# Input beats - output syslog, what in the middle

**URL:** <https://discuss.elastic.co/t/input-beats-output-syslog-what-in-the-middle/310310>\
**Category:** Logstash\
**Created:** [July 21, 2022, 2:40pm UTC](https://discuss.elastic.co/t/input-beats-output-syslog-what-in-the-middle/310310 "2022-07-21T14:40:43Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![Kakos](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kakos/32/99734_2.png) [@Kakos](https://discuss.elastic.co/u/Kakos)\
**Post date:** [July 21, 2022, 2:40pm UTC](https://discuss.elastic.co/t/input-beats-output-syslog-what-in-the-middle/310310/1 "2022-07-21T14:40:43Z")

</div>

Hi,

The messages i get from beats are completely unstructured. The most important of all they include characters like \t and \n and actually don't recognize the new lines and tabs which exist in the raw data. So they look very messy.

Is there any efficient way to break the message in lines by replacing those characters and get back the data in their readable format? One by one the lines of the raw data.

Thanks in advance

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 18, 2022, 2:40pm UTC](https://discuss.elastic.co/t/input-beats-output-syslog-what-in-the-middle/310310/2 "2022-08-18T14:40:46Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
