Hi Rios,
Sorry, i wrote wrong, you are correct, the json is "id": 123.
This is the original string
{ "time": "2022-11-06T23:21:54+00:00", "client": "1212", "session_id": "-", "stream": "-", "host": "hom.app.com", "request_time": "0.000", "request_method": "GET", "status": "400", "proxy_status": "-", "scheme": "http", "request_uri": "/heapdump", "request_length": "251", "bytes_sent": "208", "tcpinfo_rtt": "142131", "upstream_cache_status": "-", "upstream_status": "-", "upstream_bytes_received": "-", "upstream_connect_time": "-", "upstream_header_time": "-", "upstream_response_time": "-", "upstream_addr": "-", "upstream_bytes_sent": "-", "sent_http_content_type": "application/json", "http_user_agent": "Mozilla/5.0 (Windows NT 5.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/36.0.1985.67 Safari/537.36", "http_referer": "-", "sent_http_x_original_image_size": "-", "server_protocol": "HTTP/1.1", "server_port": "80", "server_addr": "54.23.12.22", "remote_addr": "54.33.92.80", "remote_port": "42398", "waf_attack_family": "-", "waf_attack_action": "-", "waf_learning": "-", "waf_block": "-", "waf_total_processed": "0", "waf_total_blocked": "0", "waf_score": "-", "waf_match": "-", "waf_headers": "-", "country": "Brazil", "state": "Sao Paulo", "asn": "AS16509 AMAZON-02", "ssl_protocol": "-", "ssl_cipher": "-", "ssl_session_reused": "-", "ssl_server_name": "-", "request_id": "615af3c3a0527c1582f0c09ddb4212e2", "requestPath": "/heapdump", "requestQuery": "", "configuration": "1633703625" }
{ "time": "2022-11-06T23:22:48+00:00", "client": "1212", "session_id": "-", "stream": "-", "host": "hom.app.com", "request_time": "0.000", "request_method": "GET", "status": "400", "proxy_status": "-", "scheme": "https", "request_uri": "/config/", "request_length": "263", "bytes_sent": "208", "tcpinfo_rtt": "143154", "upstream_cache_status": "-", "upstream_status": "-", "upstream_bytes_received": "-", "upstream_connect_time": "-", "upstream_header_time": "-", "upstream_response_time": "-", "upstream_addr": "-", "upstream_bytes_sent": "-", "sent_http_content_type": "application/json", "http_user_agent": "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.3538.77 Safari/537.36", "http_referer": "-", "sent_http_x_original_image_size": "-", "server_protocol": "HTTP/1.1", "server_port": "443", "server_addr": "54.23.12.22", "remote_addr": "54.33.92.80", "remote_port": "41412", "waf_attack_family": "-", "waf_attack_action": "-", "waf_learning": "-", "waf_block": "-", "waf_total_processed": "0", "waf_total_blocked": "0", "waf_score": "-", "waf_match": "-", "waf_headers": "-", "country": "Brazil", "state": "Sao Paulo", "asn": "AS16509 AMAZON-02", "ssl_protocol": "TLSv1.3", "ssl_cipher": "TLS_AES_256_GCM_SHA384", "ssl_session_reused": ".", "ssl_server_name": "hom.app.com.br", "request_id": "1ab3ccb50e83312722354a51c703a19f", "requestPath": "/config/", "requestQuery": "", "configuration": "1633703625" }
{ "time": "2022-11-06T23:22:44+00:00", "client": "1212", "session_id": "-", "stream": "-", "host": "hom.app.com", "request_time": "0.000", "request_method": "GET", "status": "400", "proxy_status": "-", "scheme": "http", "request_uri": "/console.html", "request_length": "418", "bytes_sent": "208", "tcpinfo_rtt": "142426", "upstream_cache_status": "-", "upstream_status": "-", "upstream_bytes_received": "-", "upstream_connect_time": "-", "upstream_header_time": "-", "upstream_response_time": "-", "upstream_addr": "-", "upstream_bytes_sent": "-", "sent_http_content_type": "application/json", "http_user_agent": "Mozilla/5.0 (Windows NT 5.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/36.0.1985.67 Safari/537.36", "http_referer": "-", "sent_http_x_original_image_size": "-", "server_protocol": "HTTP/1.1", "server_port": "80", "server_addr": "54.23.12.22", "remote_addr": "54.33.92.80", "remote_port": "46478", "waf_attack_family": "-", "waf_attack_action": "-", "waf_learning": "-", "waf_block": "-", "waf_total_processed": "0", "waf_total_blocked": "0", "waf_score": "-", "waf_match": "-", "waf_headers": "-", "country": "Brazil", "state": "Sao Paulo", "asn": "AS16509 AMAZON-02", "ssl_protocol": "-", "ssl_cipher": "-", "ssl_session_reused": "-", "ssl_server_name": "-", "request_id": "ca1048d658008aa82f49085e3ebb47ac", "requestPath": "console.html", "requestQuery": "", "configuration": "1633703625" }
{ "time": "2022-11-06T23:22:46+00:00", "client": "1212", "session_id": "-", "stream": "-", "host": "hom.app.com", "request_time": "0.000", "request_method": "GET", "status": "400", "proxy_status": "-", "scheme": "http", "request_uri": "/redirect.php", "request_length": "377", "bytes_sent": "208", "tcpinfo_rtt": "143804", "upstream_cache_status": "-", "upstream_status": "-", "upstream_bytes_received": "-", "upstream_connect_time": "-", "upstream_header_time": "-", "upstream_response_time": "-", "upstream_addr": "-", "upstream_bytes_sent": "-", "sent_http_content_type": "application/json", "http_user_agent": "Mozilla/5.0 (X11; OpenBSD i386) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/36.0.1985.125 Safari/537.36", "http_referer": "-", "sent_http_x_original_image_size": "-", "server_protocol": "HTTP/1.1", "server_port": "80", "server_addr": "54.23.12.22", "remote_addr": "54.33.92.80", "remote_port": "44980", "waf_attack_family": "-", "waf_attack_action": "-", "waf_learning": "-", "waf_block": "-", "waf_total_processed": "0", "waf_total_blocked": "0", "waf_score": "-", "waf_match": "-", "waf_headers": "-", "country": "Brazil", "state": "Sao Paulo", "asn": "AS16509 AMAZON-02", "ssl_protocol": "-", "ssl_cipher": "-", "ssl_session_reused": "-", "ssl_server_name": "-", "request_id": "fe81bb65f4f3f320e00230ad8be0d74b", "requestPath": " redirect.php", "requestQuery": "/", "configuration": "1633703625" }
{ "time": "2022-11-06T23:22:45+00:00", "client": "1212", "session_id": "-", "stream": "-", "host": "hom.app.com", "request_time": "0.000", "request_method": "GET", "status": "400", "proxy_status": "-", "scheme": "http", "request_uri": "/download.php?file=invoice.pdf", "request_length": "276", "bytes_sent": "208", "tcpinfo_rtt": "142362", "upstream_cache_status": "-", "upstream_status": "-", "upstream_bytes_received": "-", "upstream_connect_time": "-", "upstream_header_time": "-", "upstream_response_time": "-", "upstream_addr": "-", "upstream_bytes_sent": "-", "sent_http_content_type": "application/json", "http_user_agent": "Mozilla/5.0 (X11; OpenBSD i386) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/36.0.1985.125 Safari/537.36", "http_referer": "-", "sent_http_x_original_image_size": "-", "server_protocol": "HTTP/1.1", "server_port": "80", "server_addr": "54.23.12.22", "remote_addr": "54.33.92.80", "remote_port": "46568", "waf_attack_family": "-", "waf_attack_action": "-", "waf_learning": "-", "waf_block": "-", "waf_total_processed": "0", "waf_total_blocked": "0", "waf_score": "-", "waf_match": "-", "waf_headers": "-", "country": "Brazil", "state": "Sao Paulo", "asn": "AS16509 AMAZON-02", "ssl_protocol": "-", "ssl_cipher": "-", "ssl_session_reused": "-", "ssl_server_name": "-", "request_id": "82579e372c4f027da194ef4a81b328e6", "requestPath": "/download.php", "requestQuery": "file=/etc/passwd", "configuration": "1633703625" }
Applying your suggested the error changes to bellow.
Error parsing json {:source=>"message", :raw=>"POST / HTTP/1.1\rContent-Type: application/json\rcontent-length: 17969\rhost: 52.45.8.88:8080\raccept: */*\ruser-agent: AHC/2.1\r\r", :exception=>#<LogStash::Json::ParserError: Unrecognized token 'POST': was expecting (JSON String, Number, Array, Object or token 'null', 'true' or 'false')
Error parsing json {:source=>"message", :raw=>"POST / HTTP/1.1\rContent-Type: application/json\rcontent-length: 12225\rhost: 52.45.8.88:8080\raccept: */*\ruser-agent: AHC/2.1\r\r", :exception=>#<LogStash::Json::ParserError: Unrecognized token 'POST': was expecting (JSON String, Number, Array, Object or token 'null', 'true' or 'false')
Error parsing json {:source=>"message", :raw=>"POST / HTTP/1.1\rContent-Type: application/json\rcontent-length: 18604\rhost: 52.45.8.88:8080\raccept: */*\ruser-agent: AHC/2.1\r\r", :exception=>#<LogStash::Json::ParserError: Unrecognized token 'POST': was expecting (JSON String, Number, Array, Object or token 'null', 'true' or 'false')
Error parsing json {:source=>"message", :raw=>"POST / HTTP/1.1\rContent-Type: application/json\rcontent-length: 62574\rhost: 52.45.8.88:8080\raccept: */*\ruser-agent: AHC/2.1\r\r", :exception=>#<LogStash::Json::ParserError: Unrecognized token 'POST': was expecting (JSON String, Number, Array, Object or token 'null', 'true' or 'false')
Error parsing json {:source=>"message", :raw=>"POST / HTTP/1.1\rContent-Type: application/json\rcontent-length: 7675\rhost: 52.45.8.88:8080\raccept: */*\ruser-agent: AHC/2.1\r\r", :exception=>#<LogStash::Json::ParserError: Unrecognized token 'POST': was expecting (JSON String, Number, Array, Object or token 'null', 'true' or 'false')