# JSON Extractor stops messages from showing up in input

**URL:** <https://community.graylog.org/t/json-extractor-stops-messages-from-showing-up-in-input/24921>\
**Category:** Graylog Central (peer support)\
**Created:** [July 22, 2022, 7:39am UTC](https://community.graylog.org/t/json-extractor-stops-messages-from-showing-up-in-input/24921 "2022-07-22T07:39:51Z")\
**Posts on this page:** 10\
**Page:** 1

<div class="post-metadata">

**Author:** ![cesq](https://avatars.discourse-cdn.com/v4/letter/c/f0a364/32.png) [@cesq](https://community.graylog.org/u/cesq)\
**Post date:** [July 22, 2022, 7:39am UTC](https://community.graylog.org/t/json-extractor-stops-messages-from-showing-up-in-input/24921/1 "2022-07-22T07:39:51Z")

</div>

Hello,  
I have an Input that collects nginx access logs that are sent in the JSON format. I’ve been following the official Graylog guide on how to set up the extractor: [How to use a JSON Extractor | Graylog](https://www.graylog.org/videos/json-extractor)

As it’s been suggested in the guide, I have two extractors: One to parse the message into a json field and one that extracts it.

Here’s an example message before parsing into a proper json field (data changed for privacy):

**MyHost nginx** : { “timestamp”: “1658474614.043”, “remote\_addr”: “x.x.x.x.x”, “body\_bytes\_sent”: 229221, “request\_time”: 0.005, “response\_status”: 200, “request”: “GET /foo/bar/1999/09/sth.jpeg HTTP/2.0”, “request\_method”: “GET”, “host”: “www…somesite.com”,“upstream\_cache\_status”: “”,“upstream\_addr”: “x.x.x.x.x:xxx”,“http\_x\_forwarded\_for”: “”,“http\_referrer”: “https:////www.somesite.com/foo/bar/woo/boo/moo”, “http\_user\_agent”: “Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/103.0.0.0 Safari/537.36”, “http\_version”: “HTTP/2.0”, “nginx\_access”: true }

And it is successfully extracted into a json field by a regex extractor: **nginx:\s+(.\*)**

{ “timestamp”: “1658474614.043”, “remote\_addr”: “x.x.x.x.x”, “body\_bytes\_sent”: 229221, “request\_time”: 0.005, “response\_status”: 200, “request”: “GET /foo/bar/1999/09/sth.jpeg HTTP/2.0”, “request\_method”: “GET”, “host”: “www…somesite.com”,“upstream\_cache\_status”: “”,“upstream\_addr”: “x.x.x.x.x:xxx”,“http\_x\_forwarded\_for”: “”,“http\_referrer”: “[https://www.somesite.com/foo/bar/woo/boo/moo](https://www.somesite.com/foo/bar/woo/boo/moo)”, “http\_user\_agent”: “Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/103.0.0.0 Safari/537.36”, “http\_version”: “HTTP/2.0”, “nginx\_access”: true }

After that it goes to the second extractor that fails completely. Not only is the preview incorrect (it omits some fields entirely):  
**remote\_addr**  
x.x.x.x  
**request**  
GET /sth.dat HTTP/1.1  
**response\_status**  
301  
**upstream\_addr**  
**body\_bytes\_sent**  
162  
**http\_version**  
HTTP/1.1  
**request\_method**  
GET  
**nginx\_access**  
**http\_user\_agent**  
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/103.0.0.0 Safari/537.36  
**request\_time**  
0  
**upstream\_cache\_status**  
**host**  
sth  
**http\_x\_forwarded\_for**  
**http\_referrer**  
**timestamp**  
1658475023.035

It also keeps missing, it doesn’t extract at all:  
 ![obraz](https://us1.discourse-cdn.com/flex016/uploads/graylog/original/2X/1/1075b90f4d48c86abffdcfec81d30050a8923326.png)

The second Extractor configuration is left default with the exception of “flatten structure” option being turned on.

I kindly request your help and wish you a good day!

---

<div class="post-metadata">

**Author:** ![cesq](https://avatars.discourse-cdn.com/v4/letter/c/f0a364/32.png) [@cesq](https://community.graylog.org/u/cesq)\
**Post date:** [July 22, 2022, 9:20am UTC](https://community.graylog.org/t/json-extractor-stops-messages-from-showing-up-in-input/24921/2 "2022-07-22T09:20:58Z")

</div>

I have come to the conclusion that the extractor works properly, however it still keeps missing. I do not know why this happens

---

<div class="post-metadata">

**Author:** ![cesq](https://avatars.discourse-cdn.com/v4/letter/c/f0a364/32.png) [@cesq](https://community.graylog.org/u/cesq)\
**Post date:** [July 22, 2022, 11:52am UTC](https://community.graylog.org/t/json-extractor-stops-messages-from-showing-up-in-input/24921/3 "2022-07-22T11:52:58Z")

</div>

Update: As soon as I apply the second extractor, the messages stop coming in.

---

<div class="post-metadata">

**Author:** ![gsmith](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/gsmith/32/1222_2.png) [@gsmith](https://community.graylog.org/u/gsmith)\
**Post date:** [July 22, 2022, 10:15pm UTC](https://community.graylog.org/t/json-extractor-stops-messages-from-showing-up-in-input/24921/4 "2022-07-22T22:15:32Z")

</div>

Hello && Welcome @cesq

We would need to see the configuration made, How your ingesting them, logs (i.e., GL , ES) etc…  
Its had to tell what the issue is from the information given.  
When you do post any configuration please use the markdown, if you’re unsure take a look [here](https://community.graylog.org/t/how-to-post-a-question-in-the-community-that-gets-responses/20879)

---

<div class="post-metadata">

**Author:** ![cesq](https://avatars.discourse-cdn.com/v4/letter/c/f0a364/32.png) [@cesq](https://community.graylog.org/u/cesq)\
**Post date:** [July 23, 2022, 6:54am UTC](https://community.graylog.org/t/json-extractor-stops-messages-from-showing-up-in-input/24921/5 "2022-07-23T06:54:07Z")

</div>

Hi, sadly I don’t understand what you mean by that. Nor do I understand these terms. Configuration of what exactly would you like to see?

---

<div class="post-metadata">

**Author:** ![cesq](https://avatars.discourse-cdn.com/v4/letter/c/f0a364/32.png) [@cesq](https://community.graylog.org/u/cesq)\
**Post date:** [July 25, 2022, 7:31am UTC](https://community.graylog.org/t/json-extractor-stops-messages-from-showing-up-in-input/24921/6 "2022-07-25T07:31:27Z")

</div>

Graylog version is 4.2.10+37fbc90 and it’s running on Red Hat - kernel 4.18

---

<div class="post-metadata">

**Author:** ![cesq](https://avatars.discourse-cdn.com/v4/letter/c/f0a364/32.png) [@cesq](https://community.graylog.org/u/cesq)\
**Post date:** [July 25, 2022, 7:52am UTC](https://community.graylog.org/t/json-extractor-stops-messages-from-showing-up-in-input/24921/7 "2022-07-25T07:52:27Z")

</div>

@gsmith I found an error log

 ![err new](https://us1.discourse-cdn.com/flex016/uploads/graylog/original/2X/c/c265eb3a7b1b2d97cfb1b261f8d0ea64a9d9a563.png)  
It has something to do with the DateTime format

---

<div class="post-metadata">

**Author:** ![gsmith](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/gsmith/32/1222_2.png) [@gsmith](https://community.graylog.org/u/gsmith)\
**Post date:** [July 25, 2022, 9:11pm UTC](https://community.graylog.org/t/json-extractor-stops-messages-from-showing-up-in-input/24921/8 "2022-07-25T21:11:19Z")

</div>

Hello,

Error shown above, Elasticsearch failed to parse the date in the “DateTime” field. You need to convert it and best option probably would be a pipeline

---

<div class="post-metadata">

**Author:** ![cesq](https://avatars.discourse-cdn.com/v4/letter/c/f0a364/32.png) [@cesq](https://community.graylog.org/u/cesq)\
**Post date:** [July 27, 2022, 7:29am UTC](https://community.graylog.org/t/json-extractor-stops-messages-from-showing-up-in-input/24921/9 "2022-07-27T07:29:31Z")

</div>

Solution on this post: [Failed to index [1] messages. failed to parse field [DateTime] of type [date] in document - #6 by cesq](https://community.graylog.org/t/failed-to-index-1-messages-failed-to-parse-field-datetime-of-type-date-in-document/24960/6)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/flex016/uploads/graylog/original/3X/c/7/c7c09c6b5099570133d6502b83f50ba4430de5b6.png) [@system](https://community.graylog.org/u/system)\
**Post date:** [August 10, 2022, 7:30am UTC](https://community.graylog.org/t/json-extractor-stops-messages-from-showing-up-in-input/24921/10 "2022-08-10T07:30:13Z")

</div>

This topic was automatically closed 14 days after the last reply. New replies are no longer allowed.
