# Logs not showing up in readable format in Kibana after Logstash ingestion

**URL:** <https://discuss.elastic.co/t/logs-not-showing-up-in-readable-format-in-kibana-after-logstash-ingestion/217484>\
**Category:** Logstash\
**Created:** [February 1, 2020, 6:51am UTC](https://discuss.elastic.co/t/logs-not-showing-up-in-readable-format-in-kibana-after-logstash-ingestion/217484 "2020-02-01T06:51:59Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![ckough](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ckough/32/61892_2.png) [@ckough](https://discuss.elastic.co/u/ckough)\
**Post date:** [February 1, 2020, 6:52am UTC](https://discuss.elastic.co/t/logs-not-showing-up-in-readable-format-in-kibana-after-logstash-ingestion/217484/1 "2020-02-01T06:52:00Z")

</div>

Hi There,

I've a problem with cloudwatch logs showing up in readable format in kibana and I believe the problem is with setting Logstash charset. The error is:

[main] Received an event that has a different character encoding than you configured. {:text=\>"\u0017\u0016\xBE\xAE\xED\"\xBE\xA5\xF0\u0004`B\>\xDC١\xAFu\u000FV\xFC\xA3lz\u000F\xA6\xBF\xD1q\u001Fހ\u007F\u0006|\xF1\xF0\b\xAA\x95\xAF\a\xFB\n", :expected\_charset=\>"UTF-8"}

My setup is:  
CWL -\> Kinesis Firehose -\> S3 -\> Logstash -\> EC2 ES Cluster -\> Kibana

If I replace Logstash with Fluentd, the logs show up fine in Kibana so I know the setup is correct.

Any idea which charset I should be using in Logstash for my scenario?

Thanks in advance!  
CK

---

<div class="post-metadata">

**Author:** ![ckough](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ckough/32/61892_2.png) [@ckough](https://discuss.elastic.co/u/ckough)\
**Post date:** [February 3, 2020, 4:32pm UTC](https://discuss.elastic.co/t/logs-not-showing-up-in-readable-format-in-kibana-after-logstash-ingestion/217484/2 "2020-02-03T16:32:41Z")

</div>

OK i have figure this out. I configure s3 event notification to go to an aws sqs queue. then I install the logstash-input-s3-sns-sqs plugin. I use a Logstash pipe like this:

input  
{  
s3snssqs  
{  
region =\> "ap-southeast-1"  
queue =\> "my-sqs-queue"  
type =\> "sqs\_logs"  
codec =\> json { charset =\> "UTF-8" }  
sqs\_skip\_delete =\> true  
from\_sns =\> false  
s3\_options\_by\_bucket =\> [  
{  
bucket\_name =\> "my-s3-bucket"  
prefix =\> "my-folder-in-s3/"  
}  
]  
}  
}

Hope this helps anyone having the same issue.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 2, 2020, 4:32pm UTC](https://discuss.elastic.co/t/logs-not-showing-up-in-readable-format-in-kibana-after-logstash-ingestion/217484/3 "2020-03-02T16:32:42Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
