# Custom logs ingest: how?

**URL:** <https://discuss.elastic.co/t/custom-logs-ingest-how/321928>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [December 23, 2022, 3:24pm UTC](https://discuss.elastic.co/t/custom-logs-ingest-how/321928 "2022-12-23T15:24:46Z")\
**Posts on this page:** 1\
**Showing post:** 2

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [December 23, 2022, 3:41pm UTC](https://discuss.elastic.co/t/custom-logs-ingest-how/321928/2 "2022-12-23T15:41:27Z")

</div>

Hi @Johannnnnn

I suspect your first issue is that your JSON is Pretty formatted / multi-line and filebeat is line oriented so it expects the JSON to be single line ndjson.

If your file actually looks like above, you're going to have to use a multiline parser or just simply convert it to newline delimited with `jq` [here](https://discuss.elastic.co/t/error-in-parsing-pretty-json-data/293103/3) are some instructions ignore it for logstash, same concept

Once in ndjson see [here](https://www.elastic.co/guide/en/beats/filebeat/current/filebeat-input-filestream.html#_ndjson)

If you don't want to do that, then please provide an actual sample of your file with multiple entries. Then we'll have to construct a multi-line parser which is not always easy. If you were saying it is alwaysif you were saying it is always exactly the same number of lines You can do multi-line with just number of lines... Otherwise you have to construct a regex expression.

Second part I do not recommend trying to remove parts of filebeat to get rid of the fields. Just used to [drop\_field](https://www.elastic.co/guide/en/beats/filebeat/current/drop-fields.html) processor and drop the host agent, ECS fields, etc. People do that all the time. It's very common to clean up the output ... Quick and easy

---

_[View the full topic](https://discuss.elastic.co/t/custom-logs-ingest-how/321928)._
