# Log formatting under lumberjack lost in filebeats

**URL:** <https://discuss.elastic.co/t/log-formatting-under-lumberjack-lost-in-filebeats/41296>\
**Category:** Beats\
**Created:** [February 9, 2016, 4:38pm UTC](https://discuss.elastic.co/t/log-formatting-under-lumberjack-lost-in-filebeats/41296 "2016-02-09T16:38:27Z")\
**Posts on this page:** 1\
**Showing post:** 2

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [February 9, 2016, 5:49pm UTC](https://discuss.elastic.co/t/log-formatting-under-lumberjack-lost-in-filebeats/41296/2 "2016-02-09T17:49:25Z")

</div>

> [@bluethundr](#):
>
> filebeats are now using yaml and not json

Filebeat uses YAML only for its configuration file. The data it sends to Logstash is JSON. The line it reads from your files is put into the `message` field of the event sent to Logstash.

Since your lines are JSON, you need to apply the JSON codec to the input. See [Parse / ship JSON file with filebeat](https://discuss.elastic.co/t/parse-ship-json-file-with-filebeat/34540)

---

_[View the full topic](https://discuss.elastic.co/t/log-formatting-under-lumberjack-lost-in-filebeats/41296)._
