# How to extract the schema from a LogStach Event

**URL:** <https://discuss.elastic.co/t/how-to-extract-the-schema-from-a-logstach-event/52834>\
**Category:** Logstash\
**Created:** [June 15, 2016, 8:14am UTC](https://discuss.elastic.co/t/how-to-extract-the-schema-from-a-logstach-event/52834 "2016-06-15T08:14:57Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Nir\_Sharony](https://avatars.discourse-cdn.com/v4/letter/n/cdc98d/32.png) [@Nir\_Sharony](https://discuss.elastic.co/u/Nir_Sharony)\
**Post date:** [June 15, 2016, 8:14am UTC](https://discuss.elastic.co/t/how-to-extract-the-schema-from-a-logstach-event/52834/1 "2016-06-15T08:14:57Z")

</div>

Hello,

I am using LogStash with the [logstash-codec-avro\_schema\_registry](https://github.com/revpoint/logstash-codec-avro_schema_registry) codec.

However the encoding segment is not implemented yet and I need to implement it myself.

Here is my LogStash configuration (POC):

> input {  
> file {  
> path =\> '/tmp/logstash\_input'  
> }  
> }  
> output {  
> kafka {  
> topic\_id =\> 'test'  
> codec =\> avro\_schema\_registry {  
> endpoint =\> '[http://localhost:2181](http://localhost:2181)'  
> }  
> }  
> }

Every line in the input file which will get processed by LogStash should include the full schema and the payload.  
My goal in implementing the encode method is to extract the schema from the LogStash event and then use it to communicate with the schema registry and get a schema\_id from it.  
Once I have the schema\_id, I will replace the schema with the schema\_id and this will get sent to Kafka.

Does anyone know if this can be done and if how?  
I am fairly new to ruby/LogStash/AVRO

Thank you,  
Nir

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [June 15, 2016, 8:19am UTC](https://discuss.elastic.co/t/how-to-extract-the-schema-from-a-logstach-event/52834/2 "2016-06-15T08:19:02Z")

</div>

I think your syntax is wrong, see [https://www.elastic.co/guide/en/logstash/current/plugins-codecs-avro.html](https://www.elastic.co/guide/en/logstash/current/plugins-codecs-avro.html)

---

<div class="post-metadata">

**Author:** ![Nir\_Sharony](https://avatars.discourse-cdn.com/v4/letter/n/cdc98d/32.png) [@Nir\_Sharony](https://discuss.elastic.co/u/Nir_Sharony)\
**Post date:** [June 15, 2016, 8:20am UTC](https://discuss.elastic.co/t/how-to-extract-the-schema-from-a-logstach-event/52834/3 "2016-06-15T08:20:36Z")

</div>

Hi,

The syntax is actually correct and it seems to work.  
The ruby encode function from the correct plugin does indeed get executed.  
I just need to know how to implemented it...

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 4:52am UTC](https://discuss.elastic.co/t/how-to-extract-the-schema-from-a-logstach-event/52834/4 "2017-07-06T04:52:47Z")

</div>


