# GELF output with compression option?

**URL:** <https://discuss.elastic.co/t/gelf-output-with-compression-option/164435>\
**Category:** Logstash\
**Created:** [January 16, 2019, 10:01am UTC](https://discuss.elastic.co/t/gelf-output-with-compression-option/164435 "2019-01-16T10:01:09Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![piellick](https://avatars.discourse-cdn.com/v4/letter/p/35a633/32.png) [@piellick](https://discuss.elastic.co/u/piellick)\
**Post date:** [January 16, 2019, 10:01am UTC](https://discuss.elastic.co/t/gelf-output-with-compression-option/164435/1 "2019-01-16T10:01:09Z")

</div>

Hello Everyone,

does logstash support option compressions for GELF over UDP ?

Related to this documentation :

[http://docs.graylog.org/en/latest/pages/gelf.html?highlight=compression#compression](http://docs.graylog.org/en/latest/pages/gelf.html?highlight=compression#compression)

I found nothing on logstash GELF output option :  
[https://www.elastic.co/guide/en/logstash/current/plugins-outputs-gelf.html](https://www.elastic.co/guide/en/logstash/current/plugins-outputs-gelf.html)

I need to forward logs throught a low bandwitch link a lot of syslog datas.

Thanks 😉

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [January 16, 2019, 10:17pm UTC](https://discuss.elastic.co/t/gelf-output-with-compression-option/164435/2 "2019-01-16T22:17:28Z")

</div>

Assuming the logstash gelf output is using [this](https://github.com/graylog-labs/gelf-rb) gelf library, then my reading of the [code](https://github.com/graylog-labs/gelf-rb/blob/eb2d31cdc4b37c316de880122279bcac52a08ba2/lib/gelf/notifier.rb#L233) is that it unconditionally does 'Zlib::Deflate.deflate(hash.to\_json).bytes' before adding the datagram to the queue.

If you are able to run a packet trace it should be pretty obvious whether the packets contains JSON or compressed JSON.

---

<div class="post-metadata">

**Author:** ![piellick](https://avatars.discourse-cdn.com/v4/letter/p/35a633/32.png) [@piellick](https://discuss.elastic.co/u/piellick)\
**Post date:** [January 17, 2019, 8:27am UTC](https://discuss.elastic.co/t/gelf-output-with-compression-option/164435/3 "2019-01-17T08:27:30Z")

</div>

hi @Badger thanks for your help...it should automaticaly compress the JSON if i understand ?

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [January 17, 2019, 1:32pm UTC](https://discuss.elastic.co/t/gelf-output-with-compression-option/164435/4 "2019-01-17T13:32:49Z")

</div>

Yes.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 14, 2019, 1:32pm UTC](https://discuss.elastic.co/t/gelf-output-with-compression-option/164435/5 "2019-02-14T13:32:52Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
