# One of the entries does not get indexed

**URL:** <https://discuss.elastic.co/t/one-of-the-entries-does-not-get-indexed/136488>\
**Category:** Logstash\
**Created:** [June 19, 2018, 12:10pm UTC](https://discuss.elastic.co/t/one-of-the-entries-does-not-get-indexed/136488 "2018-06-19T12:10:43Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![Milind\_Gawde](https://avatars.discourse-cdn.com/v4/letter/m/b5ac83/32.png) [@Milind\_Gawde](https://discuss.elastic.co/u/Milind_Gawde)\
**Post date:** [June 19, 2018, 12:10pm UTC](https://discuss.elastic.co/t/one-of-the-entries-does-not-get-indexed/136488/1 "2018-06-19T12:10:43Z")

</div>

I have a huge JSON file, having **multilined, nested and indented** JSON which is about 28000 lines. I am trying to figure out how to parse this JSON under one message field in Kibana. But it seems that the **message gets split into 57 different entries**. Suggest a solution to combine them OR an alternative solution to prevent this split at Logstash itself.

---

<div class="post-metadata">

**Author:** ![Larry\_Gregory](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/larry_gregory/32/34969_2.png) [@Larry\_Gregory](https://discuss.elastic.co/u/Larry_Gregory)\
**Post date:** [June 19, 2018, 1:52pm UTC](https://discuss.elastic.co/t/one-of-the-entries-does-not-get-indexed/136488/2 "2018-06-19T13:52:13Z")

</div>

Hi @Milind_Gawde,

The easiest way to get this data into a single field is to index it as a string, rather than as an object. Is your Logstash configuration parsing or otherwise interpreting the JSON data?

---

<div class="post-metadata">

**Author:** ![Milind\_Gawde](https://avatars.discourse-cdn.com/v4/letter/m/b5ac83/32.png) [@Milind\_Gawde](https://discuss.elastic.co/u/Milind_Gawde)\
**Post date:** [June 20, 2018, 5:36am UTC](https://discuss.elastic.co/t/one-of-the-entries-does-not-get-indexed/136488/3 "2018-06-20T05:36:13Z")

</div>

@Larry_Gregory  
Thanks for the reply.  
It just parses generally; does not interpret JSON. By the way is there any limit on the size of events which are parsed through Logstash? If so, then how can we change this limit?

---

<div class="post-metadata">

**Author:** ![Larry\_Gregory](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/larry_gregory/32/34969_2.png) [@Larry\_Gregory](https://discuss.elastic.co/u/Larry_Gregory)\
**Post date:** [June 20, 2018, 12:10pm UTC](https://discuss.elastic.co/t/one-of-the-entries-does-not-get-indexed/136488/4 "2018-06-20T12:10:34Z")

</div>

Hey @Milind_Gawde, I've moved this to the Logstash forum, so that they can help you with your Logstash configuration. Thank you!

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [June 20, 2018, 8:26pm UTC](https://discuss.elastic.co/t/one-of-the-entries-does-not-get-indexed/136488/5 "2018-06-20T20:26:05Z")

</div>

What does your Logstash configuration look like?

---

<div class="post-metadata">

**Author:** ![Milind\_Gawde](https://avatars.discourse-cdn.com/v4/letter/m/b5ac83/32.png) [@Milind\_Gawde](https://discuss.elastic.co/u/Milind_Gawde)\
**Post date:** [June 25, 2018, 8:45am UTC](https://discuss.elastic.co/t/one-of-the-entries-does-not-get-indexed/136488/6 "2018-06-25T08:45:29Z")

</div>

@magnusbaeck, somehow managed to parse the data but one of the entries does not get indexed at all; which is a particular entry. Tried changing its position, yet does not get indexed. Any suggestions regarding solving this problem?

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [June 25, 2018, 10:28am UTC](https://discuss.elastic.co/t/one-of-the-entries-does-not-get-indexed/136488/7 "2018-06-25T10:28:20Z")

</div>

> Tried changing its position, yet does not get indexed.

What position?

Check your Logstash logs for details. It's possible that Elasticsearch rejects one of the events but then Logstash will log a message that should contain enough details to fix the problem.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 23, 2018, 10:28am UTC](https://discuss.elastic.co/t/one-of-the-entries-does-not-get-indexed/136488/8 "2018-07-23T10:28:20Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
