# LogStash - Add properties in the logback and send them to Logstash

**URL:** <https://discuss.elastic.co/t/logstash-add-properties-in-the-logback-and-send-them-to-logstash/70172>\
**Category:** Logstash\
**Created:** [December 29, 2016, 2:45am UTC](https://discuss.elastic.co/t/logstash-add-properties-in-the-logback-and-send-them-to-logstash/70172 "2016-12-29T02:45:35Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![AleGallagher](https://avatars.discourse-cdn.com/v4/letter/a/439d5e/32.png) [@AleGallagher](https://discuss.elastic.co/u/AleGallagher)\
**Post date:** [December 29, 2016, 2:45am UTC](https://discuss.elastic.co/t/logstash-add-properties-in-the-logback-and-send-them-to-logstash/70172/1 "2016-12-29T02:45:35Z")

</div>

I'm using Logback and Logstash in a SpringBoot application.

In the logback.xml I have a property with the name of the service, and is like:

> configuration\>  
> include resource="org/springframework/boot/logging/logback/defaults.xml" /\>

> include resource="org/springframework/boot/logging/logback/console-appender.xml" /\>

> property name="spring.application.name" value="service" scope="context"/\>

> appender name="stash" class="net.logstash.logback.appender.LogstashTcpSocketAppender"\>  
> destination\>localhost:9600  
> encoder class="net.logstash.logback.encoder.LogstashEncoder"/\>  
> /appender\>

> root level="INFO"\>  
> appender-ref ref="CONSOLE" /\>  
> appender-ref ref="stash" /\>

> /configuration\>

The Logstash conf file is like:

> input{ tcp{  
> port=\> 9600  
> host=\>logstash  
> }  
> }

> filter {  
> grok {  
> match =\> {  
> "message" =\>  
> "^%{TIMESTAMP\_ISO8601:timestamp}\s+%{LOGLEVEL:level}\s+%{NUMBER:pid}\s+---\s+[\s\*%{USERNAME:thread}\s\*]\s+%{JAVAFILE:class}\s\*:\s\*%{DATA:themessage}(?:\n+(?(?:.|\r|\n)+))?$"  
> }  
> }  
> date {  
> match =\> ["timestamp" , "yyyy-MM-dd HH:mm:ss.SSS"]  
> }  
> mutate {  
> remove\_field =\> ["@version"]

> }  
> }  
> output{

> elasticsearch {  
> hosts =\> ["elasticsearch"]  
> index =\> "indice"  
> }  
> stdout{}  
> }

The log is the following:

> 28T00:34:53.198+00:00","@version":1, **"message"** :"Entrada de datos incompletos","logger\_name":"com.empresa.miAlquiler.controllers.UserController","thread\_name":"http-nio-7777-exec-2","level":"INFO","level\_value":20000,"HOSTNAME":"8fe48aff9ca8", **"spring.application.name"** :"visit-service","X-Span-Export":"false","X-B3-SpanId":"1cccc5c7252100c4","X-B3-TraceId":"1cccc5c7252100c4"} tags:\_grokparsefailure

But, the problem is that The property appears in the log, but whitin "message" field. I want to have the property as field (out of **message** ), to filter the logs with Kibana

Is there anyway to do that?

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [December 31, 2016, 1:18pm UTC](https://discuss.elastic.co/t/logstash-add-properties-in-the-logback-and-send-them-to-logstash/70172/2 "2016-12-31T13:18:36Z")

</div>

I've responded to this question in your other thread. Please don't post the same question multiple times.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 28, 2017, 1:19pm UTC](https://discuss.elastic.co/t/logstash-add-properties-in-the-logback-and-send-them-to-logstash/70172/3 "2017-01-28T13:19:01Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
