# Logstash raising json\_e\_o\_f\_exception when input events are coming from elastisearch

**URL:** https://discuss.elastic.co/t/logstash-raising-json-e-o-f-exception-when-input-events-are-coming-from-elastisearch/127635
**Category:** Logstash
**Created:** [April 11, 2018, 1:07pm UTC](https://discuss.elastic.co/t/logstash-raising-json-e-o-f-exception-when-input-events-are-coming-from-elastisearch/127635 "2018-04-11T13:07:57Z")
**Posts on this page:** 4
**Page:** 1

<div class="post-metadata">

### Author: ![Zhihai\_Xian](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/zhihai_xian/32/105667_2.png) [@Zhihai\_Xian](https://discuss.elastic.co/u/Zhihai_Xian)
#### Post date: [April 11, 2018, 1:07pm UTC](https://discuss.elastic.co/t/logstash-raising-json-e-o-f-exception-when-input-events-are-coming-from-elastisearch/127635/1 "2018-04-11T13:07:57Z")

</div>

Here is my configuration file

input {  
elasticsearch {  
hosts =\> ["[XXXXXXXXXXXXXX.ap-southeast-1.es.amazonaws.com:443](http://XXXXXXXXXXXXXX.ap-southeast-1.es.amazonaws.com:443)"]  
index =\> "transcripts"  
query =\> '{ "query": { "match\_all": {} }'  
scroll =\> "5m"  
size =\> 100  
ssl =\> true   
}  
}

filter {

}

output{

stdout { codec =\> rubydebug}  
}

I use logstash v6.2.2 to remotely read elasticsearch v6.0.1 in aws.

Logs showed json\_e\_o\_f\_exception and 500 Internal Server Error

The following are the error logs.

[ERROR] 2018-04-11 20:53:42.610 [[main]\<elasticsearch] pipeline - A plugin had an unrecoverable error. Will restart this plugin.  
Pipeline\_id:main  
Plugin: \<LogStash::Inputs::Elasticsearch hosts=\>["[XXXXXXXXXXXXXX.ap-southeast-1.es.amazonaws.com:443](http://XXXXXXXXXXXXXX.ap-southeast-1.es.amazonaws.com:443)"], query=\>"{ "query": { "match\_all": {} }", scroll=\>"5m", ssl=\>true, size=\>100, docinfo=\>true, index=\>"transcripts", id=\>"cc6608de73166f4d5d5874033fff0850fac5f2049b235c959825eb45154f8b81", enable\_metric=\>true, codec=\>\<LogStash::Codecs::JSON id=\>"json\_16f75b5b-fdb8-4417-ac40-ccaab3f95010", enable\_metric=\>true, charset=\>"UTF-8"\>, docinfo\_target=\>"@metadata", docinfo\_fields=\>["\_index", "\_type", "\_id"]\>  
Error: [500] {"error":{"root\_cause":[{"type":"json\_e\_o\_f\_exception","reason":"Unexpected end-of-input: expected close marker for Object (start marker at [Source: org.elasticsearch.common.bytes.BytesReference$MarkSupportingStreamInputWrapper@254304b2; line: 1, column: 1])\n at [Source: org.elasticsearch.common.bytes.BytesReference$MarkSupportingStreamInputWrapper@254304b2; line: 1, column: 61]"}],"type":"json\_e\_o\_f\_exception","reason":"Unexpected end-of-input: expected close marker for Object (start marker at [Source: org.elasticsearch.common.bytes.BytesReference$MarkSupportingStreamInputWrapper@254304b2; line: 1, column: 1])\n at [Source: org.elasticsearch.common.bytes.BytesReference$MarkSupportingStreamInputWrapper@254304b2; line: 1, column: 61]"},"status":500}  
Exception: Elasticsearch::Transport::Transport::Errors::InternalServerError  
Stack: /usr/share/logstash/vendor/bundle/jruby/2.3.0/gems/elasticsearch-transport-5.0.4/lib/elasticsearch/transport/transport/base.rb:202:in `__raise_transport_error' /usr/share/logstash/vendor/bundle/jruby/2.3.0/gems/elasticsearch-transport-5.0.4/lib/elasticsearch/transport/transport/base.rb:319:in`perform\_request'  
/usr/share/logstash/vendor/bundle/jruby/2.3.0/gems/elasticsearch-transport-5.0.4/lib/elasticsearch/transport/transport/http/faraday.rb:20:in `perform_request' /usr/share/logstash/vendor/bundle/jruby/2.3.0/gems/elasticsearch-transport-5.0.4/lib/elasticsearch/transport/client.rb:131:in`perform\_request'  
/usr/share/logstash/vendor/bundle/jruby/2.3.0/gems/elasticsearch-api-5.0.4/lib/elasticsearch/api/actions/search.rb:183:in `search' /usr/share/logstash/vendor/bundle/jruby/2.3.0/gems/logstash-input-elasticsearch-4.2.0/lib/logstash/inputs/elasticsearch.rb:200:in`do\_run'  
/usr/share/logstash/vendor/bundle/jruby/2.3.0/gems/logstash-input-elasticsearch-4.2.0/lib/logstash/inputs/elasticsearch.rb:188:in `run' /usr/share/logstash/logstash-core/lib/logstash/pipeline.rb:516:in`inputworker'  
/usr/share/logstash/logstash-core/lib/logstash/pipeline.rb:509:in `block in start\_input'

Any help is much appreciated.

---

<div class="post-metadata">

### Author: ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)
#### Post date: [April 11, 2018, 5:51pm UTC](https://discuss.elastic.co/t/logstash-raising-json-e-o-f-exception-when-input-events-are-coming-from-elastisearch/127635/2 "2018-04-11T17:51:35Z")

</div>

There's a `}` missing from your query.

---

<div class="post-metadata">

### Author: ![Zhihai\_Xian](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/zhihai_xian/32/105667_2.png) [@Zhihai\_Xian](https://discuss.elastic.co/u/Zhihai_Xian)
#### Post date: [April 11, 2018, 11:25pm UTC](https://discuss.elastic.co/t/logstash-raising-json-e-o-f-exception-when-input-events-are-coming-from-elastisearch/127635/3 "2018-04-11T23:25:31Z")

</div>

Thank you very much

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [May 9, 2018, 11:25pm UTC](https://discuss.elastic.co/t/logstash-raising-json-e-o-f-exception-when-input-events-are-coming-from-elastisearch/127635/4 "2018-05-09T23:25:32Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
