# How do I configure line codec to output plain events?

**URL:** <https://discuss.elastic.co/t/how-do-i-configure-line-codec-to-output-plain-events/278791>\
**Category:** Logstash\
**Created:** [July 15, 2021, 1:38pm UTC](https://discuss.elastic.co/t/how-do-i-configure-line-codec-to-output-plain-events/278791 "2021-07-15T13:38:30Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![albgus](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/albgus/32/88012_2.png) [@albgus](https://discuss.elastic.co/u/albgus)\
**Post date:** [July 15, 2021, 1:38pm UTC](https://discuss.elastic.co/t/how-do-i-configure-line-codec-to-output-plain-events/278791/1 "2021-07-15T13:38:30Z")

</div>

Hello,

I assumed that the plain and line plugins would output the event message unmodified, but this does not appear to be the case, as a bunch of "garbage" data I don't care about is prepended to the event.

```auto
2021-07-15 13:04:42 INFO dev-app: Log message...

becomes

2021-07-15T13:04:42.929Z {hostname=prod-system-filebeat-filebeat-4vhtf, os={kernel=4.18.0-305.3.1.el8.x86_64, codename=Core, name=CentOS Linux, type=linux, family=redhat, version=7 (Core), platform=centos},.[and lots of more mostly useless data...]} 2021-07-15 13:04:42 INFO dev-app: Log message...

```

It would seem like this is configurable by the format option to the line plugin, but I can't find any documentation describing either what the default is, the expected format, or where this option is expected to be added. It doesn't appear like the output plugins actually accepts a format option?

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [July 15, 2021, 4:06pm UTC](https://discuss.elastic.co/t/how-do-i-configure-line-codec-to-output-plain-events/278791/2 "2021-07-15T16:06:04Z")

</div>

The default for both the [plain](https://github.com/logstash-plugins/logstash-codec-plain/blob/b60b84edb41cc094bb7afb0e3bec4f3bc25da051/lib/logstash/codecs/plain.rb#L39) and [line](https://github.com/logstash-plugins/logstash-codec-line/blob/8036e2b0343da1ee16f9fae0a8f6f456bdb4efd1/lib/logstash/codecs/line.rb#L62) codecs is to call event.to\_s if no format is supplied. This will prepend the timestamp and hostname.

If you just want to write the message then use

```
output { someOutput { codec => line { format => "%{message}" } } }
```

---

<div class="post-metadata">

**Author:** ![albgus](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/albgus/32/88012_2.png) [@albgus](https://discuss.elastic.co/u/albgus)\
**Post date:** [July 16, 2021, 7:08am UTC](https://discuss.elastic.co/t/how-do-i-configure-line-codec-to-output-plain-events/278791/3 "2021-07-16T07:08:45Z")

</div>

I didn't realize that the codec option could be a hash itself, but this solved it!

Thanks!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 13, 2021, 7:08am UTC](https://discuss.elastic.co/t/how-do-i-configure-line-codec-to-output-plain-events/278791/4 "2021-08-13T07:08:47Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
