# Parse json file with logstash

**URL:** <https://discuss.elastic.co/t/parse-json-file-with-logstash/134795>\
**Category:** Logstash\
**Created:** [June 6, 2018, 12:02pm UTC](https://discuss.elastic.co/t/parse-json-file-with-logstash/134795 "2018-06-06T12:02:47Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![Super8film](https://avatars.discourse-cdn.com/v4/letter/s/bcef8e/32.png) [@Super8film](https://discuss.elastic.co/u/Super8film)\
**Post date:** [June 6, 2018, 12:02pm UTC](https://discuss.elastic.co/t/parse-json-file-with-logstash/134795/1 "2018-06-06T12:02:47Z")

</div>

hey

I've following json file

```
{
"time":"2015-09-20;12:13:24",
"bug_code":"test",
"stacktrace":1235
}

```

I got this from a python script and logstash reading it out with following configuration:

```
    input {
 file{
	
 	path => "D:\logstash_pipeline\test.json"
	start_position => "beginning"
	sincedb_path => "var/log/kibana/kibana.stdout" # is this right?
	codec => "json"
		}
}

output {
  stdout{
     codec => json # for debugging
  }
  
  file {
			path => "logs/log.txt"
			codec => json_lines
	}
	
elasticsearch {
    hosts => ["localhost:9200"]
	index => "json_test"
    document_type => "jenkins_perfReport"
  }
 
  if "_jsonparsefailure" in [tags] {
		file {
		codec => json_lines
			path => "logs/_jsonparsefailure.txt"
			codec => json_lines
	}
			}
		stdout{
		}
	
}

{"path":"D:\\logstash_pipeline\\test.json","@version":"1","@timestamp":"2018-06-06T12:10:13.512Z","message":"\"bug_code\":\"test\",\r","host":"bla","tags":["_jsonparsefailure"]}
{"path":"D:\\Jlogstash_pipeline\\test.json","@version":"1","@timestamp":"2018-06-06T12:10:13.512Z","message":"\"stacktrace\":1235\r","host":"bla","tags":["_jsonparsefailure"]}
{"path":"D:\\logstash_pipeline\\test.json","@version":"1","@timestamp":"2018-06-06T12:10:13.466Z","message":"{\r","host":"bla","tags":["_jsonparsefailure"]}
{"path":"D:\\logstash_pipeline\\test.json","@version":"1","@timestamp":"2018-06-06T12:10:13.497Z","message":"\"time\":\"2015-09-20;12:13:24\",\r","host":"bla","tags":["_jsonparsefailure"]}

```

I thought that I will see in kibana the information like  
bug\_code: test  
strackrace: 1235

Questions?  
1.) Shouldnt the codec be json\_lines? If I use it there is no result? Do I've to install json\_lines?  
2.) How do I've to mutate the field to have to result how I think?  
3.) How can I add a counter that increment an id =\> for every

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [June 7, 2018, 6:26am UTC](https://discuss.elastic.co/t/parse-json-file-with-logstash/134795/2 "2018-06-07T06:26:27Z")

</div>

> {  
> "time":"2015-09-20;12:13:24",  
> "bug\_code":"test",  
> "stacktrace":1235  
> }

Does the file look exactly like this, i.e. is the JSON message spread out over multiple lines? Does a file contain multiple such messages?

> sincedb\_path =\> "var/log/kibana/kibana.stdout" # is this right?

No, that doesn't really make sense. Technically it probably works but the path is at best misleading in its name.

> 3.) How can I add a counter that increment an id =\> for every

Why do you want to do that?

---

<div class="post-metadata">

**Author:** ![Super8film](https://avatars.discourse-cdn.com/v4/letter/s/bcef8e/32.png) [@Super8film](https://discuss.elastic.co/u/Super8film)\
**Post date:** [June 8, 2018, 11:58am UTC](https://discuss.elastic.co/t/parse-json-file-with-logstash/134795/3 "2018-06-08T11:58:12Z")

</div>

Thank you very much for your response - It don't have to look like this. If put it together in one line I still no result in Kibana... nothing happen in logstash.

I chagend the sincedb\_path to "/dev/null"

> Why do you want to do that?  
> I want to add a pie chart with the last information of a specific build - if I use the information it just add all passed test together,

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [June 8, 2018, 12:06pm UTC](https://discuss.elastic.co/t/parse-json-file-with-logstash/134795/4 "2018-06-08T12:06:11Z")

</div>

> I chagend the sincedb\_path to "/dev/null"

On Windows use "nul", not "/dev/null".

Increasing the loglevel could give clues about what's going on.

---

<div class="post-metadata">

**Author:** ![Super8film](https://avatars.discourse-cdn.com/v4/letter/s/bcef8e/32.png) [@Super8film](https://discuss.elastic.co/u/Super8film)\
**Post date:** [June 10, 2018, 6:23pm UTC](https://discuss.elastic.co/t/parse-json-file-with-logstash/134795/5 "2018-06-10T18:23:26Z")

</div>

So I changed my input to:  
input {  
file{

```
 	path => "C:\Users\test\data.json" # also tried ["C:\Users\test\data.json"]
	start_position => "beginning"
	sincedb_path => "NUL" 
	codec => "json" # Is codec a string?
	
		}

}

```

I

and

```
   output {
      stdout{
         codec => "json"
      }
  
  file {
			path => "logs/log.txt"
			codec => "json"
	}
	
elasticsearch {
    hosts => ["localhost:9200"]
	index => "json_test"
    document_type => "jenkins_perfReport"
  }
 
  if "_jsonparsefailure" in [tags] {
		file {
		codec => json_lines
			path => "logs/_jsonparsefailure.txt"
			codec => "json"
		}
	}

}

```

The complete Log is to long to post -when I read the log I see this as problem description:

> :exception=\>"LogStash::ConfigurationError", :message=\>"Expected one of #, input, filter, output at line 1, column 1 (byte 1) after "

my conf file starts in line1 - I use notepad++ - I've no filter so far...

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [June 11, 2018, 5:55am UTC](https://discuss.elastic.co/t/parse-json-file-with-logstash/134795/6 "2018-06-11T05:55:11Z")

</div>

Make sure you don't have any garbage characters (like a byte-order mark) at the very beginning of the file.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 9, 2018, 5:55am UTC](https://discuss.elastic.co/t/parse-json-file-with-logstash/134795/7 "2018-07-09T05:55:11Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
