# Want to parse multiline json logs using filebeat and logstash except non-josn logs without any failure

**URL:** <https://discuss.elastic.co/t/want-to-parse-multiline-json-logs-using-filebeat-and-logstash-except-non-josn-logs-without-any-failure/230665>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [May 1, 2020, 5:41am UTC](https://discuss.elastic.co/t/want-to-parse-multiline-json-logs-using-filebeat-and-logstash-except-non-josn-logs-without-any-failure/230665 "2020-05-01T05:41:20Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![Dragon9](https://avatars.discourse-cdn.com/v4/letter/d/7bcc69/32.png) [@Dragon9](https://discuss.elastic.co/u/Dragon9)\
**Post date:** [May 1, 2020, 5:41am UTC](https://discuss.elastic.co/t/want-to-parse-multiline-json-logs-using-filebeat-and-logstash-except-non-josn-logs-without-any-failure/230665/1 "2020-05-01T05:41:20Z")

</div>

my json log file

```auto
{
"a":{
"se":"NA",
"event":"158",
"sys":"NA",
"Id":"149",
"ma":"o",
"ab":"Pod",
"source": "Application",
"eq":"NA",
"pr":"NA",
"sev":"CRIT"
},
"b":{
"total_memory":"10GB",
"memory_usage":"8GB",
"memory_available":"2GB"
}
}

--------------abc JSON ----------------

{
"a":{
"se":"NA",
"event":"158",
"sys":"NA",
"Id":"149",
"ma":"o",
"ab":"Pod",
"source": "Application",
"eq":"NA",
"pr":"NA",
"sev":"CRIT"
},
"b":{
"total_memory":"10GB",
"memory_usage":"8GB",
"memory_available":"2GB"
}
}

```

i want to exclude "--------------abc JSON ----------------" line for now in this logfile  
and non -json log without any error

my filebeat -configuration

```auto
filebeat.yml: |-
     filebeat.inputs:
     - type: log
       paths:
         - /var/log/containers/test.log
       multiline.pattern: '^{'
       multiline.negate: true 
       multiline.match: after
     processors:
     - decode_json_fields:
         fields: ['message']
         target: ""
     - drop_fields:
         fields: ['message']     

```

logstash.conf

```auto
input {
	beats {
		port => 5044
	}
}
filter {

 json {
        
      source => "message"
   }
}
output {
    elasticsearch {
        hosts => ["http://10.109.226.97:9200"]
        user => kibanauser
        password => kibanauser
        index => "multiline-json-%{+YYYY.MM.dd}"
    }
  stdout{ codec => rubydebug }

}

```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 29, 2020, 5:41am UTC](https://discuss.elastic.co/t/want-to-parse-multiline-json-logs-using-filebeat-and-logstash-except-non-josn-logs-without-any-failure/230665/2 "2020-05-29T05:41:20Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
