OSX right now

thanks.

---

<div class="post-metadata">

**Author:** ![danhermann](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/danhermann/32/33024_2.png) [@danhermann](https://discuss.elastic.co/u/danhermann)\
**Post date:** [June 19, 2019, 12:25pm UTC](https://discuss.elastic.co/t/logstash-exec-curl-cant-create-valid-json/185301/2 "2019-06-19T12:25:09Z")

</div>

@johnwood, I would suggest escaping the quotes around your JSON content and ensuring that the `config.support_escapes` setting is enabled per the docs:

[https://www.elastic.co/guide/en/logstash/master/configuration-file-structure.html#\_escape\_sequences](https://www.elastic.co/guide/en/logstash/master/configuration-file-structure.html#_escape_sequences)

---

<div class="post-metadata">

**Author:** ![johnwood](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/johnwood/32/78918_2.png) [@johnwood](https://discuss.elastic.co/u/johnwood)\
**Post date:** [June 23, 2019, 12:43am UTC](https://discuss.elastic.co/t/logstash-exec-curl-cant-create-valid-json/185301/3 "2019-06-23T00:43:09Z")

</div>

Thank you Dan - that worked perfectly - I will update the support ticket too so there is a reference over there should this come up again.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 21, 2019, 12:43am UTC](https://discuss.elastic.co/t/logstash-exec-curl-cant-create-valid-json/185301/4 "2019-07-21T00:43:10Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
