# Parse / ship JSON file with filebeat

**URL:** <https://discuss.elastic.co/t/parse-ship-json-file-with-filebeat/34540>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [November 13, 2015, 5:39pm UTC](https://discuss.elastic.co/t/parse-ship-json-file-with-filebeat/34540 "2015-11-13T17:39:08Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![rummages](https://avatars.discourse-cdn.com/v4/letter/r/48db29/32.png) [@rummages](https://discuss.elastic.co/u/rummages)\
**Post date:** [November 13, 2015, 5:39pm UTC](https://discuss.elastic.co/t/parse-ship-json-file-with-filebeat/34540/1 "2015-11-13T17:39:08Z")

</div>

Is it possible to directly parse a json file from filebeats into elasticsearch?

I have a small json file and I would like to have filebeats read in and ship directly to elasticsearch in json. json file -\> filebeats =\> elasticsearch.

---

<div class="post-metadata">

**Author:** ![steffens](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/steffens/32/79630_2.png) [@steffens](https://discuss.elastic.co/u/steffens)\
**Post date:** [November 13, 2015, 5:56pm UTC](https://discuss.elastic.co/t/parse-ship-json-file-with-filebeat/34540/2 "2015-11-13T17:56:27Z")

</div>

No, filebeat will just forward lines from files. For parsing it must be used with logstash. You can use json\_lines codec in logstash to parse.

In case you have one complete json-object per line you can try in logstash

```
input {
    beats {
        ...
        codec => "json_lines"
     }
}

```

See [codec documentation](https://www.elastic.co/guide/en/logstash/current/plugins-codecs-json_lines.html)

filebeat will follow lines being written. If you want to send your file only once you can try the [tcp input plugin](https://www.elastic.co/guide/en/logstash/current/plugins-inputs-tcp.html) in logstash with [netcat](http://netcat.sourceforge.net/).

edit: added the missing 's' on json\_lines

---

<div class="post-metadata">

**Author:** ![bluethundr](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bluethundr/32/409_2.png) [@bluethundr](https://discuss.elastic.co/u/bluethundr)\
**Post date:** [February 10, 2016, 3:31am UTC](https://discuss.elastic.co/t/parse-ship-json-file-with-filebeat/34540/3 "2016-02-10T03:31:15Z")

</div>

> [@steffens](#):
>
> No, filebeat will just forward lines from files. For parsing it must be used with logstash. You can use json\_lines codec in logstash to parse.
> 
> In case you have one complete json-object per line you can try in logstash
> 
> input {  
> beats {  
> ...  
> codec =\> "json\_line"  
> }  
> }
> 
> See codec documentation
> 
> filebeat will follow lines being written. If you want to send your file only once you can try the tcp input plugin in logstash with netcat.

Hi Steffens,

I just tried the json\_line codec you talk about here. I copied it from the post into my beats plugin on my input config.

```auto
    beats {
     port => 5000
     tags => "beats"
     codec => "json_line"
     #ssl => true
     #ssl_certificate => "/opt/filebeats/logs.example.com.crt"
     #ssl_key => "/opt/filebeats/logs.example.com.key"
     }

```

```auto
[root@logs:/etc/logstash/conf.d] #/opt/logstash/bin/logstash --configtest --config 10-logstash-input.conf
The error reported is:
  Couldn't find any codec plugin named 'json_line'. Are you sure this is correct? Trying to load the json_line codec plugin resulted in this error: no such file to load -- logstash/codecs/json_line

```

And I'm on the latest version:

```auto
[root@logs:/etc/logstash/conf.d] #/opt/logstash/bin/logstash --version
logstash 2.2.0

```

This is my whole input config:

```auto
input {
   lumberjack {
       # The port to listen on
       port => 2541

       # The paths to your ssl cert and key
       ssl_certificate => "/etc/pki/tls/certs/logstash.crt"
       ssl_key => "/etc/pki/tls/private/logstash.key"

         # Set this to whatever you want.
         type => "logstash"
         codec => "json"
       }

     beats {
     port => 5000
     tags => "beats"
     codec => "json_line"
     #ssl => true
     #ssl_certificate => "/opt/filebeats/logs.example.com.crt"
     #ssl_key => "/opt/filebeats/logs.example.com.key"
     }

     syslog {
        type => "syslog"
        port => "5514"

    }

    redis {
     host => "216.xxx.xxx.98"
     type => "redis-input"
     data_type => "list"
     key => "logstash"
    }
}

```

What's going wrong here?

Thanks

---

<div class="post-metadata">

**Author:** ![bluethundr](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bluethundr/32/409_2.png) [@bluethundr](https://discuss.elastic.co/u/bluethundr)\
**Post date:** [February 10, 2016, 3:53am UTC](https://discuss.elastic.co/t/parse-ship-json-file-with-filebeat/34540/4 "2016-02-10T03:53:01Z")

</div>

Oh, it should've been codec =\> "json\_lines" instead of codec =\> "json\_line"!!! Wah wah wah wahhhhh. lol 😂

---

<div class="post-metadata">

**Author:** ![steffens](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/steffens/32/79630_2.png) [@steffens](https://discuss.elastic.co/u/steffens)\
**Post date:** [February 10, 2016, 3:45pm UTC](https://discuss.elastic.co/t/parse-ship-json-file-with-filebeat/34540/5 "2016-02-10T15:45:23Z")

</div>

is "json\_lines" working for you? You can also try the "json" codec.

---

<div class="post-metadata">

**Author:** ![bluethundr](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bluethundr/32/409_2.png) [@bluethundr](https://discuss.elastic.co/u/bluethundr)\
**Post date:** [February 10, 2016, 4:31pm UTC](https://discuss.elastic.co/t/parse-ship-json-file-with-filebeat/34540/6 "2016-02-10T16:31:12Z")

</div>

> [@steffens](#):
>
> is "json\_lines" working for you? You can also try the "json" codec.

Hi Steffens,

Yeah they both seem to work really great!

I've run into another issue where filebeat stopped working however.

[Filebeat Stopped working](https://discuss.elastic.co/t/filebeat-stopped-working/41401/2)

It was nice having it work while it lasted !

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 5, 2017, 9:55pm UTC](https://discuss.elastic.co/t/parse-ship-json-file-with-filebeat/34540/7 "2017-07-05T21:55:50Z")

</div>


