# Logstash warning

**URL:** <https://discuss.elastic.co/t/logstash-warning/107368>\
**Category:** Logstash\
**Created:** [November 13, 2017, 10:42am UTC](https://discuss.elastic.co/t/logstash-warning/107368 "2017-11-13T10:42:36Z")\
**Posts on this page:** 11\
**Page:** 1

<div class="post-metadata">

**Author:** ![Jonesthomas](https://avatars.discourse-cdn.com/v4/letter/j/f4b2a3/32.png) [@Jonesthomas](https://discuss.elastic.co/u/Jonesthomas)\
**Post date:** [November 13, 2017, 10:42am UTC](https://discuss.elastic.co/t/logstash-warning/107368/1 "2017-11-13T10:42:36Z")

</div>

i get this warning in logstash log

`[2017-11-13T10:41:22,803][WARN][logstash.filters.json] Error parsing json {:source=>"LogMsg", :raw=>"UID:420: Out /getData/{city}/{speciality}/{doctorName} all/all/all", :exception=>#<LogStash::Json::ParserError: Unrecognized token 'UID': was expecting ('true', 'false' or 'null') at [Source: [B@7139abf; line: 1, column: 5]>}`

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [November 13, 2017, 11:23am UTC](https://discuss.elastic.co/t/logstash-warning/107368/2 "2017-11-13T11:23:00Z")

</div>

You've asked Logstash to parse

```
UID:420: Out /getData/{city}/{speciality}/{doctorName} all/all/all

```

as JSON but it's not a JSON string.

---

<div class="post-metadata">

**Author:** ![Jonesthomas](https://avatars.discourse-cdn.com/v4/letter/j/f4b2a3/32.png) [@Jonesthomas](https://discuss.elastic.co/u/Jonesthomas)\
**Post date:** [November 20, 2017, 5:13am UTC](https://discuss.elastic.co/t/logstash-warning/107368/3 "2017-11-20T05:13:44Z")

</div>

i have the valid json log lines.Still getting this warning

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [November 20, 2017, 6:39am UTC](https://discuss.elastic.co/t/logstash-warning/107368/4 "2017-11-20T06:39:04Z")

</div>

The `LogMsg` field that you're trying to parse did in this case not contain a valid JSON string. Period.

Perhaps you already have a json or json\_lines codec in your input configuration, making the json filter unnecessary.

---

<div class="post-metadata">

**Author:** ![Jonesthomas](https://avatars.discourse-cdn.com/v4/letter/j/f4b2a3/32.png) [@Jonesthomas](https://discuss.elastic.co/u/Jonesthomas)\
**Post date:** [November 20, 2017, 6:46am UTC](https://discuss.elastic.co/t/logstash-warning/107368/5 "2017-11-20T06:46:28Z")

</div>

> [@magnusbaeck](#):
>
> on\_lines codec

Ohh,Then shall i remove the stdin { codec =\> "json" } from my input filter?

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [November 20, 2017, 6:48am UTC](https://discuss.elastic.co/t/logstash-warning/107368/6 "2017-11-20T06:48:58Z")

</div>

Either that, or remove the json filter. Just don't keep both.

---

<div class="post-metadata">

**Author:** ![Jonesthomas](https://avatars.discourse-cdn.com/v4/letter/j/f4b2a3/32.png) [@Jonesthomas](https://discuss.elastic.co/u/Jonesthomas)\
**Post date:** [November 20, 2017, 7:05am UTC](https://discuss.elastic.co/t/logstash-warning/107368/7 "2017-11-20T07:05:32Z")

</div>

i removed the stdin { codec =\> "json" } in input filter but getting the warning in logstash

---

<div class="post-metadata">

**Author:** ![Jonesthomas](https://avatars.discourse-cdn.com/v4/letter/j/f4b2a3/32.png) [@Jonesthomas](https://discuss.elastic.co/u/Jonesthomas)\
**Post date:** [November 20, 2017, 7:09am UTC](https://discuss.elastic.co/t/logstash-warning/107368/8 "2017-11-20T07:09:16Z")

</div>

my sample log format  
`{"LogLevel":"ERROR","LogMsg":"{\"itemId\":0,\"module\":\"/curie/encounter\",\"action\":\"/addToken\",\"errorMessage\":\"java.lang.RuntimeException: org.apache.ibatis.exceptions.PersistenceException: \\n### Error querying database. Cause: com.mysql.jdbc.exceptions.jdbc4.CommunicationsException: The last packet successfully received from the server was 134,717,933 milliseconds ago. The last packet sent successfully to the server was 134,717,972 milliseconds ago. is longer than the server configured value of \\u0027wait_timeout\\u0027. You should consider either expiring and/or testing connection validity before use in your application, increasing the server configured values for client timeouts, or using the Connector/J connection property \\u0027autoReconnect\\u003dtrue\\u0027 to avoid this problem.\\n### The error may exist in EncounterMapper.xml\\n### The error may involve EncounterMapper.checkTokenExist-Inline\\n### The error occurred while setting parameters\\n### SQL: SELECT COUNT(*) FROM token WHERE appointmentId \\u003d ?\\n### Cause: com.mysql.jdbc.exceptions.jdbc4.CommunicationsException: The last packet successfully received from the server was 134,717,933 milliseconds ago. The last packet sent successfully to the server was 134,717,972 milliseconds ago. is longer than the server configured value of \\u0027wait_timeout\\u0027. You should consider either expiring and/or testing connection validity before use in your application, increasing the server configured values for client timeouts, or using the Connector/J connection property \\u0027autoReconnect\\u003dtrue\\u0027 to avoid this problem.\",\"parameter\":\"java.lang.RuntimeException: java.lang.RuntimeException: org.apache.ibatis.exceptions.PersistenceException: \\n### Error querying database. Cause: com.mysql.jdbc.exceptions.jdbc4.CommunicationsException: The last packet successfully received from the server was 134,717,933 milliseconds ago. The last packet sent successfully to the server was 134,717,972 milliseconds ago. is longer than the server configured value of \\u0027wait_timeout\\u0027. You should consider either expiring and/or testing connection validity before use in your application, increasing the server configured values for client timeouts, or using the Connector/J connection property \\u0027autoReconnect\\u003dtrue\\u0027 to avoid this problem.\\n### The error may exist in EncounterMapper.xml\\n### The error may involve EncounterMapper.checkTokenExist-Inline\\n### The error occurred while setting parameters\\n### SQL: SELECT COUNT(*) FROM token WHERE appointmentId \\u003d ?\\n### Cause: com.mysql.jdbc.exceptions.jdbc4.CommunicationsException: The last packet successfully received from the server was 134,717,933 milliseconds ago. The last packet sent successfully to the server was 134,717,972 milliseconds ago. is longer than the server configured value of \\u0027wait_timeout\\u0027. You should consider either expiring and/or testing connection validity before use in your application, increasing the server configured values for client timeouts, or using the Connector/J connection property \\u0027autoReconnect\\u003dtrue\\u0027 to avoid this problem.systems.ellora.core.api.encounter.domain.EncounterBuilder.addToken(EncounterBuilder.java:995)\"}","Time":"2017-11-20_09:12:21.042"} {"LogLevel":"INFO","LogMsg":"UID: Invoice [invoiceId=465, encounterId=1676, subject=null, reason=null, dateRaised=null, total=299, isPaid=false, datePaid=null, lineItems=[LineItem [invoiceId=0, consultancy=null, labFee=null, scanFee=null, vaccination=null, medicalDispense=MedDispense [invoiceId=465, medicationId=104, totalAmount=49, performer=v7LoV3ZFhLZy0z8M4uHpAJisTeJ3, type=Normal, facilityId=3, doctorId=3, encounterId=1676, patientKey=17169, listOfItem=[DispenseItem [medicationId=104, substanceDetailId=56, substanceName=Ambroxol hydrochloride, quantity=1, cost=49.0]]], chargeItem=null], LineItem [invoiceId=0, consultancy=ConsultancyFee [name=Consultancy, amount=250, performer=null], labFee=null, scanFee=null, vaccination=null, medicalDispense=null, chargeItem=null], LineItem [invoiceId=0, consultancy=null, labFee=null, scanFee=ScanFee [name=ScanFee, amount=1000, performer=null], vaccination=null, medicalDispense=null, chargeItem=null], LineItem [invoiceId=0, consultancy=null, labFee=LabFee [name=LabFee, amount=500, performer=null], scanFee=null, vaccination=null, medicalDispense=null, chargeItem=null]]], Completed Invoice Task {}UID:11: ","Time":"2017-11-20_12:11:07.931"}`

im trying to remove the "LogLevel"="INFO"  
and i want only "LogLevel":"ERROR" field to shown in kibana

My filter plugin :  
`filter { json { source => "message" } json { source => "LogMsg" } if [LogLevel] == "INFO" { drop { remove_field => ["LogLevel"] } } mutate { add_field => { "ErrorMsg" => "%{errorMessage}" } } truncate { fields => "ErrorMsg" length_bytes => 1000 } }`

Correct me if I'm wrong

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [November 20, 2017, 8:36am UTC](https://discuss.elastic.co/t/logstash-warning/107368/9 "2017-11-20T08:36:25Z")

</div>

Your first sample line does indeed have a `LogMsg` field that's JSON, but the second one doesn't. Perhaps you should use the json filter's `skip_on_invalid_json` option.

---

<div class="post-metadata">

**Author:** ![Jonesthomas](https://avatars.discourse-cdn.com/v4/letter/j/f4b2a3/32.png) [@Jonesthomas](https://discuss.elastic.co/u/Jonesthomas)\
**Post date:** [November 20, 2017, 8:54am UTC](https://discuss.elastic.co/t/logstash-warning/107368/10 "2017-11-20T08:54:10Z")

</div>

> [@Jonesthomas](#):
>
> {"LogLevel":"INFO","LogMsg":"UID: Invoice [invoiceId=465, encounterId=1676, subject=null, reason=null, dateRaised=null, total=299, isPaid=false, datePaid=null, lineItems=[LineItem [invoiceId=0, consultancy=null, labFee=null, scanFee=null, vaccination=null, medicalDispense=MedDispense [invoiceId=465, medicationId=104, totalAmount=49, performer=v7LoV3ZFhLZy0z8M4uHpAJisTeJ3, type=Normal, facilityId=3, doctorId=3, encounterId=1676, patientKey=17169, listOfItem=[DispenseItem [medicationId=104, substanceDetailId=56, substanceName=Ambroxol hydrochloride, quantity=1, cost=49.0]]], chargeItem=null], LineItem [invoiceId=0, consultancy=ConsultancyFee [name=Consultancy, amount=250, performer=null], labFee=null, scanFee=null, vaccination=null, medicalDispense=null, chargeItem=null], LineItem [invoiceId=0, consultancy=null, labFee=null, scanFee=ScanFee [name=ScanFee, amount=1000, performer=null], vaccination=null, medicalDispense=null, chargeItem=null], LineItem [invoiceId=0, consultancy=null, labFee=LabFee [name=LabFee, amount=500, performer=null], scanFee=null, vaccination=null, medicalDispense=null, chargeItem=null]]], Completed Invoice Task {}UID:11: ","Time":"2017-11-20\_12:11:07.931"}

Thank you so much, appreciate your help

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 18, 2017, 8:54am UTC](https://discuss.elastic.co/t/logstash-warning/107368/11 "2017-12-18T08:54:23Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
