# Logstash JSON parser error

**URL:** <https://discuss.elastic.co/t/logstash-json-parser-error/323356>\
**Category:** Logstash\
**Created:** [January 17, 2023, 6:55pm UTC](https://discuss.elastic.co/t/logstash-json-parser-error/323356 "2023-01-17T18:55:50Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![Ramesh\_Perumal](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ramesh_perumal/32/98764_2.png) [@Ramesh\_Perumal](https://discuss.elastic.co/u/Ramesh_Perumal)\
**Post date:** [January 17, 2023, 6:55pm UTC](https://discuss.elastic.co/t/logstash-json-parser-error/323356/1 "2023-01-17T18:55:50Z")

</div>

Hi,

We are getting json parser warning message as below:

1. [2023-01-08T13:21:12,936][WARN][logstash.filters.json] Error parsing json {:source=\>"slmPart", :raw=\>"{"action":UPDATE,"information":"Signing CSR for root Machine1"}", :exception=\>#\<LogStash::Json::ParserError: Unrecognized token 'UPDATE': was expecting (JSON String, Number, Array, Object or token 'null', 'true' or 'false') at [Source: byte)"{"action":UPDATE,"information":"Signing CSR for root Machine1"}"; line: 1, column: 18]\>}  
[2023-01-08T13:21:12,937][WARN][logstash.filters.json] Error parsing json {:source=\>"slmPart", :raw=\>"{"action":UPDATE,"information":"Instance configuration file has been updated"}", :exception=\>#\<LogStash::Json::ParserError: Unrecognized token 'UPDATE': was expecting (JSON String, Number, Array, Object or token 'null', 'true' or 'false') at [Source: (byte)"{"action":UPDATE,"information":"Instance configuration file has been updated"}"; line: 1, column: 18]\>}

Eventhough logstash config test and exit command returns OK. But, the logtstash writing the above log entries in the log.

Please share your expertise.

Regards,  
Ramesh P

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [January 17, 2023, 7:45pm UTC](https://discuss.elastic.co/t/logstash-json-parser-error/323356/2 "2023-01-17T19:45:34Z")

</div>

> [@Ramesh\_Perumal](#):
>
> {"action":UPDATE,"information":"Instance configuration file has been updated"}

I don't think this is a valid JSON, the `UPDATE` should be between double quotes.

The `json` filter won't be able to parse this message, do you have control on the source that generates this messages to add the double quotes?

---

<div class="post-metadata">

**Author:** ![chris3](https://avatars.discourse-cdn.com/v4/letter/c/65b543/32.png) [@chris3](https://discuss.elastic.co/u/chris3)\
**Post date:** [January 17, 2023, 8:16pm UTC](https://discuss.elastic.co/t/logstash-json-parser-error/323356/3 "2023-01-17T20:16:51Z")

</div>

Hi Ramesh,

I think follow what leandrojmp has mentioned about the json, and the source message. You could test that json here to see if its valid if you have control to access it: [https://jsonlint.com/](https://jsonlint.com/)

Kind Regards,  
Chris

---

<div class="post-metadata">

**Author:** ![Rios](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rios/32/95745_2.png) [@Rios](https://discuss.elastic.co/u/Rios)\
**Post date:** [January 18, 2023, 9:38pm UTC](https://discuss.elastic.co/t/logstash-json-parser-error/323356/4 "2023-01-18T21:38:36Z")

</div>

` logstash config test` is only test your .conf file for instance: json.conf, not data.

As leandrojmp said, your data is not OK, LS will raise the tag: \_jsonparsefailure. Or you have several records OK, then a wrong record. Incorrect data you can handle in output

```auto
output {
 if ("_jsonparsefailure" in [tags]) { 
     elasticsearch {
     hosts => ["http://eshost:9200"]
     index => "error_%{+YYYY.MM}"
     user => "user"
     password => "pass"
  }
 }

```

---

<div class="post-metadata">

**Author:** ![Ramesh\_Perumal](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ramesh_perumal/32/98764_2.png) [@Ramesh\_Perumal](https://discuss.elastic.co/u/Ramesh_Perumal)\
**Post date:** [January 19, 2023, 7:01am UTC](https://discuss.elastic.co/t/logstash-json-parser-error/323356/5 "2023-01-19T07:01:29Z")

</div>

Thanks All for your reply.

I'm getting this warning only at the LS start-up, post-start, it is not getting displayed. But the source data keeps on passing through the LS. Not sure, Why the same is not coming for all the source data.

The same issue is not occurring in the LS version 7.10.2 for the same source data. Whereas the LS version 8.4.0 only throws this warning.

Please share your expertise.

Regards,  
Ramesh P

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 16, 2023, 7:02am UTC](https://discuss.elastic.co/t/logstash-json-parser-error/323356/6 "2023-02-16T07:02:14Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
