# Input elasticsearch plugin and codec

**URL:** <https://discuss.elastic.co/t/input-elasticsearch-plugin-and-codec/155761>\
**Category:** Logstash\
**Created:** [November 7, 2018, 4:37pm UTC](https://discuss.elastic.co/t/input-elasticsearch-plugin-and-codec/155761 "2018-11-07T16:37:55Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![phr0gz](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/phr0gz/32/9454_2.png) [@phr0gz](https://discuss.elastic.co/u/phr0gz)\
**Post date:** [November 7, 2018, 4:37pm UTC](https://discuss.elastic.co/t/input-elasticsearch-plugin-and-codec/155761/1 "2018-11-07T16:37:55Z")

</div>

Hello,  
I'm trying get the raw value of %{message}, but whatever is the codec argument (in ES plugin) the result is always in json (without the field "message").

Test config:

input {  
elasticsearch {  
hosts =\> "localhost"  
index =\> "logstash-2018.10.09"  
query =\> '{ "query": { "query\_string": { "query": "\*" } } }'  
size =\> 500  
scroll =\> "5m"  
docinfo =\> false  
codec =\> "line"  
}  
}  
output {  
stdout { codec =\> rubydebug }  
}

Is that normal?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 5, 2018, 4:38pm UTC](https://discuss.elastic.co/t/input-elasticsearch-plugin-and-codec/155761/2 "2018-12-05T16:38:02Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
