# Journalbeat message format

**URL:** <https://discuss.elastic.co/t/journalbeat-message-format/247289>\
**Category:** Beats\
**Tags:** journalbeat\
**Created:** [September 2, 2020, 9:20pm UTC](https://discuss.elastic.co/t/journalbeat-message-format/247289 "2020-09-02T21:20:47Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![cartesian-theatrics](https://avatars.discourse-cdn.com/v4/letter/c/848f3c/32.png) [@cartesian-theatrics](https://discuss.elastic.co/u/cartesian-theatrics)\
**Post date:** [September 2, 2020, 9:20pm UTC](https://discuss.elastic.co/t/journalbeat-message-format/247289/1 "2020-09-02T21:20:47Z")

</div>

Hello, I'm looking for documentation on the journalbeat message format? I need to understand what I can about the format in order to understand the tradeoffs related to batching.

Thanks,  
John

---

<div class="post-metadata">

**Author:** ![aaron-nimocks](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/aaron-nimocks/32/73965_2.png) [@aaron-nimocks](https://discuss.elastic.co/u/aaron-nimocks)\
**Post date:** [September 3, 2020, 1:34am UTC](https://discuss.elastic.co/t/journalbeat-message-format/247289/2 "2020-09-03T01:34:52Z")

</div>

Welcome to the community @cartesian-theatrics

Here are the [exported fields of journalbeat](https://www.elastic.co/guide/en/beats/journalbeat/current/exported-fields.html). Is this what you were looking for?

---

<div class="post-metadata">

**Author:** ![cartesian-theatrics](https://avatars.discourse-cdn.com/v4/letter/c/848f3c/32.png) [@cartesian-theatrics](https://discuss.elastic.co/u/cartesian-theatrics)\
**Post date:** [September 3, 2020, 6:22am UTC](https://discuss.elastic.co/t/journalbeat-message-format/247289/3 "2020-09-03T06:22:06Z")

</div>

Not exactly, I was more hoping to better understand how messages are compressed and serialized before being shipped, in order to better understand the cost of adding additional fields, as well to better understand the tradeoff between larger and smaller batch intervals.

---

<div class="post-metadata">

**Author:** ![aaron-nimocks](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/aaron-nimocks/32/73965_2.png) [@aaron-nimocks](https://discuss.elastic.co/u/aaron-nimocks)\
**Post date:** [September 3, 2020, 1:15pm UTC](https://discuss.elastic.co/t/journalbeat-message-format/247289/4 "2020-09-03T13:15:43Z")

</div>

To my understanding it just uses [gzip](https://www.elastic.co/guide/en/beats/filebeat/current/elasticsearch-output.html#_compression_level) to compress the messages. You could take a sample of your data and compress it with gzip using the compression ranges of 1-9 to see the results.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 1, 2020, 3:15pm UTC](https://discuss.elastic.co/t/journalbeat-message-format/247289/5 "2020-10-01T15:15:43Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
