# LogStash::Json::ParserError: Unexpected character (':' (code 58))

**URL:** <https://discuss.elastic.co/t/logstash-unexpected-character-code-58/337864>\
**Category:** Elasticsearch\
**Created:** [July 7, 2023, 7:42am UTC](https://discuss.elastic.co/t/logstash-unexpected-character-code-58/337864 "2023-07-07T07:42:24Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![shailendra1](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/shailendra1/32/122783_2.png) [@shailendra1](https://discuss.elastic.co/u/shailendra1)\
**Post date:** [July 7, 2023, 7:42am UTC](https://discuss.elastic.co/t/logstash-unexpected-character-code-58/337864/1 "2023-07-07T07:42:24Z")

</div>

i am facing the unexpected character error code 58 in my json data. even after validation of the data the logstash is reporting the errors . below is the sample data , can anyone help why logstash reporting an error here.

```auto

{
	"http": {
		"request": {
			"headers": {
				"accept-api-version": ["resource=2.0"],
				"host": ["blue-csecidp.uat.abc.com:8443"],
				"user-agent": ["Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/113.0.0.0 Safari/537.36"],
				"x-forgerock-transactionid": ["ZIIZ9s_ewIWfgPhkrsqdxgAA234"],
				"x-forwarded-for": ["1.1.1.y"]
			},
			"secure": true,
			"method": "POST",
			"path": "https://blue-csecidp.uat.abc.com:8443/am/json/realms/root/realms/employee/authenticate",
			"queryParameters": {
				"authIndexType": ["service"],
				"authIndexValue": ["Push"]
			}
		}
	},
	"_id": "85f902e4-b971-4364-be35-07a4838bceed-195030431",
	"timestamp": "2023-06-08T18:12:07.186Z",
	"eventName": "AM-ACCESS-OUTCOME",
	"transactionId": "ZIIZ9s_ewIWfgPhkrsqdxgAAAII",
	"trackingIds": ["85f902e4-b971-4364-be35-07a4838bceed-195030421"],
	"client": {
		"ip": "1.1.1.x",
		"port": 23698
	},
	"response": {
		"status": "SUCCESSFUL",
		"statusCode": "200",
		"elapsedTime": 840,
		"elapsedTimeUnits": "MILLISECONDS"
	},
	"realm": "/employee",
	"component": "Authentication"
}

```

---

<div class="post-metadata">

**Author:** ![shailendra1](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/shailendra1/32/122783_2.png) [@shailendra1](https://discuss.elastic.co/u/shailendra1)\
**Post date:** [July 13, 2023, 5:17am UTC](https://discuss.elastic.co/t/logstash-unexpected-character-code-58/337864/2 "2023-07-13T05:17:49Z")

</div>

below is my logstash config

```auto
 filter {
                json { source => "message" }
                #### ACCESS AUDIT JSON Filtering
                if [application] == ["CSEC-elk"] {
                        ruby { code => 'h = event.get("[http][request][headers]")
                if h
                        h.each { |k, v| event.set("[headers][#{k}]", v[0]) }
                end'
                }
                 split { field => "[headers][_id]" }
                 mutate { rename => { "_id" => "[trac_id]" } }
                }

```

also i am getting warning with this filter in split field that

`Only String and Array types are splittable. field:[headers][_id] is of type = NilClass`

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 10, 2023, 5:18am UTC](https://discuss.elastic.co/t/logstash-unexpected-character-code-58/337864/3 "2023-08-10T05:18:47Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
