# Problems with logstash codecs (json, rubydebug)

**URL:** <https://discuss.elastic.co/t/problems-with-logstash-codecs-json-rubydebug/44252>\
**Category:** Logstash\
**Created:** [March 13, 2016, 10:11am UTC](https://discuss.elastic.co/t/problems-with-logstash-codecs-json-rubydebug/44252 "2016-03-13T10:11:37Z")\
**Posts on this page:** 12\
**Page:** 1

<div class="post-metadata">

**Author:** ![tetlika](https://avatars.discourse-cdn.com/v4/letter/t/c6cbf5/32.png) [@tetlika](https://discuss.elastic.co/u/tetlika)\
**Post date:** [March 13, 2016, 10:11am UTC](https://discuss.elastic.co/t/problems-with-logstash-codecs-json-rubydebug/44252/1 "2016-03-13T10:11:37Z")

</div>

hi,  
we're using logstash 2.2.2  
I'm trying to feed logstash with kibana logs, kibana log looks like:

`{"type":"log","@timestamp":"2016-03-13T10:05:30+00:00","tags":["status","plugin:elasticsearch","info"],"pid":15856,"name":"plugin:elasticsearch","state":"green","message":"Status changed from yellow to green - Kibana index ready","prevState":"yellow","prevMsg":"Waiting for Elasticsearch"}`

so its json

when I do like this:

```
input {
    file {
        type => "ELK_kibana"
        path => "/var/log/kibana/kibana.stdout"
    }
}

```

and output goes to elasticsearch, it works ok, the only thing its unformatted

ok, so I did:

```
input {
    file {
        type => "ELK_kibana"
        path => "/var/log/kibana/kibana.stdout"
        codec => "json"
    }
}

```

And logs never goes to output, and nothing is happening (but other logs are working ok)

the same issue is with rubydebug plugin:

```
input {
    file {
        type => "ELK_logstash"
        path => "/var/log/logstash/logstash.log"
        codec => "rubydebug"
    }
}

```

And nothing goes to output.

Am I missing something in my configurations?

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [March 14, 2016, 1:12am UTC](https://discuss.elastic.co/t/problems-with-logstash-codecs-json-rubydebug/44252/2 "2016-03-14T01:12:54Z")

</div>

Can you provide the complete config? It's hard to say what is happening when all we can see is the input.

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [March 14, 2016, 6:37am UTC](https://discuss.elastic.co/t/problems-with-logstash-codecs-json-rubydebug/44252/3 "2016-03-14T06:37:41Z")

</div>

Unless you delete the sincedb file /var/log/kibana/kibana.stdout won't be reprocessed since Logstash think it's already done with that file. If new data is added to Kibana's logfile that data should show up though.

---

<div class="post-metadata">

**Author:** ![tetlika](https://avatars.discourse-cdn.com/v4/letter/t/c6cbf5/32.png) [@tetlika](https://discuss.elastic.co/u/tetlika)\
**Post date:** [March 14, 2016, 8:17am UTC](https://discuss.elastic.co/t/problems-with-logstash-codecs-json-rubydebug/44252/4 "2016-03-14T08:17:46Z")

</div>

output {  
elasticsearch {  
hosts =\> ["127.0.0.1"]  
}  
}

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [March 14, 2016, 8:45am UTC](https://discuss.elastic.co/t/problems-with-logstash-codecs-json-rubydebug/44252/5 "2016-03-14T08:45:39Z")

</div>

Like Magnus said, it's probably your sincedb.

---

<div class="post-metadata">

**Author:** ![tetlika](https://avatars.discourse-cdn.com/v4/letter/t/c6cbf5/32.png) [@tetlika](https://discuss.elastic.co/u/tetlika)\
**Post date:** [March 14, 2016, 2:40pm UTC](https://discuss.elastic.co/t/problems-with-logstash-codecs-json-rubydebug/44252/6 "2016-03-14T14:40:33Z")

</div>

what you mean exactly?

but not just kibana logs is not working - logstash too

how it can be fixed?

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [March 14, 2016, 2:48pm UTC](https://discuss.elastic.co/t/problems-with-logstash-codecs-json-rubydebug/44252/7 "2016-03-14T14:48:42Z")

</div>

Logstash's file input is designed to continuously monitor log files and send newly added data but not resend old data. When you restart Logstash after changing the configuration Logstash won't reprocess the file again unless you delete Logstash's sincedb file which contains the current position in the log files it reads. The file input documentation explains how this works.

---

<div class="post-metadata">

**Author:** ![tetlika](https://avatars.discourse-cdn.com/v4/letter/t/c6cbf5/32.png) [@tetlika](https://discuss.elastic.co/u/tetlika)\
**Post date:** [March 14, 2016, 2:50pm UTC](https://discuss.elastic.co/t/problems-with-logstash-codecs-json-rubydebug/44252/8 "2016-03-14T14:50:05Z")

</div>

yes, but new data goes into file after restart

so , when codecs are used data does not go to output - not to elasticsearch neither to stdout (which I tyde for tests)

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [March 14, 2016, 2:53pm UTC](https://discuss.elastic.co/t/problems-with-logstash-codecs-json-rubydebug/44252/9 "2016-03-14T14:53:20Z")

</div>

> yes, but new data goes into file after restart

Yes, new data will always be processed as it arrives.

> so , when codecs are used data does not go to output - not to elasticsearch neither to stdout (which I tyde for tests)

This is unrelated to codecs.

---

<div class="post-metadata">

**Author:** ![tetlika](https://avatars.discourse-cdn.com/v4/letter/t/c6cbf5/32.png) [@tetlika](https://discuss.elastic.co/u/tetlika)\
**Post date:** [March 14, 2016, 2:54pm UTC](https://discuss.elastic.co/t/problems-with-logstash-codecs-json-rubydebug/44252/10 "2016-03-14T14:54:57Z")

</div>

what would you suggest to try to find out what is the problem?

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [March 14, 2016, 2:56pm UTC](https://discuss.elastic.co/t/problems-with-logstash-codecs-json-rubydebug/44252/11 "2016-03-14T14:56:59Z")

</div>

From the evidence I've seen Logstash works as expected. Please read the file input documentation and make sure you understand how sincedb works. If you increase Logstash's logging verbosity by starting it with `--verbose` it'll tell you more about what's going on with the sincedb files.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 5:07am UTC](https://discuss.elastic.co/t/problems-with-logstash-codecs-json-rubydebug/44252/12 "2017-07-06T05:07:08Z")

</div>


