# How to disable all formatting/processing done by logstash

**URL:** <https://discuss.elastic.co/t/how-to-disable-all-formatting-processing-done-by-logstash/245377>\
**Category:** Logstash\
**Created:** [August 18, 2020, 9:02am UTC](https://discuss.elastic.co/t/how-to-disable-all-formatting-processing-done-by-logstash/245377 "2020-08-18T09:02:00Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![joel.ng](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/joel.ng/32/74069_2.png) [@joel.ng](https://discuss.elastic.co/u/joel.ng)\
**Post date:** [August 18, 2020, 9:02am UTC](https://discuss.elastic.co/t/how-to-disable-all-formatting-processing-done-by-logstash/245377/1 "2020-08-18T09:02:00Z")

</div>

I am using logstash purely to upload them to my S3 bucket. My logs are already formatted nicely and I do not want any further formatting done on it.

Is there any way to disable _all_ the processing done by logstash? It's current prepending this to all my logs, and I don't want them:

```auto
2020-08-18T10:30:24.599Z ip-x-x-x-x

```

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [August 18, 2020, 12:32pm UTC](https://discuss.elastic.co/t/how-to-disable-all-formatting-processing-done-by-logstash/245377/2 "2020-08-18T12:32:56Z")

</div>

What output configuration are you using?

---

<div class="post-metadata">

**Author:** ![joel.ng](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/joel.ng/32/74069_2.png) [@joel.ng](https://discuss.elastic.co/u/joel.ng)\
**Post date:** [August 19, 2020, 1:46am UTC](https://discuss.elastic.co/t/how-to-disable-all-formatting-processing-done-by-logstash/245377/3 "2020-08-19T01:46:23Z")

</div>

My configuration is like this, placed in the conf.d folder. Everything else is untouched:

```auto
input {
  file {
    path => "/home/user/vf_xxxx/current/log/*.log"
  }
}

output {
  s3 {
    region => "ap-southeast-1"
    bucket => "vf-xxxx"
    size_file => 20000
  }
}

```

---

<div class="post-metadata">

**Author:** ![joel.ng](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/joel.ng/32/74069_2.png) [@joel.ng](https://discuss.elastic.co/u/joel.ng)\
**Post date:** [August 24, 2020, 3:41am UTC](https://discuss.elastic.co/t/how-to-disable-all-formatting-processing-done-by-logstash/245377/4 "2020-08-24T03:41:48Z")

</div>

Anything? I find it really strange how Logstash is unable to simply just watch a folder for logs and just upload them directly. Why the forced need to prepend `2020-08-24T03:33:42.908Z ip-x-x-x-x` to all my logs?

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [August 24, 2020, 3:31pm UTC](https://discuss.elastic.co/t/how-to-disable-all-formatting-processing-done-by-logstash/245377/5 "2020-08-24T15:31:31Z")

</div>

An s3 output uses a line codec by default. A line codec [calls .to\_s](https://github.com/logstash-plugins/logstash-codec-line/blob/cf59fd80cafd9fab9d56e0c9e5ef592d96db116b/lib/logstash/codecs/line.rb#L49) on the event if it is not given a format to use. [to\_s](https://github.com/elastic/logstash/blob/e8d1073bdd01a4cf8e08f150cabf7f07645b3d01/logstash-core/src/main/java/org/logstash/Event.java#L348) adds a timestamp and hostname. If you do not want it do do that then set the format option on the codec.

---

<div class="post-metadata">

**Author:** ![joel.ng](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/joel.ng/32/74069_2.png) [@joel.ng](https://discuss.elastic.co/u/joel.ng)\
**Post date:** [August 25, 2020, 5:02am UTC](https://discuss.elastic.co/t/how-to-disable-all-formatting-processing-done-by-logstash/245377/6 "2020-08-25T05:02:52Z")

</div>

Nice, that works. Thank you.

Just need to add this inside the s3 block:

```auto
codec => line { 
  format => "%{message}" 
}

```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 22, 2020, 7:02am UTC](https://discuss.elastic.co/t/how-to-disable-all-formatting-processing-done-by-logstash/245377/7 "2020-09-22T07:02:53Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
