# \[Logstash OSS\] Invalid UTF-8 start byte issue

**URL:** <https://discuss.elastic.co/t/logstash-oss-invalid-utf-8-start-byte-issue/323772>\
**Category:** Logstash\
**Tags:** docker\
**Created:** [January 23, 2023, 10:30pm UTC](https://discuss.elastic.co/t/logstash-oss-invalid-utf-8-start-byte-issue/323772 "2023-01-23T22:30:27Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![dstepanov25](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dstepanov25/32/116303_2.png) [@dstepanov25](https://discuss.elastic.co/u/dstepanov25)\
**Post date:** [January 23, 2023, 10:30pm UTC](https://discuss.elastic.co/t/logstash-oss-invalid-utf-8-start-byte-issue/323772/1 "2023-01-23T22:30:28Z")

</div>

**Describe the bug**  
It's not possible to save item with non-ASCII characters into OpenSearch

**To Reproduce**  
Steps to reproduce the behavior:

1. Run OpenSearch in a Docker container:

> docker run -d -p 9200:9200 -p 9600:9600 -e "discovery.type=single-node" -e "plugins.security.disabled=true" opensearchproject/opensearch:latest

1. Setup and install logstash-oss-8-5-2 (Windows)
2. Install logstash-output-opensearch plugin:

> \<path/to/your/logstash/dir\>/bin/logstash-plugin install --version 2.0.0 logstash-output-opensearch

1. Use below sample code to run the logstash, save file as logstash-example.conf

```auto
input {
    stdin { } 
}

filter {
# if you remove letter 'ß' error will dissapear
    mutate { add_field => { "name" => "Groß" } }    
    prune { whitelist_names => ["^name$"] }
}

output {
    opensearch {
        hosts => ["localhost:9200"]
        auth_type => {
            type => 'basic'
            user => 'admin'
            password => 'admin'
        }
        index => "test_index"
        action => "index"
    }
}

```

1. Run the logstash as:

> \<path/to/your/logstash/dir\>/bin/logstash -f logstash-example.conf

1. Type any text into std input, press enter
2. See the error:

> "status"=\>400, "error"=\>{"type"=\>"mapper\_parsing\_exception", "reason"=\>"failed to parse", "caused\_by"=\>{"type"=\>"json\_parse\_exception", "reason"=\>"Invalid UTF-8 start byte 0xa0\n at [Source: (byte)"{"event":{"original":"\r"},"message":"\r","[@timestamp](https://github.com/timestamp)":"2023-01-19T11:07:14.447970Z","name":"Gro∩┐╜","host":{"hostname":"DESKTOP-SP31NNN"},"[@Version](https://github.com/Version)":"1"}"; line: 1, column: 98]

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 23, 2023, 10:30pm UTC](https://discuss.elastic.co/t/logstash-oss-invalid-utf-8-start-byte-issue/323772/2 "2023-01-23T22:30:28Z")

</div>

OpenSearch/OpenDistro are AWS run products and differ from the original Elasticsearch and Kibana products that Elastic builds and maintains. You may need to contact them directly for further assistance.

(This is an automated response from your friendly Elastic bot. Please report this post if you have any suggestions or concerns :elasticheart: )

---

<div class="post-metadata">

**Author:** ![dstepanov25](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dstepanov25/32/116303_2.png) [@dstepanov25](https://discuss.elastic.co/u/dstepanov25)\
**Post date:** [January 23, 2023, 10:36pm UTC](https://discuss.elastic.co/t/logstash-oss-invalid-utf-8-start-byte-issue/323772/3 "2023-01-23T22:36:21Z")

</div>

Here I provided more details when investigated the issue [[BUG] Invalid UTF-8 start byte issue · Issue #187 · opensearch-project/logstash-output-opensearch · GitHub](https://github.com/opensearch-project/logstash-output-opensearch/issues/187)

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [January 23, 2023, 11:02pm UTC](https://discuss.elastic.co/t/logstash-oss-invalid-utf-8-start-byte-issue/323772/4 "2023-01-23T23:02:30Z")

</div>

Hi @dstepanov25 You are in the wrong community, this community forum for Elasticsearch and does not support Opensearch nor the Opensearch Logstash output plugin so we can not help with that. I suspect you need to visit the [Opensearch forum](https://forum.opensearch.org/).

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [January 23, 2023, 11:03pm UTC](https://discuss.elastic.co/t/logstash-oss-invalid-utf-8-start-byte-issue/323772/5 "2023-01-23T23:03:00Z")

</div>

Can you replicate the issue using Logstash-OSS and the `elasticsearch` output pointing to a Elasticsearch cluster?

If you cannot replicate the issue with the above configuration, then the issue may be in the `logstash-output-opensearch`, which is not developed by Elastic and you will need to check this in the Opensearch forum.

---

<div class="post-metadata">

**Author:** ![Rios](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rios/32/95745_2.png) [@Rios](https://discuss.elastic.co/u/Rios)\
**Post date:** [January 23, 2023, 11:22pm UTC](https://discuss.elastic.co/t/logstash-oss-invalid-utf-8-start-byte-issue/323772/6 "2023-01-23T23:22:04Z")

</div>

It's working normally on the LS standard version 8.5.3

```auto
filter {
    mutate { add_field => { "name1" => "Groß" } }     
    mutate { add_field => { "name2" => "Groß" } }     
    mutate { gsub => ["name2","ß","ößü"] }   
}

```

Result:

```auto
{
    "name2" => "Groößü",
    "name1" => "Groß"
}

```

Might be related to Docker and local settings, check [here](https://stackoverflow.com/questions/27931668/encoding-problems-when-running-an-app-in-docker-python-java-ruby-with-u).  
Can you check your locale settings:  
**localectl status**

---

<div class="post-metadata">

**Author:** ![dstepanov25](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dstepanov25/32/116303_2.png) [@dstepanov25](https://discuss.elastic.co/u/dstepanov25)\
**Post date:** [January 24, 2023, 11:25am UTC](https://discuss.elastic.co/t/logstash-oss-invalid-utf-8-start-byte-issue/323772/7 "2023-01-24T11:25:38Z")

</div>

Hi, this issue also reproduced for Elasticsearch output plugin. I can change my examlpe

---

<div class="post-metadata">

**Author:** ![dstepanov25](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dstepanov25/32/116303_2.png) [@dstepanov25](https://discuss.elastic.co/u/dstepanov25)\
**Post date:** [January 24, 2023, 11:32am UTC](https://discuss.elastic.co/t/logstash-oss-invalid-utf-8-start-byte-issue/323772/8 "2023-01-24T11:32:03Z")

</div>

Yes, I can reproduce it for Elasticsearch as well.  
I tried to execute the script for Elasticsearch 8.6.0 and received the same error.

> docker run -p 9200:9200 -p 9300:9300 -e "discovery.type=single-node" -e "xpack.security.enabled=false" [docker.elastic.co/elasticsearch/elasticsearch:8.6.0](http://docker.elastic.co/elasticsearch/elasticsearch:8.6.0)

```auto
...
output {
    elasticsearch {
        hosts => ["localhost:9200"]
        index => "test_index"
        action => "index"
    }
}

```

I tried this scenario with Logstash-8-6-0 and with Logstash-OSS-8-6-0.  
The issue is reproduced only with OSS version

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 21, 2023, 11:32am UTC](https://discuss.elastic.co/t/logstash-oss-invalid-utf-8-start-byte-issue/323772/9 "2023-02-21T11:32:41Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
