# How to queue ECS formatted logs through RabbitMQ

**URL:** https://discuss.elastic.co/t/how-to-queue-ecs-formatted-logs-through-rabbitmq/335105
**Category:** Logstash
**Tags:** ecs-elastic-common-schema
**Created:** [June 2, 2023, 3:57pm UTC](https://discuss.elastic.co/t/how-to-queue-ecs-formatted-logs-through-rabbitmq/335105 "2023-06-02T15:57:22Z")
**Posts on this page:** 5
**Page:** 1

<div class="post-metadata">

### Author: ![bvoros](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bvoros/32/5246_2.png) [@bvoros](https://discuss.elastic.co/u/bvoros)
#### Post date: [June 2, 2023, 3:57pm UTC](https://discuss.elastic.co/t/how-to-queue-ecs-formatted-logs-through-rabbitmq/335105/1 "2023-06-02T15:57:22Z")

</div>

Hello all,

Our logging infrastructure is the following:

log shippers -\> logstash -\> rabbitmq -\> logstash -\> elasticsearch

I am trying to start using ECS, have the template set up. However, when the first logstash places the log document in the RabbitMQ queue, the original ecs log message gets embedded inside another json document.

Example: (incomplete)  
{"@timestamp":"2023-06-02T14:56:14.094Z","message":"{"@timestamp":"2023-06-02T17:56:12.8391096+03:00","log.level":"Information","message":"Simple test log","ecs.version":"8.4.0"

Is it possible to configure logstash to simply pass through the document as received?

Thanks in advance,  
BV

---

<div class="post-metadata">

### Author: ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)
#### Post date: [June 4, 2023, 5:38am UTC](https://discuss.elastic.co/t/how-to-queue-ecs-formatted-logs-through-rabbitmq/335105/2 "2023-06-04T05:38:26Z")

</div>

> [@bvoros](#):
>
> Is it possible to configure logstash to simply pass through the document as received?

You may try to change the [codec](https://www.elastic.co/guide/en/logstash/current/plugins-outputs-rabbitmq.html#plugins-outputs-rabbitmq-codec) in your output.

I do not use rabbitmq, but I have the following codec configuration on some Kafka outputs to send the original message that Logstash received.

```auto
codec => plain { format => "%{message}" }

```

---

<div class="post-metadata">

### Author: ![bvoros](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bvoros/32/5246_2.png) [@bvoros](https://discuss.elastic.co/u/bvoros)
#### Post date: [June 7, 2023, 8:24am UTC](https://discuss.elastic.co/t/how-to-queue-ecs-formatted-logs-through-rabbitmq/335105/3 "2023-06-07T08:24:20Z")

</div>

Thank you, this is a good tip, will try and report back here.

---

<div class="post-metadata">

### Author: ![bvoros](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bvoros/32/5246_2.png) [@bvoros](https://discuss.elastic.co/u/bvoros)
#### Post date: [June 7, 2023, 1:48pm UTC](https://discuss.elastic.co/t/how-to-queue-ecs-formatted-logs-through-rabbitmq/335105/4 "2023-06-07T13:48:16Z")

</div>

Thanks again for the tip, the following appears to be working when added to the rabbitmq output plugin.

```auto
codec => plain {
        format => "%{message}"
        ecs_compatibility => v8
      }

```

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [July 5, 2023, 1:48pm UTC](https://discuss.elastic.co/t/how-to-queue-ecs-formatted-logs-through-rabbitmq/335105/5 "2023-07-05T13:48:40Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
