# Json configuration for GELF using test VM

**URL:** <https://community.graylog.org/t/json-configuration-for-gelf-using-test-vm/9704>\
**Category:** Graylog Central (peer support)\
**Created:** [March 31, 2019, 10:27am UTC](https://community.graylog.org/t/json-configuration-for-gelf-using-test-vm/9704 "2019-03-31T10:27:15Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![quarterpipe](https://avatars.discourse-cdn.com/v4/letter/q/d26b3c/32.png) [@quarterpipe](https://community.graylog.org/u/quarterpipe)\
**Post date:** [March 31, 2019, 10:27am UTC](https://community.graylog.org/t/json-configuration-for-gelf-using-test-vm/9704/1 "2019-03-31T10:27:15Z")

</div>

Hi,

I am trying to send a GELF JSON message over TCP to the graylog test VM. I have an TCP Gelf input which works and receives a message and ingests it when this JSON is used.

echo -n -e ‘{ “version”: “1.1”, “host”: “[example.org](http://example.org)”, “short\_message”: “A short message”, “level”: 5, “\_some\_info”: “foo” }’"\0" | nc -w0 192.168.1.18 12201

But when this JSON is used in place it is not picked up by the graylog input.

echo -n -e ‘{“Body”:"",“HTTPmethod”:“POST”,“Headers”:{“Accept”:["_/_"],“Accept-Encoding”:[“gzip, deflate”],“Cache-Control”:[“no-cache”],“Connection”:[“keep-alive”],“Content-Length”:[“0”],“Postman-Token”:[“0ad4e67d-f69a-4f54-a487-a91845922683”],“User-Agent”:[“PostmanRuntime/7.6.0”]},“Protocol”:“HTTP/1.1”,“URL”:"/",“level”:“info”,“logtype”:“request”,“msg”:"",“remoteip”:“127.0.0.1:52410”,“time”:“2019-03-31T21:13:25+11:00”, “short\_message”:“this is a short message”, “version”:“1.1”, “hostname”: “quarterpipe”}’"\0" | nc -w0 192.168.1.18 12201

I have checked by stopping the input and running a netcat listener and it is transferred fine, and when the input is running it gets network traffic but no messages. So what is wrong with my JSON between the 2 messages sent? Is there something else i need to do in configuration regarding expected JSON?

Thanks

---

<div class="post-metadata">

**Author:** ![jan](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/jan/32/11_2.png) [@jan](https://community.graylog.org/u/jan)\
**Post date:** [March 31, 2019, 5:39pm UTC](https://community.graylog.org/t/json-configuration-for-gelf-using-test-vm/9704/2 "2019-03-31T17:39:34Z")

</div>

GELF =! JSON

If you want to send JSON, use a RAW Input. You can find in your Graylog server.log some information if your GELF message does not follow the standard and is rejected.

---

<div class="post-metadata">

**Author:** ![quarterpipe](https://avatars.discourse-cdn.com/v4/letter/q/d26b3c/32.png) [@quarterpipe](https://community.graylog.org/u/quarterpipe)\
**Post date:** [April 1, 2019, 5:38am UTC](https://community.graylog.org/t/json-configuration-for-gelf-using-test-vm/9704/3 "2019-04-01T05:38:44Z")

</div>

Thank you. I’ll look into raw input

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/flex016/uploads/graylog/original/3X/c/7/c7c09c6b5099570133d6502b83f50ba4430de5b6.png) [@system](https://community.graylog.org/u/system)\
**Post date:** [April 15, 2019, 5:38am UTC](https://community.graylog.org/t/json-configuration-for-gelf-using-test-vm/9704/4 "2019-04-15T05:38:47Z")

</div>

This topic was automatically closed 14 days after the last reply. New replies are no longer allowed.
