# How to customize output format?

**URL:** <https://discuss.elastic.co/t/how-to-customize-output-format/53158>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [June 17, 2016, 12:52pm UTC](https://discuss.elastic.co/t/how-to-customize-output-format/53158 "2016-06-17T12:52:52Z")\
**Posts on this page:** 10\
**Page:** 1

<div class="post-metadata">

**Author:** ![jiming](https://avatars.discourse-cdn.com/v4/letter/j/dc4da7/32.png) [@jiming](https://discuss.elastic.co/u/jiming)\
**Post date:** [June 17, 2016, 12:52pm UTC](https://discuss.elastic.co/t/how-to-customize-output-format/53158/1 "2016-06-17T12:52:52Z")

</div>

Dear guys,

I wanted to customize output format for filebeat, like logback or log4j does. Does filebeat support it?

For example:

"%m" means output origin message

"%ip %m %t" means local ip, message and timestamp in a line

Thanks!

---

<div class="post-metadata">

**Author:** ![ruflin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ruflin/32/3116_2.png) [@ruflin](https://discuss.elastic.co/u/ruflin)\
**Post date:** [June 20, 2016, 7:30am UTC](https://discuss.elastic.co/t/how-to-customize-output-format/53158/2 "2016-06-20T07:30:00Z")

</div>

This is not supported by filebeat. Filebeat takes every single log line and forwards it without processing the content. For processing the content of log files, Logstash should be sued.

---

<div class="post-metadata">

**Author:** ![ruflin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ruflin/32/3116_2.png) [@ruflin](https://discuss.elastic.co/u/ruflin)\
**Post date:** [June 20, 2016, 7:30am UTC](https://discuss.elastic.co/t/how-to-customize-output-format/53158/3 "2016-06-20T07:30:31Z")

</div>

@jiming On a second thought: Were you above referring the the filebeat logging format?

---

<div class="post-metadata">

**Author:** ![jiming](https://avatars.discourse-cdn.com/v4/letter/j/dc4da7/32.png) [@jiming](https://discuss.elastic.co/u/jiming)\
**Post date:** [June 20, 2016, 9:47am UTC](https://discuss.elastic.co/t/how-to-customize-output-format/53158/4 "2016-06-20T09:47:07Z")

</div>

@fuflin thanks for the reply.

I agree with you that filebeat should only do it's own job and let logstash do the rest.

What I expected is NOT filebeat logging format, I expect the output format.

The reason I want customize the output format is that I don't need the meta data added by filebeat. I just need my pure log message from log files.

If you do not think output format is necessory, at least please add a config, like "noBeatMeta" or "messageOnly", so the output is clean one.

Thanks!

Jiming

---

<div class="post-metadata">

**Author:** ![steffens](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/steffens/32/79630_2.png) [@steffens](https://discuss.elastic.co/u/steffens)\
**Post date:** [June 20, 2016, 10:01am UTC](https://discuss.elastic.co/t/how-to-customize-output-format/53158/5 "2016-06-20T10:01:46Z")

</div>

I think generic filtering support introduced in 5.x will help. See [5.0 alpha 3 docs](https://www.elastic.co/guide/en/beats/filebeat/master/configuration-filter.html).

One can use generic filtering to remove unwanted fields from events + drop events.

---

<div class="post-metadata">

**Author:** ![jiming](https://avatars.discourse-cdn.com/v4/letter/j/dc4da7/32.png) [@jiming](https://discuss.elastic.co/u/jiming)\
**Post date:** [June 21, 2016, 3:01am UTC](https://discuss.elastic.co/t/how-to-customize-output-format/53158/6 "2016-06-21T03:01:56Z")

</div>

@steffens Thanks. I read the docs. Yes, I can use this feature to filter out unnecessary fileds. But it still wrap in an json object. I expected a clean log entry.

For example, I have an log message:

"{ip:xxx.xxx.xxx, time:yyyy-mm-dd}"

I don't want it be changed to

{  
message: "{ip:xxx.xxx.xxx, time:yyyy-mm-dd}"  
}

I just want to get my origin message. Using logstash do convert is an option. But to a system with huge amount of logs, this wrap and unwrap make no sense but waste resource.

Thanks!

Jiming

---

<div class="post-metadata">

**Author:** ![steffens](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/steffens/32/79630_2.png) [@steffens](https://discuss.elastic.co/u/steffens)\
**Post date:** [June 21, 2016, 11:32am UTC](https://discuss.elastic.co/t/how-to-customize-output-format/53158/7 "2016-06-21T11:32:29Z")

</div>

Having a full object is on purpose, to make logs more searchable from within kibana. Main purpose of filebeat is to ship logs, not to process them. Elasticsearch 5.0 will get a so called ingest node, supporting even more filtering/processing.

---

<div class="post-metadata">

**Author:** ![jiming](https://avatars.discourse-cdn.com/v4/letter/j/dc4da7/32.png) [@jiming](https://discuss.elastic.co/u/jiming)\
**Post date:** [June 21, 2016, 1:53pm UTC](https://discuss.elastic.co/t/how-to-customize-output-format/53158/8 "2016-06-21T13:53:39Z")

</div>

@steffens

I can understand you define it on purpose. But my log item already contains everything I need to process next. The data which filebeat added is kind of like noisy. I think it is good idea to let users make the choice by themselves.

And BTW the timestamp that filebeat generated is not accurate if I read the document correct.

---

<div class="post-metadata">

**Author:** ![steffens](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/steffens/32/79630_2.png) [@steffens](https://discuss.elastic.co/u/steffens)\
**Post date:** [June 22, 2016, 3:39pm UTC](https://discuss.elastic.co/t/how-to-customize-output-format/53158/9 "2016-06-22T15:39:24Z")

</div>

As I said, filebeat is not processing content. More elaborate processing needs to be done either via logstash or elasticsearch.

The timestamp generated by filebeat is the time filebeat did read the line from your log-file. In case filebeat has to deal with back-pressure from logstash/elasticsearch/... , it will be slowed down. If log-files contain timestamps themselves, one can use grok to parse the timestamp and compare log file timestamp with timestamp generated by filebeat to tell the difference.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 8, 2016, 12:52pm UTC](https://discuss.elastic.co/t/how-to-customize-output-format/53158/10 "2016-07-08T12:52:52Z")

</div>

This topic was automatically closed after 21 days. New replies are no longer allowed.
