# Logstash sending json written by Java

**URL:** <https://discuss.elastic.co/t/logstash-sending-json-written-by-java/187583>\
**Category:** Logstash\
**Created:** [June 26, 2019, 1:47pm UTC](https://discuss.elastic.co/t/logstash-sending-json-written-by-java/187583 "2019-06-26T13:47:39Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![nhbala](https://avatars.discourse-cdn.com/v4/letter/n/a9adbd/32.png) [@nhbala](https://discuss.elastic.co/u/nhbala)\
**Post date:** [June 26, 2019, 1:47pm UTC](https://discuss.elastic.co/t/logstash-sending-json-written-by-java/187583/1 "2019-06-26T13:47:39Z")

</div>

I currently have code that writes a json array to a file. However, logstash only seems to attempt to parse it if I manually go in and touch the file myself, rather than take it in after the initial writing to the file. How could I change this behavior so that the json array is sent to logstash as soon as the initial write in my java program occurs? My config file is as follows:

```auto
input{
 file{
        path => "/root/test_last/complete/example.json"
        codec => "json"
        start_position => "beginning"
        ignore_older => 0
 }
}
filter {
    mutate {
            gsub => ["message","\[",""]
            gsub => ["message","\n",""]
            gsub => ["event","\},\{",","]
        }
    json { source => message }
}

output{
    stdout { codec => rubydebug }
}
```

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [June 26, 2019, 2:08pm UTC](https://discuss.elastic.co/t/logstash-sending-json-written-by-java/187583/2 "2019-06-26T14:08:22Z")

</div>

> [@nhbala](#):
>
> file{ path =\> "/root/test\_last/complete/example.json" codec =\> "json" start\_position =\> "beginning" ignore\_older =\> 0 }

'ignore\_older =\> 0' says to ignore any files more than zero seconds old, which is all files. You should remove this option.

When you say you are writing an array to the file does that mean you are appending to it?

It is unlikely you want both a json codec and a json filter. And if you have a json codec on a file input you do not have a field called message, so your filters will have no effect.

---

<div class="post-metadata">

**Author:** ![nhbala](https://avatars.discourse-cdn.com/v4/letter/n/a9adbd/32.png) [@nhbala](https://discuss.elastic.co/u/nhbala)\
**Post date:** [June 26, 2019, 2:53pm UTC](https://discuss.elastic.co/t/logstash-sending-json-written-by-java/187583/3 "2019-06-26T14:53:05Z")

</div>

Just a singular array containing a bunch of json objects.

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [June 26, 2019, 3:04pm UTC](https://discuss.elastic.co/t/logstash-sending-json-written-by-java/187583/4 "2019-06-26T15:04:06Z")

</div>

OK, so if you remove the ignore\_older option does it work as expected?

---

<div class="post-metadata">

**Author:** ![nhbala](https://avatars.discourse-cdn.com/v4/letter/n/a9adbd/32.png) [@nhbala](https://discuss.elastic.co/u/nhbala)\
**Post date:** [June 26, 2019, 3:11pm UTC](https://discuss.elastic.co/t/logstash-sending-json-written-by-java/187583/5 "2019-06-26T15:11:55Z")

</div>

I start getting this error in terms of parsing:

`exception=>#<LogStash::Json::ParserError: Unexpected character (':' (code 58)): expected a valid value (number, String, array, object, 'true', 'false' or 'null')`

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [June 26, 2019, 3:30pm UTC](https://discuss.elastic.co/t/logstash-sending-json-written-by-java/187583/6 "2019-06-26T15:30:26Z")

</div>

Your JSON is not valid JSON. For example, this will produce that error

```
[{ "foo" :: 1 }]
```

---

<div class="post-metadata">

**Author:** ![nhbala](https://avatars.discourse-cdn.com/v4/letter/n/a9adbd/32.png) [@nhbala](https://discuss.elastic.co/u/nhbala)\
**Post date:** [June 26, 2019, 3:35pm UTC](https://discuss.elastic.co/t/logstash-sending-json-written-by-java/187583/7 "2019-06-26T15:35:33Z")

</div>

Hm, thats interesting because I put my json through a jsonlint to validate it and it said it was a valid json...

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 24, 2019, 3:35pm UTC](https://discuss.elastic.co/t/logstash-sending-json-written-by-java/187583/8 "2019-07-24T15:35:45Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
