# Logstash data unload

**URL:** <https://discuss.elastic.co/t/logstash-data-unload/281506>\
**Category:** Logstash\
**Created:** [August 16, 2021, 6:39am UTC](https://discuss.elastic.co/t/logstash-data-unload/281506 "2021-08-16T06:39:34Z")\
**Posts on this page:** 1\
**Showing post:** 2

<div class="post-metadata">

**Author:** ![online](https://avatars.discourse-cdn.com/v4/letter/o/bb73d2/32.png) [@online](https://discuss.elastic.co/u/online)\
**Post date:** [August 16, 2021, 8:00am UTC](https://discuss.elastic.co/t/logstash-data-unload/281506/2 "2021-08-16T08:00:49Z")

</div>

Please note, the above config file is for Logstash.

I found a similar issue under the below thread.

> [@Elasticsearch output: LogStash::Error: timestamp field is missing](https://discuss.elastic.co/t/elasticsearch-output-logstash-timestamp-field-is-missing/197888):
>
> Hello, I have an elasticsearch output working without any problem elasticsearch { hosts =\> ["${LOGS\_ELASTICSEARCH\_CLUSTER}:443"] ssl =\> true index =\> "cwl-%{+YYYY.MM.dd}" document\_type =\> "log" } I wanted to redirect some type of logs to a new elasticsearch index but I'm getting this error [2019-09-03T14:39:00,242][FATAL][logstash.runner] An unexpected error occurred! {:error=\>#\<LogStash::Error: timestamp field is missing\>, :backtrace=\>["org/logstash/ext/JrubyEventExtLibrary.java:…

I have to now figure out how to create a [@metadata] field and sprintf to at least access the index name. Any pointers would be highly appreciated.

I think I am having the below issue in logstash compared to Postman where it outputs the additional metadata. How would include them in logstash?

> **[@metadata is missing in Logstash | Filebeat Reference \[8.11\] | Elastic](https://www.elastic.co/guide/en/beats/filebeat/current/metadata-missing.html)**

---

_[View the full topic](https://discuss.elastic.co/t/logstash-data-unload/281506)._
