# JSON Extractor Problem 2

**URL:** <https://community.graylog.org/t/json-extractor-problem-2/3150>\
**Category:** Graylog Central (peer support)\
**Created:** [November 13, 2017, 5:12pm UTC](https://community.graylog.org/t/json-extractor-problem-2/3150 "2017-11-13T17:12:27Z")\
**Posts on this page:** 11\
**Page:** 1

<div class="post-metadata">

**Author:** ![habib-the-sweet](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/habib-the-sweet/32/1204_2.png) [@habib-the-sweet](https://community.graylog.org/u/habib-the-sweet)\
**Post date:** [November 13, 2017, 5:12pm UTC](https://community.graylog.org/t/json-extractor-problem-2/3150/1 "2017-11-13T17:12:27Z")

</div>

Hello. I have the same problem like in [Problem with JSON extractor](https://community.graylog.org/t/problem-with-json-extractor/1313)

I have JSON messages:

`{"timestamp":"2017-11-13T17:09:32.878Z","level":"INFO","message":"Exchange [creators/createAllExchangersForUser]: Currencies to gen: ","meta":""}`

After enabling JSON extractor for message field I have errors in my server log:

```
2017-11-13T16:58:56.475Z ERROR [BlockingBatchedESOutput] Unable to flush message buffer
java.lang.ClassCastException: Cannot cast java.lang.String to org.joda.time.DateTime
	at java.lang.Class.cast(Class.java:3369) ~[?:1.8.0_151]
	at org.graylog2.plugin.Message.getFieldAs(Message.java:384) ~[graylog.jar:?]
	at org.graylog2.plugin.Message.getTimestamp(Message.java:189) ~[graylog.jar:?]
	at org.graylog2.indexer.messages.Messages.propagateFailure(Messages.java:181) ~[graylog.jar:?]
	at org.graylog2.indexer.messages.Messages.bulkIndex(Messages.java:145) ~[graylog.jar:?]
	at org.graylog2.outputs.ElasticSearchOutput.writeMessageEntries(ElasticSearchOutput.java:111) ~[graylog.jar:?]
	at org.graylog2.outputs.BlockingBatchedESOutput.flush(BlockingBatchedESOutput.java:129) [graylog.jar:?]
	at org.graylog2.outputs.BlockingBatchedESOutput.writeMessageEntry(BlockingBatchedESOutput.java:110) [graylog.jar:?]
	at org.graylog2.outputs.BlockingBatchedESOutput.write(BlockingBatchedESOutput.java:92) [graylog.jar:?]
	at org.graylog2.buffers.processors.OutputBufferProcessor$1.run(OutputBufferProcessor.java:191) [graylog.jar:?]
	at com.codahale.metrics.InstrumentedExecutorService$InstrumentedRunnable.run(InstrumentedExecutorService.java:176) [graylog.jar:?]
	at java.util.concurrent.Executors$RunnableAdapter.call(Executors.java:511) [?:1.8.0_151]
	at java.util.concurrent.FutureTask.run(FutureTask.java:266) [?:1.8.0_151]
	at java.util.concurrent.ThreadPoolExecutor.runWorker(ThreadPoolExecutor.java:1149) [?:1.8.0_151]
	at java.util.concurrent.ThreadPoolExecutor$Worker.run(ThreadPoolExecutor.java:624) [?:1.8.0_151]
	at java.lang.Thread.run(Thread.java:748) [?:1.8.0_151]

```

The timestamp field is vaild. How I can resolve this issue?

Graylog 2.3.2+3df951e on localhost (Oracle Corporation 1.8.0\_151 on Linux 4.4.0-78-generic)

---

<div class="post-metadata">

**Author:** ![jochen](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/jochen/32/8_2.png) [@jochen](https://community.graylog.org/u/jochen)\
**Post date:** [November 13, 2017, 7:45pm UTC](https://community.graylog.org/t/json-extractor-problem-2/3150/2 "2017-11-13T19:45:48Z")

</div>

“timestamp” is a special field and has to be an actual date/time and not a string.

You can either use a “Key prefix” in your JSON extractor, so that the field will be extracted to another name (e. g. “timestamp” → “custom\_timestamp”, “level” → “custom\_level”) or write a pipeline rule which extracts the JSON payload with [`parse_json()`](http://docs.graylog.org/en/2.3/pages/pipelines/functions.html#parse-json) and then converts the “timestamp” field to an actual date/time with [`parse_date()`](http://docs.graylog.org/en/2.3/pages/pipelines/functions.html#parse-date).

---

<div class="post-metadata">

**Author:** ![habib-the-sweet](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/habib-the-sweet/32/1204_2.png) [@habib-the-sweet](https://community.graylog.org/u/habib-the-sweet)\
**Post date:** [November 13, 2017, 8:19pm UTC](https://community.graylog.org/t/json-extractor-problem-2/3150/3 "2017-11-13T20:19:04Z")

</div>

But It is actual log timestamp, not some kind of custom timestamp. Can this extractor substitute the timestamp from JSON field?

---

<div class="post-metadata">

**Author:** ![jochen](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/jochen/32/8_2.png) [@jochen](https://community.graylog.org/u/jochen)\
**Post date:** [November 14, 2017, 9:19am UTC](https://community.graylog.org/t/json-extractor-problem-2/3150/4 "2017-11-14T09:19:03Z")

</div>

> [@habib-the-sweet](#):
>
> But It is actual log timestamp, not some kind of custom timestamp.

No, it’s a string which contains something resembling an ISO-8601 timestamp in Zulu time.

You have to use `parse_date()` to convert it into a “real” date/time instance as described in my previous post.

---

<div class="post-metadata">

**Author:** ![habib-the-sweet](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/habib-the-sweet/32/1204_2.png) [@habib-the-sweet](https://community.graylog.org/u/habib-the-sweet)\
**Post date:** [November 14, 2017, 1:46pm UTC](https://community.graylog.org/t/json-extractor-problem-2/3150/5 "2017-11-14T13:46:50Z")

</div>

It is absolutely valid ISO 8601 timesatmp [https://www.regexpal.com/97766](https://www.regexpal.com/97766)  
Why have I use some pipeline rules or extract timestamp to another field when Graylog should parse this normally?

---

<div class="post-metadata">

**Author:** ![jochen](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/jochen/32/8_2.png) [@jochen](https://community.graylog.org/u/jochen)\
**Post date:** [November 14, 2017, 3:52pm UTC](https://community.graylog.org/t/json-extractor-problem-2/3150/6 "2017-11-14T15:52:36Z")

</div>

A string object is not a date object, that’s why you have to use `parse_date()`.

---

<div class="post-metadata">

**Author:** ![habib-the-sweet](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/habib-the-sweet/32/1204_2.png) [@habib-the-sweet](https://community.graylog.org/u/habib-the-sweet)\
**Post date:** [November 14, 2017, 5:17pm UTC](https://community.graylog.org/t/json-extractor-problem-2/3150/7 "2017-11-14T17:17:45Z")

</div>

Well. I just renamed timestamp field from JSON and have got next error:

`ERROR [Messages] Failed to index [3] messages. Please check the index error log in your web interface for the reason. Error: One or more of the items in the Bulk request failed, check BulkResult.getItems() for more information.`

`{"type":"mapper_parsing_exception","reason":"failed to parse [level]","caused_by":{"type":"number_format_exception","reason":"For input string: \"INFO\""}}`

---

<div class="post-metadata">

**Author:** ![jochen](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/jochen/32/8_2.png) [@jochen](https://community.graylog.org/u/jochen)\
**Post date:** [November 14, 2017, 5:32pm UTC](https://community.graylog.org/t/json-extractor-problem-2/3150/8 "2017-11-14T17:32:54Z")

</div>

The “level” field should be numeric, mirroring the syslog severity levels:

> **[syslog | Severity level](https://en.wikipedia.org/wiki/Syslog#Severity_level)**
>
> The list of severities is also defined by RFC 5424:

---

<div class="post-metadata">

**Author:** ![habib-the-sweet](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/habib-the-sweet/32/1204_2.png) [@habib-the-sweet](https://community.graylog.org/u/habib-the-sweet)\
**Post date:** [November 14, 2017, 6:41pm UTC](https://community.graylog.org/t/json-extractor-problem-2/3150/9 "2017-11-14T18:41:45Z")

</div>

Looks like there is a problem with elasticsearch indices. I have two inputs - kafka and nginx (from filebeat). My nginx logs already mapped fields with different types.

Is it possible to write kafka input to another index?

---

<div class="post-metadata">

**Author:** ![habib-the-sweet](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/habib-the-sweet/32/1204_2.png) [@habib-the-sweet](https://community.graylog.org/u/habib-the-sweet)\
**Post date:** [November 14, 2017, 7:21pm UTC](https://community.graylog.org/t/json-extractor-problem-2/3150/10 "2017-11-14T19:21:59Z")

</div>

It is okay now. I just created new index set and new stream with “Remove matches from ‘All messages’ stream” option. Now JSON parsing as expected. Thank you

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/flex016/uploads/graylog/original/3X/c/7/c7c09c6b5099570133d6502b83f50ba4430de5b6.png) [@system](https://community.graylog.org/u/system)\
**Post date:** [November 28, 2017, 7:22pm UTC](https://community.graylog.org/t/json-extractor-problem-2/3150/11 "2017-11-28T19:22:03Z")

</div>

This topic was automatically closed 14 days after the last reply. New replies are no longer allowed.
