# New json filter crashing logstash

**URL:** <https://discuss.elastic.co/t/new-json-filter-crashing-logstash/2014>\
**Category:** Logstash\
**Created:** [June 5, 2015, 1:51pm UTC](https://discuss.elastic.co/t/new-json-filter-crashing-logstash/2014 "2015-06-05T13:51:50Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![Melpheos](https://avatars.discourse-cdn.com/v4/letter/m/8baadc/32.png) [@Melpheos](https://discuss.elastic.co/u/Melpheos)\
**Post date:** [June 5, 2015, 1:51pm UTC](https://discuss.elastic.co/t/new-json-filter-crashing-logstash/2014/1 "2015-06-05T13:51:50Z")

</div>

We are filtering sflow data with logstash with the following filter  
filter {  
json {  
source =\> "message"  
type =\> "json"  
}  
}  
Which works fine. However, it seems it's deprecated.

But if we use the supported 1.5 json filter

filter {  
if [type] == "sflow" {  
json {  
source =\> "message"  
}  
}  
}

logstash will crash immediately or after a few seconds without any error in the logs.  
We are doing something wrong ?

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [June 6, 2015, 10:16am UTC](https://discuss.elastic.co/t/new-json-filter-crashing-logstash/2014/2 "2015-06-06T10:16:24Z")

</div>

That looks totally fine to me. Please increase the logging verbosity with `--verbose` or `--debug`.

---

<div class="post-metadata">

**Author:** ![Melpheos](https://avatars.discourse-cdn.com/v4/letter/m/8baadc/32.png) [@Melpheos](https://discuss.elastic.co/u/Melpheos)\
**Post date:** [June 8, 2015, 3:30pm UTC](https://discuss.elastic.co/t/new-json-filter-crashing-logstash/2014/3 "2015-06-08T15:30:36Z")

</div>

--verbose does not give anything but "adding pattern" with the list of pattern used  
With --debug we can see all the flows in the log file but no sflow log is recorded. All the received logs are registered in the log file but nothing seems to be outputed to elasticsearch.

There is no error in the logs.

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [June 8, 2015, 8:15pm UTC](https://discuss.elastic.co/t/new-json-filter-crashing-logstash/2014/4 "2015-06-08T20:15:46Z")

</div>

So... the crash is gone?

---

<div class="post-metadata">

**Author:** ![Melpheos](https://avatars.discourse-cdn.com/v4/letter/m/8baadc/32.png) [@Melpheos](https://discuss.elastic.co/u/Melpheos)\
**Post date:** [June 9, 2015, 7:39am UTC](https://discuss.elastic.co/t/new-json-filter-crashing-logstash/2014/5 "2015-06-09T07:39:16Z")

</div>

Huuu nope... It still crashes but without any errors that's the weird thing. The logs get filled up with received and parsed log and sflow but nothing is actualy outputed to elasticsearch.  
Once this occurs and most of the time, only kill -9 will work to stop logstash.

I wish i could see something of interest in the log but ☹

---

<div class="post-metadata">

**Author:** ![asafyigal](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/asafyigal/32/685_2.png) [@asafyigal](https://discuss.elastic.co/u/asafyigal)\
**Post date:** [June 16, 2015, 9:59am UTC](https://discuss.elastic.co/t/new-json-filter-crashing-logstash/2014/6 "2015-06-16T09:59:44Z")

</div>

What is the volume of logs you are trying to process?

We ran into similar issues with Logstash and it ended up being memory consumption issue with logstash. Take a look at the memory consumption of the machine and of the logstash process, when it dies from out of memory there are no errors in the log files and it just hangs.

-- Asaf.

---

<div class="post-metadata">

**Author:** ![Melpheos](https://avatars.discourse-cdn.com/v4/letter/m/8baadc/32.png) [@Melpheos](https://discuss.elastic.co/u/Melpheos)\
**Post date:** [June 17, 2015, 9:38pm UTC](https://discuss.elastic.co/t/new-json-filter-crashing-logstash/2014/7 "2015-06-17T21:38:14Z")

</div>

Thanks, i'll look into that but this server has 176Go of ram and and 28 allocated to logstash itself, 32 allocated to elasticsearch.  
I dont think that's the issue

---

<div class="post-metadata">

**Author:** ![fishnix](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/fishnix/32/4863_2.png) [@fishnix](https://discuss.elastic.co/u/fishnix)\
**Post date:** [September 19, 2015, 2:02pm UTC](https://discuss.elastic.co/t/new-json-filter-crashing-logstash/2014/8 "2015-09-19T14:02:32Z")

</div>

Did you ever resolve this issue? I'm seeing the same exact thing with no errors in the log.

```auto
  if [types] == "platform_json" {
    json {
      source => "message"
    }
  }

```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 5:28am UTC](https://discuss.elastic.co/t/new-json-filter-crashing-logstash/2014/9 "2017-07-06T05:28:38Z")

</div>


