# Filebeat, raw logs to JSON format to send to elasticsearch directly

**URL:** <https://discuss.elastic.co/t/filebeat-raw-logs-to-json-format-to-send-to-elasticsearch-directly/210089>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [December 1, 2019, 10:58pm UTC](https://discuss.elastic.co/t/filebeat-raw-logs-to-json-format-to-send-to-elasticsearch-directly/210089 "2019-12-01T22:58:43Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![ali\_khalil](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ali_khalil/32/57888_2.png) [@ali\_khalil](https://discuss.elastic.co/u/ali_khalil)\
**Post date:** [December 1, 2019, 10:58pm UTC](https://discuss.elastic.co/t/filebeat-raw-logs-to-json-format-to-send-to-elasticsearch-directly/210089/1 "2019-12-01T22:58:43Z")

</div>

Hi,

I had googled a lot and spent many hours but I am not able to find a satisfying answer. How can I parse the raw log strings to JSON.

Here is sample logs:  
[11/Nov/2019 18:39:15] INFO [services2.abc:123] Company name: Facebook, Inc.  
[11/Nov/2019 18:39:15] INFO [services2.abc:121] Company id: fsdfsfs3213  
[11/Nov/2019 18:39:15] ERROR [services2.abc:121] Company not found etc.

I want to send as { 'timestamp' : '[11/Nov/2019 18:39:15]', 'message': 'Company name: Facebook, Inc.' },

How can I do that? I want filebeat oriented solution. Hoping for a quick solution.

---

<div class="post-metadata">

**Author:** ![faec](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/faec/32/46988_2.png) [@faec](https://discuss.elastic.co/u/faec)\
**Post date:** [December 6, 2019, 5:43pm UTC](https://discuss.elastic.co/t/filebeat-raw-logs-to-json-format-to-send-to-elasticsearch-directly/210089/2 "2019-12-06T17:43:45Z")

</div>

Welcome! If your logs are in format with module support you can use the appropriate module to parse them. If it's a custom format, you can generate fields by [setting up processors](https://www.elastic.co/guide/en/beats/filebeat/current/defining-processors.html) -- the [dissect processor](https://www.elastic.co/guide/en/beats/filebeat/current/dissect.html) is good for simple transformations, and for more general behavior you can try the [script processor](https://www.elastic.co/guide/en/beats/filebeat/current/processor-script.html).

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 3, 2020, 5:43pm UTC](https://discuss.elastic.co/t/filebeat-raw-logs-to-json-format-to-send-to-elasticsearch-directly/210089/3 "2020-01-03T17:43:50Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
