# LogStash::Json::ParserError

**URL:** <https://discuss.elastic.co/t/logstash-parsererror/250809>\
**Category:** Logstash\
**Created:** [October 2, 2020, 3:10pm UTC](https://discuss.elastic.co/t/logstash-parsererror/250809 "2020-10-02T15:10:03Z")\
**Posts on this page:** 11\
**Page:** 1

<div class="post-metadata">

**Author:** ![Raiderume](https://avatars.discourse-cdn.com/v4/letter/r/a6a055/32.png) [@Raiderume](https://discuss.elastic.co/u/Raiderume)\
**Post date:** [October 2, 2020, 3:10pm UTC](https://discuss.elastic.co/t/logstash-parsererror/250809/1 "2020-10-02T15:10:03Z")

</div>

Hello, I have problems with parsing json logs to logstash, there are tons of errors at log:  
Error parsing json {:source=\>"message", :raw=\>"\*\*\*\*", :exception=\>#\<LogStash::Json::ParserError: Invalid UTF-8 start byte 0xa1  
I guess that I need to decode parsed json to UTF-8 charsets but I cannot find how to do it exactly. Can someone point me?

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [October 2, 2020, 4:55pm UTC](https://discuss.elastic.co/t/logstash-parsererror/250809/2 "2020-10-02T16:55:16Z")

</div>

What does the message field look like and what is your logstash configuration?

---

<div class="post-metadata">

**Author:** ![Raiderume](https://avatars.discourse-cdn.com/v4/letter/r/a6a055/32.png) [@Raiderume](https://discuss.elastic.co/u/Raiderume)\
**Post date:** [October 5, 2020, 7:22am UTC](https://discuss.elastic.co/t/logstash-parsererror/250809/3 "2020-10-05T07:22:08Z")

</div>

sorry for long response, full error message:  
Error parsing json {:source=\>"message", :raw=\>"Init", :exception=\>#\<LogStash::Json::ParserError: Invalid UTF-8 start byte 0x98  
at [Source: (byte)"Ð�Ð½Ð"; line: 1, column: 3]\>}  
here is input and filter part of my logstash config file:  
input {  
http {  
host =\> "0.0.0.0"  
port =\> "8002"  
type =\> "logs"  
additional\_codecs =\> {"application/json"=\>"json"}  
}}

filter {

json { source =\> "message" }  
json { source =\> "message" }  
json { source =\> "message" }

mutate { remove\_field =\> ["host", "\_\_rpc\_corr", " **rpc\_node\_id**", " **rpc\_ref\_id**",, "headers"] }  
}

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [October 5, 2020, 2:16pm UTC](https://discuss.elastic.co/t/logstash-parsererror/250809/4 "2020-10-05T14:16:34Z")

</div>

> [@Raiderume](#):
>
> json { source =\> "message" }  
> json { source =\> "message" }  
> json { source =\> "message" }

If you have a message field nested inside a message field nested inside a message field I suggest you add tag\_on\_failure options to those filters so that it is clear which one is failing.

---

<div class="post-metadata">

**Author:** ![Raiderume](https://avatars.discourse-cdn.com/v4/letter/r/a6a055/32.png) [@Raiderume](https://discuss.elastic.co/u/Raiderume)\
**Post date:** [October 6, 2020, 8:00am UTC](https://discuss.elastic.co/t/logstash-parsererror/250809/5 "2020-10-06T08:00:09Z")

</div>

I'm kinda new to configuration of elastic - can you please provide me more detailed steps how to do that?

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [October 6, 2020, 2:27pm UTC](https://discuss.elastic.co/t/logstash-parsererror/250809/6 "2020-10-06T14:27:07Z")

</div>

```
json { source => "message" tag_on_failure => ["_jsonparsefailure", "1st"] }
json { source => "message" tag_on_failure => ["_jsonparsefailure", "2nd"] }
json { source => "message" tag_on_failure => ["_jsonparsefailure", "3rd"] }
```

---

<div class="post-metadata">

**Author:** ![Raiderume](https://avatars.discourse-cdn.com/v4/letter/r/a6a055/32.png) [@Raiderume](https://discuss.elastic.co/u/Raiderume)\
**Post date:** [October 7, 2020, 6:57am UTC](https://discuss.elastic.co/t/logstash-parsererror/250809/7 "2020-10-07T06:57:58Z")

</div>

I've changed filters the way you provided but nothing changed at logs:  
Error parsing json {:source=\>"message", :raw=\>"Ошибка {"status":"error","errorCode":"teach\_session\_decline","message":"Данная фукнция..."}", :exception=\>#\<LogStash::Json::ParserError: Invalid UTF-8 start byte 0x9e  
at [Source: (byte)"Ð�Ñ�Ð {"status":"error","errorCode":"teach\_session\_decline","message":"Ð�Ð°Ð½Ð½Ð¸"}"; line: 1, column: 3]\>}

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [October 7, 2020, 2:11pm UTC](https://discuss.elastic.co/t/logstash-parsererror/250809/8 "2020-10-07T14:11:23Z")

</div>

> [@Raiderume](#):
>
> nothing changed at logs:

I would not expect it to. What tags are present on the event?

---

<div class="post-metadata">

**Author:** ![Raiderume](https://avatars.discourse-cdn.com/v4/letter/r/a6a055/32.png) [@Raiderume](https://discuss.elastic.co/u/Raiderume)\
**Post date:** [October 8, 2020, 10:45am UTC](https://discuss.elastic.co/t/logstash-parsererror/250809/9 "2020-10-08T10:45:52Z")

</div>

Here is full event log:  
[2020-10-08T13:39:40,904][WARN][logstash.filters.json] Error parsing json {:source=\>"message", :raw=\>"Ошибка доступа{"status":"error","errorCode":"teach\_session\_decline","message":"Данная фукнция не доступна"}", :exception=\>#\<LogStash::Json::ParserError: Invalid UTF-8 start byte 0x9e  
at [Source: (byte)"Ð�Ñ� {"status":"error","errorCode":"teach\_session\_decline","message":"Ð�Ð°Ð½"}"; line: 1, column: 3]\>}  
[2020-10-08T13:39:40,904][WARN][logstash.filters.json] Parsed JSON object/hash requires a target configuration option {:source=\>"message", :raw=\>""}  
[2020-10-08T13:39:40,904][WARN][logstash.filters.json] Error parsing json {:source=\>"message", :raw=\>"Создана сессия", :exception=\>#\<LogStash::Json::ParserError: Invalid UTF-8 start byte 0xa1  
at [Source: (byte)"Ð¡Ð¾Ð"; line: 1, column: 3]\>}

Unfortunately I don't see any tags here

---

<div class="post-metadata">

**Author:** ![Raiderume](https://avatars.discourse-cdn.com/v4/letter/r/a6a055/32.png) [@Raiderume](https://discuss.elastic.co/u/Raiderume)\
**Post date:** [October 20, 2020, 9:08am UTC](https://discuss.elastic.co/t/logstash-parsererror/250809/10 "2020-10-20T09:08:59Z")

</div>

I'm still facing this problem. Any help would be appreciated

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 17, 2020, 9:09am UTC](https://discuss.elastic.co/t/logstash-parsererror/250809/11 "2020-11-17T09:09:02Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
