# Logstash fail to rewrite json files

**URL:** <https://discuss.elastic.co/t/logstash-fail-to-rewrite-json-files/302942>\
**Category:** Logstash\
**Created:** [April 21, 2022, 3:52pm UTC](https://discuss.elastic.co/t/logstash-fail-to-rewrite-json-files/302942 "2022-04-21T15:52:00Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Math](https://avatars.discourse-cdn.com/v4/letter/m/ea666f/32.png) [@Math](https://discuss.elastic.co/u/Math)\
**Post date:** [April 21, 2022, 3:52pm UTC](https://discuss.elastic.co/t/logstash-fail-to-rewrite-json-files/302942/1 "2022-04-21T15:52:00Z")

</div>

Hi,  
I want to send json files with filebeat to logstash and then logstash rewrite these json files locally.

Filebeat version: 8.1.2  
Logstash version: 8.1.2

There is my filebeat conf:

```auto
filebeat.inputs:

- type: filestream

  paths:
    - /path/to/json/*

output.logstash:
  hosts: ["192.168.1.15:5044"]

```

There is my logstash conf:

```auto
input {
  beats {
    port => 5044
  }
}

filter {
  ruby {
    code => 'event.set("filename", event.get("[log][file][path]").split("/").last)'
  }
}

output {
  file {
    path => "/path/to/write/json/%{filename}"
    codec => line { format => "%{message}" }
  }
}

```

For example i send this json file to logstash with filebeat:

```auto
{"widget": {
    "debug": "on",
    "window": {
        "title": "Sample Konfabulator Widget",
        "name": "main_window",
        "width": 500,
        "height": 500
    },
    "image": { 
        "src": "Images/Sun.png",
        "name": "sun1",
        "hOffset": 250,
        "vOffset": 250,
        "alignment": "center"
    },
    "text": {
        "data": "Click Here",
        "size": 36,
        "style": "bold",
        "name": "text1",
        "hOffset": 250,
        "vOffset": 100,
        "alignment": "center",
        "onMouseUp": "sun1.opacity = (sun1.opacity / 100) * 90;"
    }
}}

```

And then logstash rewrite this json as:

```auto
    "debug": "on",
    "window": {
        "vOffset": 100,
}}
{"widget": {
    "text": {
        "data": "Click Here",
        "size": 36,
        "style": "bold",
        "name": "text1",
        "hOffset": 250,
        "onMouseUp": "sun1.opacity = (sun1.opacity / 100) * 90;"
    }
        "title": "Sample Konfabulator Widget",
        "name": "main_window",
        "width": 500,
        "height": 500
    },
    "image": { 
        "src": "Images/Sun.png",
        "name": "sun1",
        "hOffset": 250,
        "vOffset": 250,
        "alignment": "center"
    },
        "alignment": "center",

```

There is exactly the same number of character/line between those two files but the lines are not in same order, so the json becomes invalid.  
Do you have a solution for this issue ?  
Thanks.

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [April 21, 2022, 4:41pm UTC](https://discuss.elastic.co/t/logstash-fail-to-rewrite-json-files/302942/2 "2022-04-21T16:41:16Z")

</div>

> [@Math](#):
>
> but the lines are not in same order, so the json becomes invalid.

Take a look at the [pipeline.ordered](https://www.elastic.co/guide/en/logstash/current/processing.html) option.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 19, 2022, 4:41pm UTC](https://discuss.elastic.co/t/logstash-fail-to-rewrite-json-files/302942/3 "2022-05-19T16:41:20Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
