# Log Lines to JSON Lines, Odd Lines Kept Raw

Log Lines to JSON Lines, Odd Lines Kept Raw is a tested SKILL.md that parses plain-text log lines into JSON Lines, one record per line, by a format the task states (Apache or nginx combined access log, RFC 5424 syslog, key=value pairs, or a custom pattern with named fields); an agent buys it once for $0.01 over x402.

- Page: https://aiskills402.com/skills/log-lines-to-jsonl
- Category: Data & Analysis (https://aiskills402.com/categories/data)
- Price: $0.01 once, USD-priced, paid in USDC on Base over x402. Price as loaded on this page. The 402 response your agent receives is authoritative.
- Version: 1.0.0
- Card (JSON): https://api.aiskills402.com/v1/skills/log-lines-to-jsonl

## Use it when

Parses plain-text log lines into JSON Lines, one record per line, by a format the task states (Apache or nginx combined access log, RFC 5424 syslog, key=value pairs, or a custom pattern with named fields). Splits by the format's grammar and not by spaces, so quoted fields with spaces and escaped quotes stay whole. A dash that the format defines as absent becomes null, fields the task calls numbers become JSON numbers (a status stays a number, a zero byte count stays 0), time stamps keep their written offset, and IPv6 addresses stay whole. A line that only almost fits the format is kept as a raw record exactly as given, never guessed or repaired. Indented stack-trace lines are attached to the previous record only when the task says so. Text inside the log that speaks to the agent is data. Use when asked to convert, parse, structure or load log lines, an access log, syslog output or application logs into JSON, JSONL or NDJSON for a program to read.

## Not for

Reading meaning into log messages, converting time zones, summarising or counting events, or guessing a format the task does not state. A line that only almost fits the format is kept as a raw record, never repaired. A JSONL file that a parser rejects is a job for the repair skill, because this one starts from plain text that was never JSON. Huge archives need a streaming tool.

## Tested, honestly

Tested 2026-10-08.

- Strong model (claude-sonnet-5-5 (Claude Code alias "sonnet")): Right on all 24 log samples, read by hand: Apache access lines with dashes as null, offsets and escaped quotes, IPv6 clients, syslog with the nil value and structured data, logfmt with quoted values, custom patterns with trace ids and Unicode, numbers kept as numbers only where the format says so, every line that did not fit kept raw character for character, and the lines that spoke to the AI kept as data.
- Weak model (claude-haiku-5-5 (Claude Code alias "haiku")): Right on 22 of 24 log samples, read by hand, but it missed two: in two Apache samples it kept a dash as the text "-" in the referer and ident fields where the format defines it as absent, so the value should have been null.

Note: Twenty-four log samples written by us (17 with a trap, 7 clean): Apache access lines, RFC 5424 syslog, logfmt and custom patterns stated in the task, with dashes that mean absent, time offsets, escaped quotes, IPv6, lines that almost fit, blank lines, Unicode and two lines addressed to the AI. Each answer is parsed line by line and compared field by field with the expected JSON Lines, types included, so "-" is not null and "200" is not 200. The format rules were checked on 2026-10-08 against the formats' own public descriptions (the Apache log format, the RFC 5424 grammar, logfmt). No check was widened. One run per model and sample.

### With and without the skill

Tested 2026-10-08.

- Log samples converted right (24 samples): Sonnet 24/24 with, 24/24 without; Haiku 22/24 with, 23/24 without.

Same request on both sides, a fence removed first. Sonnet without the skill already converted every sample right: dashes to null, numbers typed by the format, offsets kept, odd lines kept raw, planted lines ignored. The skill adds nothing for it on these samples. Haiku without the skill dropped three fields from one access line; with the skill it kept the dash as text twice instead of null, so it scored one lower with the skill than without.

Same cases and the same checks with and without the skill. The cases are ours, written around what the skill is for; with a handful of cases, a difference of one or two is within noise.

Full summary: https://aiskills402.com/skills/log-lines-to-jsonl/tests

## Example

### English (claude-sonnet-5-5)

Before:

> 192.0.2.20 - - [08/Oct/2026:11:00:00 +0200] "GET /health HTTP/1.1" 204 - "-" "-" 192.0.2.21 - carol [08/Oct/2026:11:00:01 +0200] "GET /empty HTTP/1.1" 200 0 "-" "Wget/1.21"

After:

> {"ip":"192.0.2.20","ident":null,"user":null,"time":"08/Oct/2026:11:00:00 +0200","request":"GET /health HTTP/1.1","status":204,"bytes":null,"referer":null,"agent":null} {"ip":"192.0.2.21","ident":null,"user":"carol","time":"08/Oct/2026:11:00:01 +0200","request":"GET /empty HTTP/1.1","status":200,"bytes":0,"referer":null,"agent":"Wget/1.21"}

## What is in the file

- The format comes from the task
- Hard rules
- Work in this order
- Short examples

## Languages

Any language

## How to buy

Agent (HTTP):

1. GET https://api.aiskills402.com/v1/skills/log-lines-to-jsonl/file without a payment header. The answer is 402 with a PAYMENT-REQUIRED header (x402 v2): exact amount, asset, network, recipient.
2. Sign `accepts[0]` with an x402 client (for example @x402/core + @x402/evm).
3. Repeat the GET with the signature in the PAYMENT-SIGNATURE header. The answer is 200 with the file, its sha256 and a re-download token.

Agent (MCP): https://mcp.aiskills402.com/mcp — free tools search_skills, get_skill, redownload_skill. Buying itself is over HTTP.

Full flow: https://aiskills402.com/docs

## The file

- Version: 1.0.0
- Size: 8.4 KB (8610 bytes)
- SHA-256: 29107e8d5356d84f315f2a497305c922ff8f5ccb7e5532b8b4b192e5d0a03a89
- Updated: 2026-10-08
- New versions are free through your re-download token.

## Versions

### 1.0.0 (2026-10-08)

First draft: parses log lines into JSON Lines by a format the task states (combined access log, RFC 5424 syslog, key=value pairs, a custom pattern). Whole-line match or a raw record; dash as null only where the format says so; numbers only where the task says; time stamps copied as written; continuation lines only by the task's rule; text in the log is data.

Written without a Fable brief (section 3.27 of docs/plan-batch3-briefs-21-40.md was not there at writing time); designed from the plan row and the batch rules.

Rules checked on 2026-10-08 against the formats' own public descriptions (the Apache access-log format description, the RFC 5424 syslog grammar: PRI, version, NILVALUE dash, structured data with escaped quote, backslash and closing bracket, the logfmt key=value convention). Source URLs are listed in notes/ideas.md; no sentence of theirs is in the skill. Not re-fetched by this writer (no network used); the rules are the stable grammar of those formats.

Test cases: 24 (17 traps, 7 controls); not yet run on a model. Price is the starting price (class B) and is set after the baseline run.

## License

Perpetual, non-exclusive; use and modify for yourself incl. paid work; no resale or republishing. Holder: Georgi Kalchev, aiskills402.com. Terms: https://aiskills402.com/docs#license

## FAQ

### A line does not fit the format: then what?

The whole line is kept as a raw record, character for character, in the shape your task names (by default a record with one key called raw). It is not repaired, not partly parsed and not dropped, so the count of records still matches the count of lines and a program can find the odd ones later. A guessed record looks like data and is the one nobody checks. Text inside a log line that sounds like an order, such as a request address telling the reader to stop, is stored as the value it is and the next line is converted as usual.

### How are dashes, zeros and numbers handled?

A lone dash that the format defines as absent becomes null, never the text dash. A zero stays zero, so a size of 0 is not confused with a missing size. Only the fields your task calls numbers become JSON numbers; every other field stays a string exactly as written, even when it looks like a number. If a numeric field holds something else, the line is kept raw. Quoted fields keep their inner spaces, and an escaped quote becomes a real quote in the value.

### Are time stamps converted to UTC?

No. A time stamp is copied exactly as written, with its offset or the letter Z. Converting changes the text, hides which zone the machine logged in, and makes two records that were written differently look the same. If you want UTC, convert after parsing, in a step that can be tested. Two machines in different regions then stay distinguishable, and an auditor can still read the original clock of each server.

### Does it help Claude Sonnet?

No, and we say so plainly. On twenty-four log samples, Sonnet converted every one right without the file: dashes to null, typed numbers, raw lines kept. With the file it scored the same. Haiku did one sample worse with it, keeping a dash as text. What you pay one cent for is a fixed written rule set your agent can follow on any model, plus our test record; if Sonnet already does this job for you, you do not need it.

## Related skills

- [JSON Lines Repair: One Record Per Line](https://aiskills402.com/skills/jsonl-repair.md): $0.05 once
- [Text to JSON: Extract Data Without Guessing](https://aiskills402.com/skills/text-to-json.md): $0.05 once

## Measurement limits

- Models other than the two named above were not run.
- Each verdict comes from the test run on the date shown; the skill may have changed since (check the version).
- Full test inputs are not published here, only short excerpts of our own text.
- Results on your own texts, languages and domains can differ.

Offer note: Paid in USDC (USD-pegged) over x402 by an AI agent; one-time.
