# How to read log.gz?

**URL:** <https://discuss.elastic.co/t/how-to-read-log-gz/87267>\
**Category:** Logstash\
**Created:** [May 26, 2017, 2:48pm UTC](https://discuss.elastic.co/t/how-to-read-log-gz/87267 "2017-05-26T14:48:11Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![BERUSO](https://avatars.discourse-cdn.com/v4/letter/b/ea5d25/32.png) [@BERUSO](https://discuss.elastic.co/u/BERUSO)\
**Post date:** [May 26, 2017, 2:48pm UTC](https://discuss.elastic.co/t/how-to-read-log-gz/87267/1 "2017-05-26T14:48:11Z")

</div>

Hi! any idea of how to read log.gz in logstash-Linux, it's UTF-8 format. I've tried "gzip\_lines", but it doesn't load any data.

This is the message...  
Sending Logstash's logs to /usr1/kibana/logstash-5.4.0/logs which is now configured via log4j2.properties  
[2017-05-26T09:36:25,920][INFO][logstash.outputs.elasticsearch] Elasticsearch pool URLs updated {:changes=\>{:removed=\>[], :added=\>[[http://localhost:9200/](http://localhost:9200/)]}}  
[2017-05-26T09:36:25,925][INFO][logstash.outputs.elasticsearch] Running health check to see if an Elasticsearch connection is working {:healthcheck\_url=\>[http://localhost:9200/](http://localhost:9200/), :path=\>"/"}  
[2017-05-26T09:36:26,032][WARN][logstash.outputs.elasticsearch] Restored connection to ES instance {:url=\>#\<URI::HTTP:0x15285e75 URL:[http://localhost:9200/](http://localhost:9200/)\>}  
[2017-05-26T09:36:26,035][INFO][logstash.outputs.elasticsearch] Using mapping template from {:path=\>"/usr1/kibana/logstash-5.4.0/bin/sunat\_datapower\_template.json"}  
[2017-05-26T09:36:26,089][INFO][logstash.outputs.elasticsearch] Attempting to install template {:manage\_template=\>{"template"=\>"sunat\_elk\_datapower\__", "settings"=\>{"index.refresh\_interval"=\>"5s"}, "mappings"=\>{"default"=\>{"dynamic\_templates"=\>[{"message\_field"=\>{"mapping"=\>{"index"=\>"not\_analyzed", "omit\_norms"=\>true, "type"=\>"string"}, "match\_mapping\_type"=\>"string", "match"=\>"message"}}, {"string\_fields"=\>{"mapping"=\>{"index"=\>"analyzed", "omit\_norms"=\>true, "type"=\>"string", "fields"=\>{"raw"=\>{"index"=\>"not\_analyzed", "ignore\_above"=\>256, "type"=\>"string"}}}, "match\_mapping\_type"=\>"string", "match"=\>"_"}}], "\_all"=\>{"enabled"=\>true}}}}}  
[2017-05-26T09:36:26,099][INFO][logstash.outputs.elasticsearch] Installing elasticsearch template to _template/sunat\_elk\_datapower_\*  
[2017-05-26T09:36:26,163][INFO][logstash.outputs.elasticsearch] New Elasticsearch output {:class=\>"LogStash::Outputs::ElasticSearch", :hosts=\>[#\<URI::HTTP:0x171a86c1 URL:[http://localhost:9200](http://localhost:9200)\>]}  
[2017-05-26T09:36:26,248][INFO][logstash.pipeline] Starting pipeline {"id"=\>"main", "pipeline.workers"=\>2, "pipeline.batch.size"=\>125, "pipeline.batch.delay"=\>5, "pipeline.max\_inflight"=\>250}  
[2017-05-26T09:36:26,499][INFO][logstash.pipeline] Pipeline main started  
[2017-05-26T09:36:26,577][INFO][logstash.agent] Successfully started Logstash API endpoint {:port=\>9600}

Thanks in advance...

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 23, 2017, 2:48pm UTC](https://discuss.elastic.co/t/how-to-read-log-gz/87267/2 "2017-06-23T14:48:28Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
