# Help with logstash config using datadog output plugin

**URL:** <https://discuss.elastic.co/t/help-with-logstash-config-using-datadog-output-plugin/127141>\
**Category:** Logstash\
**Created:** [April 6, 2018, 9:00pm UTC](https://discuss.elastic.co/t/help-with-logstash-config-using-datadog-output-plugin/127141 "2018-04-06T21:00:13Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![caljess599](https://avatars.discourse-cdn.com/v4/letter/c/f0a364/32.png) [@caljess599](https://discuss.elastic.co/u/caljess599)\
**Post date:** [April 6, 2018, 9:00pm UTC](https://discuss.elastic.co/t/help-with-logstash-config-using-datadog-output-plugin/127141/1 "2018-04-06T21:00:13Z")

</div>

I'm using [the old datadog output plugin for logstash](https://www.elastic.co/guide/en/logstash/5.1/plugins-outputs-datadog.html), which I'm running inside a container.

For the life of me, I cannot get my [JSON input](https://www.aptible.com/documentation/enclave/reference/logging/log-drains/https.html) (coming in via the [http input filter](https://www.elastic.co/guide/en/logstash/5.1/plugins-inputs-http.html)) to show up in DataDog.

Basically, I don't know how to either leverage the output plugin's options and/or logstash's filters to pass on the JSON.

Out of the box, what I get passed through is the "message" field, but because my input has no message field, it's useless.

Here's my current NON-WORKING config.

Help MOST appreciated!

```
input {
  http {
    port => 80
    codec => json
  }
}

filter {
  if [headers][request_method] != "POST" {
    # Drop all non-POST requests. Healthchecks happen over HTTP GET,
    # and we don't want those getting into Logstash.
    drop { }
  }
}

output {
  datadog { 
    api_key => "goes here" 
    codec => "json" 
  }
}
```

---

<div class="post-metadata">

**Author:** ![yaauie](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yaauie/32/23363_2.png) [@yaauie](https://discuss.elastic.co/u/yaauie)\
**Post date:** [April 7, 2018, 1:08am UTC](https://discuss.elastic.co/t/help-with-logstash-config-using-datadog-output-plugin/127141/2 "2018-04-07T01:08:01Z")

</div>

Typically when writing a new config, I also include a stdout output plugin until I am happy with the shape of the data.

Do you have any indication from datadog that it is (a) receiving messages and if so, (b) what the shape of those messages is? I am not familiar with what shape of data is expected by datadog, but these are the types of questions that generally lead to discovery.

---

<div class="post-metadata">

**Author:** ![caljess599](https://avatars.discourse-cdn.com/v4/letter/c/f0a364/32.png) [@caljess599](https://discuss.elastic.co/u/caljess599)\
**Post date:** [April 9, 2018, 6:12pm UTC](https://discuss.elastic.co/t/help-with-logstash-config-using-datadog-output-plugin/127141/3 "2018-04-09T18:12:50Z")

</div>

I actually had a bit of success after I posted this, but I could sure use some advice on filters...

Because of the environment there is some concern that I should not work with the stdout plugin... I'm asking for clarification on that, since it is indeed a best practice.

Basically I can get any of my fields sent across to datadog if I stuff the info into one of their fields. So for example, it was simple enough to get the "log" field from the JSON over just by adding it to DD's text field, i.e.:

`text => "%{log}"`

That's the breakthrough. So it's simple, really. But now I want to do more complex stuff like define the value of the alert\_type field based on matched text in the log line... I am certain logstash can do this (and much more) but I'm not having an easy time discovering documentation to match my needs.

Thanks.

---

<div class="post-metadata">

**Author:** ![yaauie](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yaauie/32/23363_2.png) [@yaauie](https://discuss.elastic.co/u/yaauie)\
**Post date:** [April 9, 2018, 8:15pm UTC](https://discuss.elastic.co/t/help-with-logstash-config-using-datadog-output-plugin/127141/4 "2018-04-09T20:15:36Z")

</div>

to clarify, I use stdout _only_ while developing as a way of seeing the "shape" of data that is exiting my pipeline, not in a production mode.

For example conditionals, see also the [Logstash Config Examples docs](https://www.elastic.co/guide/en/logstash/current/config-examples.html#using-conditionals).

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 7, 2018, 8:15pm UTC](https://discuss.elastic.co/t/help-with-logstash-config-using-datadog-output-plugin/127141/5 "2018-05-07T20:15:45Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
