# Logstash GELF input Json ParserError

**URL:** <https://discuss.elastic.co/t/logstash-gelf-input-json-parsererror/287159>\
**Category:** Logstash\
**Tags:** docker\
**Created:** [October 20, 2021, 7:33am UTC](https://discuss.elastic.co/t/logstash-gelf-input-json-parsererror/287159 "2021-10-20T07:33:57Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Stian\_Vale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stian_vale/32/96106_2.png) [@Stian\_Vale](https://discuss.elastic.co/u/Stian_Vale)\
**Post date:** [October 20, 2021, 7:33am UTC](https://discuss.elastic.co/t/logstash-gelf-input-json-parsererror/287159/1 "2021-10-20T07:33:57Z")

</div>

Hi!  
I'm experiencing an issue with the Logstash GELF input related to JSON parsing. It seems that there's some messages from Graylog that causes these errors:

```auto
[2021-10-20T05:21:59,443][ERROR][logstash.inputs.gelf][ppt_graylog_ingest][gelf-windows-udp] JSON parse failure. Falling back to plain-text {:error=>#<LogStash::Json::ParserError: Unrecognized token 'Exception': was expecting ('true', 'false' or 'null')
 at [Source: (byte[])"Exception: Failed to decode data: invalid compressed data -- crc error"; line: 1, column: 11]>, :data=>"\"Exception: Failed to decode data: invalid compressed data -- crc error\""}

[2021-10-20T05:54:36,944][ERROR][logstash.inputs.gelf][ppt_graylog_ingest][gelf-windows-udp] JSON parse failure. Falling back to plain-text {:error=>#<LogStash::Json::ParserError: Unrecognized token 'Exception': was expecting ('true', 'false' or 'null')
 at [Source: (byte[])"Exception: Failed to decode data: Unexpected end of ZLIB input stream"; line: 1, column: 11]>, :data=>"\"Exception: Failed to decode data: Unexpected end of ZLIB input stream\""}

```

However, I don't see why there's a Json ParserError in this case, as the plugin configuration doesn't try to cast the input to json:

```auto
input {
    gelf {
            id => "gelf-windows-udp"
            use_tcp => false
            use_udp => true
            port_udp => 12205
            remap => true
    }
}

```

Setup:

- ELK Stack v 7.14.0
- Logstash v 7.14.0
- Logstash-input-gelf v 3.3.0

Do you have any thoughts on why this happens?

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [October 20, 2021, 1:30pm UTC](https://discuss.elastic.co/t/logstash-gelf-input-json-parsererror/287159/2 "2021-10-20T13:30:42Z")

</div>

> [@Stian\_Vale](#):
>
> the plugin configuration doesn't try to cast the input to json

[GELF is JSON](https://docs.graylog.org/docs/gelf#gelf-payload-specification). If it is not valid JSON then it is not valid GELF.

---

<div class="post-metadata">

**Author:** ![Stian\_Vale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stian_vale/32/96106_2.png) [@Stian\_Vale](https://discuss.elastic.co/u/Stian_Vale)\
**Post date:** [October 20, 2021, 1:33pm UTC](https://discuss.elastic.co/t/logstash-gelf-input-json-parsererror/287159/3 "2021-10-20T13:33:51Z")

</div>

Thanks for your reply. Yeah, but as this message comes from Graylog, I would assume that it was already JSON.

However, I suspect that this issue might be related to the UDP buffer queue being filled up, I've increased the max size of that, and I'll observe whether that fixes the issue.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 17, 2021, 1:34pm UTC](https://discuss.elastic.co/t/logstash-gelf-input-json-parsererror/287159/4 "2021-11-17T13:34:21Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
