# How does filebeat (or logstash) converts single line of log to json data?

**URL:** <https://discuss.elastic.co/t/how-does-filebeat-or-logstash-converts-single-line-of-log-to-json-data/86243>\
**Category:** Beats\
**Created:** [May 18, 2017, 11:06am UTC](https://discuss.elastic.co/t/how-does-filebeat-or-logstash-converts-single-line-of-log-to-json-data/86243 "2017-05-18T11:06:27Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Mohan\_Mahajan](https://avatars.discourse-cdn.com/v4/letter/m/13edae/32.png) [@Mohan\_Mahajan](https://discuss.elastic.co/u/Mohan_Mahajan)\
**Post date:** [May 18, 2017, 11:06am UTC](https://discuss.elastic.co/t/how-does-filebeat-or-logstash-converts-single-line-of-log-to-json-data/86243/1 "2017-05-18T11:06:27Z")

</div>

We already have a ELK cluster running. I wanted to understand how the single log (line) gets converted into json data in elasticsearch. Looking for pointers or explanation.  
Thanks!  
Mohan

---

<div class="post-metadata">

**Author:** ![steffens](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/steffens/32/79630_2.png) [@steffens](https://discuss.elastic.co/u/steffens)\
**Post date:** [May 18, 2017, 12:02pm UTC](https://discuss.elastic.co/t/how-does-filebeat-or-logstash-converts-single-line-of-log-to-json-data/86243/2 "2017-05-18T12:02:45Z")

</div>

The exported fields are documented here: [https://www.elastic.co/guide/en/beats/filebeat/current/exported-fields.html](https://www.elastic.co/guide/en/beats/filebeat/current/exported-fields.html)

Filebeat keeps track of a files meta-data like path, inode and also puts these information in the final document. Offset and message field are put by the file readers. The complete line event with file metadata and message is finally serialized to json.

---

<div class="post-metadata">

**Author:** ![Mohan\_Mahajan](https://avatars.discourse-cdn.com/v4/letter/m/13edae/32.png) [@Mohan\_Mahajan](https://discuss.elastic.co/u/Mohan_Mahajan)\
**Post date:** [May 18, 2017, 12:43pm UTC](https://discuss.elastic.co/t/how-does-filebeat-or-logstash-converts-single-line-of-log-to-json-data/86243/3 "2017-05-18T12:43:29Z")

</div>

Thank you @steffens for the information.

I was curious how filebeat selects which category of exported fields to apply, so I checked the documented exported fields against my elasticsearch document and filebeat.yml. And looks like it depends on filebeat.yml?

I also have "timestamp" field added to elasticsearch document. Wondering from where it is coming.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 8, 2017, 11:06am UTC](https://discuss.elastic.co/t/how-does-filebeat-or-logstash-converts-single-line-of-log-to-json-data/86243/4 "2017-06-08T11:06:28Z")

</div>

This topic was automatically closed after 21 days. New replies are no longer allowed.
