# Alter how filebeats send data to output

**URL:** <https://discuss.elastic.co/t/alter-how-filebeats-send-data-to-output/64362>\
**Category:** Beats\
**Created:** [October 30, 2016, 3:39am UTC](https://discuss.elastic.co/t/alter-how-filebeats-send-data-to-output/64362 "2016-10-30T03:39:12Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![kalapakim](https://avatars.discourse-cdn.com/v4/letter/k/3bc359/32.png) [@kalapakim](https://discuss.elastic.co/u/kalapakim)\
**Post date:** [October 30, 2016, 3:39am UTC](https://discuss.elastic.co/t/alter-how-filebeats-send-data-to-output/64362/1 "2016-10-30T03:39:12Z")

</div>

We are created custom logs in json format and appending as a string, such as:

`{"host": "Kawika_DevServer","app_name": "Kafka Test Client","log_level": "Info","event_name": "MessageSend","extended_properties": {"kawika_log": {"logger_utility_testing": {"time": "' + time_now + '"}}}}`

When filebeats consumes it and sends to the output, it wraps it in it's own json object, like so:

```
{
  "@timestamp": "2016-10-30T02:56:52.145Z",
  "beat": {
"hostname": "MTPCTSCID807",
"name": "MTPCTSCID807",
"version": "5.0.0"
  },
  "input_type": "log",
  "message": "{\"host\": \"Kawika_DevServer\",\"app_name\": \"Kafka Test Client\",\"log_level\": \"Info\",\"event_name\": \"MessageSend\",\"extended_properties\": {\"kawika_log\": {\"logger_utility_testing\": {\"time\": \"2016-10-30T02:56:43.030Z\"}}}}",
  "offset": 9630,
  "source": "D:\\Logs\\logger.log",
  "type": "logging_test"
}

```

But this is not how we want to send it, we just want the string. Is there a way to alter how filebeats send the logs it is consuming?

Thanks

---

<div class="post-metadata">

**Author:** ![steffens](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/steffens/32/79630_2.png) [@steffens](https://discuss.elastic.co/u/steffens)\
**Post date:** [October 30, 2016, 3:06pm UTC](https://discuss.elastic.co/t/alter-how-filebeats-send-data-to-output/64362/2 "2016-10-30T15:06:33Z")

</div>

filebeat currently only sends JSON documents. Your event looks like you're forwarding the raw message. Consider using JSON parser in filebeat + put fields under root to get your original event + some beats meta-data. Use beats processors to remove fields you're not interested in.

---

<div class="post-metadata">

**Author:** ![kalapakim](https://avatars.discourse-cdn.com/v4/letter/k/3bc359/32.png) [@kalapakim](https://discuss.elastic.co/u/kalapakim)\
**Post date:** [October 31, 2016, 2:48pm UTC](https://discuss.elastic.co/t/alter-how-filebeats-send-data-to-output/64362/3 "2016-10-31T14:48:16Z")

</div>

Where can I find some documentation on how to make the JSON parser work. I'm not finding anything..

---

<div class="post-metadata">

**Author:** ![ruflin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ruflin/32/3116_2.png) [@ruflin](https://discuss.elastic.co/u/ruflin)\
**Post date:** [October 31, 2016, 5:10pm UTC](https://discuss.elastic.co/t/alter-how-filebeats-send-data-to-output/64362/4 "2016-10-31T17:10:41Z")

</div>

Here you find all the details: [https://www.elastic.co/guide/en/beats/filebeat/5.0/configuration-filebeat-options.html#config-json](https://www.elastic.co/guide/en/beats/filebeat/5.0/configuration-filebeat-options.html#config-json)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 20, 2016, 3:39am UTC](https://discuss.elastic.co/t/alter-how-filebeats-send-data-to-output/64362/5 "2016-11-20T03:39:24Z")

</div>

This topic was automatically closed after 21 days. New replies are no longer allowed.
