# Logstash Unexpected character ('-' (code 45)): was expecting comma to separate Array entries

**URL:** <https://discuss.elastic.co/t/logstash-unexpected-character-code-45-was-expecting-comma-to-separate-array-entries/224821>\
**Category:** Logstash\
**Created:** [March 24, 2020, 11:35am UTC](https://discuss.elastic.co/t/logstash-unexpected-character-code-45-was-expecting-comma-to-separate-array-entries/224821 "2020-03-24T11:35:29Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![Rahul\_Ravichandran](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rahul_ravichandran/32/53882_2.png) [@Rahul\_Ravichandran](https://discuss.elastic.co/u/Rahul_Ravichandran)\
**Post date:** [March 24, 2020, 11:35am UTC](https://discuss.elastic.co/t/logstash-unexpected-character-code-45-was-expecting-comma-to-separate-array-entries/224821/1 "2020-03-24T11:35:30Z")

</div>

Hi i am trying to move my application logs to kibana through logstash.  
1.This is my logstash.conf file:

```auto
input {
     file {
    path => "/home/ubuntu/*"
  }
}
filter {
	  
    json {
        source => "message"
    }
}

output {
  amazon_es {
    hosts => [" *****************************************"]
    region => "us-east-1"
    index => "stash"
    #user => "elastic"
    #password => "changeme"
  }
}

```

1. when i try to run the config file this what the output i get:

`[WARN] 2020-03-24 11:15:34.878 [[main]>worker1] json - Error parsing json {:source=>"message", :raw=>"[2020-03-24 11:15:33] file_db_logger.INFO: {\"Code\":\"BGDRIF947\",\"Message\":\"Total items backup today\",\"time\":1585048533,\"userId\":\" *************\",\"businessUserId\":\"********** \",\"cloudId\":1,\"domainId\":\" **** \",\"additionalInfo\":\"389,395,0\"} [] []", :exception=>#<LogStash::Json::ParserError: Unexpected character ('-' (code 45)): was expecting comma to separate Array entries`

kindly help me out with this

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [March 24, 2020, 12:32pm UTC](https://discuss.elastic.co/t/logstash-unexpected-character-code-45-was-expecting-comma-to-separate-array-entries/224821/2 "2020-03-24T12:32:03Z")

</div>

> [@Rahul\_Ravichandran](#):
>
> raw=\>"[2020-03-24 11:15:33] file\_db\_logger.INFO:

That is not valid JSON. You could parse the prefix off using [dissect](https://discuss.elastic.co/t/how-to-parse-mix-json-logs/167594/2).

---

<div class="post-metadata">

**Author:** ![Rahul\_Ravichandran](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rahul_ravichandran/32/53882_2.png) [@Rahul\_Ravichandran](https://discuss.elastic.co/u/Rahul_Ravichandran)\
**Post date:** [March 24, 2020, 12:51pm UTC](https://discuss.elastic.co/t/logstash-unexpected-character-code-45-was-expecting-comma-to-separate-array-entries/224821/3 "2020-03-24T12:51:42Z")

</div>

Hi Badger, Thank for replying will try it

---

<div class="post-metadata">

**Author:** ![Rahul\_Ravichandran](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rahul_ravichandran/32/53882_2.png) [@Rahul\_Ravichandran](https://discuss.elastic.co/u/Rahul_Ravichandran)\
**Post date:** [March 27, 2020, 12:28pm UTC](https://discuss.elastic.co/t/logstash-unexpected-character-code-45-was-expecting-comma-to-separate-array-entries/224821/4 "2020-03-27T12:28:05Z")

</div>

Hi

1. Dissect dint work for me but i used this

```auto
input {
  file {
    path => "/home/ubuntu/*"
    start_position => "beginning"
  }
}
filter {

   grok {
    match => { "message" => "(?<jsonf>({.*}))"}
  }
  json {
            source => "jsonf"
  }
  mutate {
        remove_field => ["message","jsonf"]
      }
}

output {
  amazon_es {
    hosts => [" ***********************"]
    region => "us-east-1"
    index => "lgs-%{+YYYY.MM.dd}"
    #user => "elastic"
    #password => "changeme"
  }
}

```

1. It dint show up any error says that "logstash API started successfully "
2. But still i am not able to see up the index created in kibana . I am using AWS Elasticsearch.
3. My server has a full permission to Elastic Search.  
So, what am i doing wrong here

---

<div class="post-metadata">

**Author:** ![fadjar340](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/fadjar340/32/43610_2.png) [@fadjar340](https://discuss.elastic.co/u/fadjar340)\
**Post date:** [March 28, 2020, 3:00am UTC](https://discuss.elastic.co/t/logstash-unexpected-character-code-45-was-expecting-comma-to-separate-array-entries/224821/5 "2020-03-28T03:00:46Z")

</div>

Try put:

codec =\> "json" into the input

Regards,  
Fadjar Tandabawana

---

<div class="post-metadata">

**Author:** ![Rahul\_Ravichandran](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rahul_ravichandran/32/53882_2.png) [@Rahul\_Ravichandran](https://discuss.elastic.co/u/Rahul_Ravichandran)\
**Post date:** [March 30, 2020, 8:05am UTC](https://discuss.elastic.co/t/logstash-unexpected-character-code-45-was-expecting-comma-to-separate-array-entries/224821/6 "2020-03-30T08:05:51Z")

</div>

Hey guys thank for you time Actually i was giving my log file path wrongly other than that the configurations works perfectly.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 27, 2020, 8:05am UTC](https://discuss.elastic.co/t/logstash-unexpected-character-code-45-was-expecting-comma-to-separate-array-entries/224821/7 "2020-04-27T08:05:55Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
