# Parse error on Tshark generated JSON

**URL:** <https://discuss.elastic.co/t/parse-error-on-tshark-generated-json/129587>\
**Category:** Logstash\
**Created:** [April 26, 2018, 3:59am UTC](https://discuss.elastic.co/t/parse-error-on-tshark-generated-json/129587 "2018-04-26T03:59:26Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![pohsun.teh](https://avatars.discourse-cdn.com/v4/letter/p/f08c70/32.png) [@pohsun.teh](https://discuss.elastic.co/u/pohsun.teh)\
**Post date:** [April 26, 2018, 3:59am UTC](https://discuss.elastic.co/t/parse-error-on-tshark-generated-json/129587/1 "2018-04-26T03:59:26Z")

</div>

Greetings.

I have a JSON generated using `Tshark -T ek` command converting Wireshark PCAP file to JSON to be inserted to Elasticsearch.

The thing is I am having parse error exception on production side.

> `:exception=>#<LogStash::Json::ParserError: Unexpected character (':' (code 58)): expected a valid value (number, String, array, object, 'true', 'false' or 'null')`

The weird thing is, I copied the same JSON file to be tested locally, with the Logstash config file, and it turns out fine without any exception. Any thoughts on what I might be gone wrong?

I have no clue on what is wrong because the JSON is generated using `Tshark -T ek` command

Anyone here encounter any problems with Tshark generated JSON?

OS: centos 7  
Logstash: 6.2.3

---

<div class="post-metadata">

**Author:** ![guyboertje](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/guyboertje/32/31592_2.png) [@guyboertje](https://discuss.elastic.co/u/guyboertje)\
**Post date:** [April 26, 2018, 7:55am UTC](https://discuss.elastic.co/t/parse-error-on-tshark-generated-json/129587/2 "2018-04-26T07:55:24Z")

</div>

Have you used an [online validator like jsonlint](http://jsonlint.com/) to check the JSON?

There have been [problems with how Tshark generates JSON](https://ask.wireshark.org/question/505/deduplication-in-tshark-t-ek/).

What version of Tshark are you using?

---

<div class="post-metadata">

**Author:** ![pohsun.teh](https://avatars.discourse-cdn.com/v4/letter/p/f08c70/32.png) [@pohsun.teh](https://discuss.elastic.co/u/pohsun.teh)\
**Post date:** [April 26, 2018, 8:12am UTC](https://discuss.elastic.co/t/parse-error-on-tshark-generated-json/129587/3 "2018-04-26T08:12:11Z")

</div>

Yes. Checked few times with jsonlint. Apparently, got problems with duplicated keys, but the weird things is that it process without any problems/exception on my side.

Wireshark version: wireshark-qt-2.4.6-1.x86\_64

---

<div class="post-metadata">

**Author:** ![guyboertje](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/guyboertje/32/31592_2.png) [@guyboertje](https://discuss.elastic.co/u/guyboertje)\
**Post date:** [April 26, 2018, 8:33am UTC](https://discuss.elastic.co/t/parse-error-on-tshark-generated-json/129587/4 "2018-04-26T08:33:40Z")

</div>

Its worth upgrading wireshark to `2.6.0`.

Many thousands of users are ingesting JSON with Logstash 24/7 we rarely find bugs in the JSON parser these days. The LS JSON parser is really a wrapper around the Jackson JSON processor. [https://www.google.co.uk/search?q=jackson+json](https://www.google.co.uk/search?q=jackson+json)

Jackson is very widely used. For example, Elasticsearch uses it to parse the JSON in the REST API.

---

<div class="post-metadata">

**Author:** ![pohsun.teh](https://avatars.discourse-cdn.com/v4/letter/p/f08c70/32.png) [@pohsun.teh](https://discuss.elastic.co/u/pohsun.teh)\
**Post date:** [April 26, 2018, 8:36am UTC](https://discuss.elastic.co/t/parse-error-on-tshark-generated-json/129587/5 "2018-04-26T08:36:30Z")

</div>

I try to talk to my team about it. Thanks for pointing out.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 24, 2018, 8:36am UTC](https://discuss.elastic.co/t/parse-error-on-tshark-generated-json/129587/6 "2018-05-24T08:36:33Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
