# NMON to JSON Converted Files Will Not Import

**URL:** <https://discuss.elastic.co/t/nmon-to-json-converted-files-will-not-import/309566>\
**Category:** Logstash\
**Created:** [July 13, 2022, 5:51pm UTC](https://discuss.elastic.co/t/nmon-to-json-converted-files-will-not-import/309566 "2022-07-13T17:51:10Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![yoscar](https://avatars.discourse-cdn.com/v4/letter/y/e79b87/32.png) [@yoscar](https://discuss.elastic.co/u/yoscar)\
**Post date:** [July 13, 2022, 5:51pm UTC](https://discuss.elastic.co/t/nmon-to-json-converted-files-will-not-import/309566/1 "2022-07-13T17:51:10Z")

</div>

We're trying to ingest nmon data that's recorded over a 24 hour timespan into Logstash. We first convert it to json usin nmon2json (I understand that njmon is an option, but we are trying to use existing nmon files for now), then move the file to the logstash server.

After getting to a point where the json file is validated, we see these messages:  
[2022-07-13T13:44:54,986][ERROR][logstash.codecs.json][nmon][nmon] JSON parse error, original data now in message field {:message=\>"Unexpected close marker '}': expected ']' (for root starting at [Source: (String)"\t},"; line: 1, column: 0])\n at [Source: (String)"\t},"; line: 1, column: 3]", :exception=\>LogStash::Json::ParserError, :data=\>"\t},"}

The conf file we have for logstash is this (output ommitted)

```auto
input {
  file {
    codec => "json"
   path => ["/shared/NMON/*.json"]
    sincedb_path => "/dev/null"
    tags => ["nmon"]
    id => "nmon"
    mode => "read"
    start_position => "beginning"
    stat_interval => "2s"
    file_completed_action => "delete"
  }
}

filter {
      json
        {
			source => "message"
        }
       }

```

I'm not sure if I should be using both the codec and filter. For another company that we work with, their configuration file is, and it seems to work but they also reprocess the created json file first.

```auto
input {
  file {
    codec => "json"
    path => ["/shared*"]
    sincedb_path => "/dev/null"
    tags => ["nmon"]
    id => "nmon"
    mode => "read"
    start_position => "beginning"
    stat_interval => "2s"
    file_completed_action => "delete"
  }
}
filter {
     date {
       match => ["timestamp", "HH:mm:ss'T'dd-MMM-yyyy"]
     }
}

```

I've looked in the past topics as well, and I don't really see a defined solutions for nmon2json. Can anyone help?

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [July 13, 2022, 8:14pm UTC](https://discuss.elastic.co/t/nmon-to-json-converted-files-will-not-import/309566/2 "2022-07-13T20:14:45Z")

</div>

It sounds like your JSON files are pretty-printed. You are ingesting a line that just contains "}".

Use a [multiline codec](https://discuss.elastic.co/t/merge-multiline-json-into-single-line-json-using-codec-multiline-plugin/143175/2). That example consumes the whole file as one event. If your files have multiple JSON objects you might use a pattern like `^}`. It really depends on what your files look like.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 10, 2022, 8:14pm UTC](https://discuss.elastic.co/t/nmon-to-json-converted-files-will-not-import/309566/3 "2022-08-10T20:14:57Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
