# Problem parsing Json from Beats

**URL:** <https://discuss.elastic.co/t/problem-parsing-json-from-beats/95177>\
**Category:** Logstash\
**Created:** [July 31, 2017, 11:43am UTC](https://discuss.elastic.co/t/problem-parsing-json-from-beats/95177 "2017-07-31T11:43:36Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![dgoering](https://avatars.discourse-cdn.com/v4/letter/d/ce73a5/32.png) [@dgoering](https://discuss.elastic.co/u/dgoering)\
**Post date:** [July 31, 2017, 11:43am UTC](https://discuss.elastic.co/t/problem-parsing-json-from-beats/95177/1 "2017-07-31T11:43:37Z")

</div>

Hello I am new to the Elastic stack and am trying to get a fairly simple setup running:  
logback \> filebeats \> logstash \> elasticsearch \> Kibana

I am using the logstash encoder in logback to create log entries as json files. Filebeats seems to send the json entries to logstash where they then run into a parse error:

> [2017-07-28T16:53:28,537][ERROR][logstash.codecs.json] JSON parse error, original data now in message field {:error=\>#\<LogStash::Json::ParserError: Unrecognized token 'My': was expecting ('true', 'false' or 'null')  
> at [Source: My Message; line: 1, column: 5]\>, :data=\>"My Message"}

It seems like it is trying to parse the message as a json instead of the entire json object containing the message.

Here are my configuration files:  
filebeat:

> filebeat:  
> prospectors:  
> - document\_type: my\_document  
> fields:  
> logical\_hostname: my\_host  
> app: my\_app  
> json:  
> keys\_under\_root: true  
> add\_error\_key: true  
> message\_key: message  
> paths:  
> - /path/to/log/log.json  
> output:  
> logstash:  
> hosts: ["127.0.0.1:5044"]

logstash:

> input {  
> beats {  
> port =\> 5044  
> codec =\> json  
> }  
> }
> 
> output {  
> elasticsearch {  
> hosts =\> "127.0.0.1:9200"  
> }  
> }

And here an example object published by filebeats:

> {  
> "@timestamp": "2017-07-31T11:08:10.299Z",  
> "@version": 1,  
> "beat": {  
> "hostname": "#######",  
> "name": "my-name",  
> "version": "5.2.1"  
> },  
> "fields": {  
> "app": "my-app",  
> "logical\_hostname": "my-host"  
> },  
> "input\_type": "log",  
> "level": "WARN",  
> "level\_value": 30000,  
> "logger\_name": "com.some.package.Class",  
> "message": "My Message",  
> "offset": 132282,  
> "source": "/path/to/log/log.json",  
> "thread\_name": "ajp-nio-8609-exec-8",  
> "type": "my-type"  
> }

The json looks ok to me. The problem most likely is somehow connected to the logstash config? I have tried both codec json as well as json\_lines. With codec json the log entries show up in kibana, yet they are tagged with \_jsonparsefailure. And the logstash files shows above mentioned error.  
Any help would be appreciated.

---

<div class="post-metadata">

**Author:** ![dgoering](https://avatars.discourse-cdn.com/v4/letter/d/ce73a5/32.png) [@dgoering](https://discuss.elastic.co/u/dgoering)\
**Post date:** [July 31, 2017, 1:02pm UTC](https://discuss.elastic.co/t/problem-parsing-json-from-beats/95177/2 "2017-07-31T13:02:07Z")

</div>

So after getting help in the logstash IRC channel it seems that having both the json element in the filebeats config as well as the codec =\> json in the logstash leads to the json being decoded twice and failing.  
Removing the codec and defaulting to plain seems to have resolved this issue.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 28, 2017, 1:02pm UTC](https://discuss.elastic.co/t/problem-parsing-json-from-beats/95177/3 "2017-08-28T13:02:33Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
