# Noob Alert: Trying to use FileBeat to store my JSON file into Elasticsearch

**URL:** <https://discuss.elastic.co/t/noob-alert-trying-to-use-filebeat-to-store-my-json-file-into-elasticsearch/113684>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [January 1, 2018, 11:44am UTC](https://discuss.elastic.co/t/noob-alert-trying-to-use-filebeat-to-store-my-json-file-into-elasticsearch/113684 "2018-01-01T11:44:47Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Aw\_Jeng\_Kit](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/aw_jeng_kit/32/26130_2.png) [@Aw\_Jeng\_Kit](https://discuss.elastic.co/u/Aw_Jeng_Kit)\
**Post date:** [January 1, 2018, 11:44am UTC](https://discuss.elastic.co/t/noob-alert-trying-to-use-filebeat-to-store-my-json-file-into-elasticsearch/113684/1 "2018-01-01T11:44:47Z")

</div>

Hi, I am a noob in ELK.  
My use case is this, I have created a Json file named data.json, which looks like this:  
{"clusterVirtutalCores": {"totalvc": 1, "reservedvc": 0, "allocatedvc": 0, "availablevc": 1}, "Capacity": {"capacityRemaining": 43801, "capacityUsed": 25000, "capacityTotal": 100000}, "numLiveDataNode": 1, "maintenancedataNode": {"nuEnteringnmaintenancedataNode": 0, "numInmaintenanceDeaddataNode": 0, "numInmaintenanceLivedataNode": 0}, "timestamp": "2018-01-01T18:05:49.635551", "Hostname": HDFS, "numDeadDataNode": 0, "nodeInsService": 1, "fileTotal": 560, "clustermemory": {"totalMB": 2048, "reservedMB": 520, "availableMB": 520, "allocatedMB": 520}, "datanode": {"availableMB": 2048, "usedmemoryMB": 2048, "Hostname": "hdfs-quickstart", "usedVC": 1, "availableVC": 1, "state": "running", "ID": "hdfs-quickstart"}}  
The data is fake

So I want to use Filebeat to read the Json file and store it in the Elasticsearch.  
I read over the internet and came out with this solution for filebeat:

Filebeat 6.1.1:  
filebeat.prospectors:

- paths:
  - /home/internship/Desktop/workspace/logs/data.json  
input\_type: log  
json.keys\_under\_root: true  
json.add\_error\_key: true

output.elasticsearch:  
hosts: ["[http://localhost:9200](http://localhost:9200)"]

But I am unsure if it is even doing anything. I checked Kibana but it does not show the entries. What can I do to solve my problem?

---

<div class="post-metadata">

**Author:** ![steffens](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/steffens/32/79630_2.png) [@steffens](https://discuss.elastic.co/u/steffens)\
**Post date:** [January 4, 2018, 12:58pm UTC](https://discuss.elastic.co/t/noob-alert-trying-to-use-filebeat-to-store-my-json-file-into-elasticsearch/113684/2 "2018-01-04T12:58:13Z")

</div>

Have you checked filebeat logs?

Filebeat requires the log file to have one json document per line. Plus a newline separator, after each json document is required.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 1, 2018, 12:59pm UTC](https://discuss.elastic.co/t/noob-alert-trying-to-use-filebeat-to-store-my-json-file-into-elasticsearch/113684/3 "2018-02-01T12:59:02Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
