# Syslog input decode json

**URL:** <https://discuss.elastic.co/t/syslog-input-decode-json/182645>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [May 24, 2019, 12:37pm UTC](https://discuss.elastic.co/t/syslog-input-decode-json/182645 "2019-05-24T12:37:24Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![soerenfrisk](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/soerenfrisk/32/42585_2.png) [@soerenfrisk](https://discuss.elastic.co/u/soerenfrisk)\
**Post date:** [May 24, 2019, 12:37pm UTC](https://discuss.elastic.co/t/syslog-input-decode-json/182645/1 "2019-05-24T12:37:24Z")

</div>

I have a tcp syslog input in filebeat, the incoming data is json. i would want to decode json to top level keys in elastic search. To do this has been quite the challenge for me, and i hope someone is able to help.

as the syslog input does not have an option to decode json, as the log input, i figured i either had to use Logstash or an ingest node in elastic search. I created a new ingest pipeline in elasticsearch. I have used the simulate to test if i put the content of my syslog into the "message" field (also the field targeted for decode". It all works and the response shows it correctly.

but as soon as i choose a pipeline id in my filebeat.yml either in the input or output i get this error from filebeat: `ERROR	[syslog]	syslog/input.go:131	can't parse event as syslog rfc3164`

if i remove the pipeline id it works, but just puts all the json in the message field.

this i my filebeat.yml file:

```auto
filebeat.inputs:
  - type: syslog
    protocol.tcp:
      host: ":9000"
    pipeline: "pipeline_name"

cloud.id: ${ELASTIC_CLOUD_ID}
cloud.auth: ${ELASTICSEARCH_USERNAME}:${ELASTICSEARCH_PASSWORD}

```

Here is the configuration for the pipeline:

```auto
"pipeline_name": {
    "description": "json decode",
    "processors": [
      {
        "json": {
          "field": "message",
          "add_to_root": true
        }
      }
    ]
}

```

---

<div class="post-metadata">

**Author:** ![faec](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/faec/32/46988_2.png) [@faec](https://discuss.elastic.co/u/faec)\
**Post date:** [May 29, 2019, 7:38pm UTC](https://discuss.elastic.co/t/syslog-input-decode-json/182645/2 "2019-05-29T19:38:23Z")

</div>

It's hard to tell how the pipeline id is breaking it from just the filebeat configuration. Could you share your pipeline configuration too?

---

<div class="post-metadata">

**Author:** ![soerenfrisk](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/soerenfrisk/32/42585_2.png) [@soerenfrisk](https://discuss.elastic.co/u/soerenfrisk)\
**Post date:** [June 3, 2019, 6:37am UTC](https://discuss.elastic.co/t/syslog-input-decode-json/182645/3 "2019-06-03T06:37:30Z")

</div>

Yes ofcourse! I have updated my question

---

<div class="post-metadata">

**Author:** ![soerenfrisk](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/soerenfrisk/32/42585_2.png) [@soerenfrisk](https://discuss.elastic.co/u/soerenfrisk)\
**Post date:** [June 11, 2019, 10:40am UTC](https://discuss.elastic.co/t/syslog-input-decode-json/182645/4 "2019-06-11T10:40:47Z")

</div>

anyone can help with this?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 9, 2019, 10:40am UTC](https://discuss.elastic.co/t/syslog-input-decode-json/182645/5 "2019-07-09T10:40:50Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
