# \[Logstash\] \[Filebeat\] Using codec Plain and JSON for the same input

**URL:** <https://discuss.elastic.co/t/logstash-filebeat-using-codec-plain-and-json-for-the-same-input/310836>\
**Category:** Logstash\
**Created:** [July 28, 2022, 8:41am UTC](https://discuss.elastic.co/t/logstash-filebeat-using-codec-plain-and-json-for-the-same-input/310836 "2022-07-28T08:41:39Z")\
**Posts on this page:** 10\
**Page:** 1

<div class="post-metadata">

**Author:** ![hdryx](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/hdryx/32/108960_2.png) [@hdryx](https://discuss.elastic.co/u/hdryx)\
**Post date:** [July 28, 2022, 8:41am UTC](https://discuss.elastic.co/t/logstash-filebeat-using-codec-plain-and-json-for-the-same-input/310836/1 "2022-07-28T08:41:39Z")

</div>

Hi,

Actually we have this architecture : Filebeat --\> Kafaka --\> Logstash

The Logstash is using this input config :

**file1.conf**

```auto
input {
  kafka {
    codec => json
    bootstrap_servers => "....."
    topics_pattern => ["prd*"]
    auto_offset_reset => earliest
    decorate_events => true
  }
}
filter {
...
}

```

**file2.conf**

```auto
input {
  kafka {
    codec => plain
    bootstrap_servers => "....."
    topics_pattern => ["prd*"]
    auto_offset_reset => earliest
    decorate_events => true
  }
}
filter {
...
}

```

So for file1 we use JSON codec and for file2 we use PLAIN.

Now we are going to remove the Kafka so will have this : Filebeat --\> Logstash

```auto

input {
  beats {
    port => 5044
    codec => plain
    ssl => true
    ssl_certificate_authorities => ["/etc/ca.crt"]
    ssl_certificate => "/etc/logstash.crt"
    ssl_key => "/etc/logstash.key"
    ssl_verify_mode => "force_peer"
  }
}

```

The problem is when previously we had 2 input : one for JSON and one for PLAIN, i can't see how to that with a single INPUT Beats ?

Thank you

---

<div class="post-metadata">

**Author:** ![hdryx](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/hdryx/32/108960_2.png) [@hdryx](https://discuss.elastic.co/u/hdryx)\
**Post date:** [August 14, 2022, 8:01am UTC](https://discuss.elastic.co/t/logstash-filebeat-using-codec-plain-and-json-for-the-same-input/310836/2 "2022-08-14T08:01:41Z")

</div>

Any idea ?

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [August 14, 2022, 3:12pm UTC](https://discuss.elastic.co/t/logstash-filebeat-using-codec-plain-and-json-for-the-same-input/310836/3 "2022-08-14T15:12:08Z")

</div>

hi @hdryx Welcome to the community, apologies for taking so long to get back to you.

Are the plain and json coming from 2 different sources / filebeat?

If so just use 2 ports / 2 inputs like below and of course set the logstash output in each filebeat to the correct port.

**file2.conf**

```auto
input {
  beats {
    port => 5044
    codec => json

```

**file2.conf**

```auto
input {
  beats {
    port => 5045
    codec => plain

```

---

<div class="post-metadata">

**Author:** ![hdryx](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/hdryx/32/108960_2.png) [@hdryx](https://discuss.elastic.co/u/hdryx)\
**Post date:** [August 14, 2022, 4:00pm UTC](https://discuss.elastic.co/t/logstash-filebeat-using-codec-plain-and-json-for-the-same-input/310836/4 "2022-08-14T16:00:28Z")

</div>

Non they are coming from the same beat, so i have to expose only 1 port

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [August 14, 2022, 4:06pm UTC](https://discuss.elastic.co/t/logstash-filebeat-using-codec-plain-and-json-for-the-same-input/310836/5 "2022-08-14T16:06:11Z")

</div>

With the old configuration did the same events go through both kafka inputs? If not, what determined whether they were treated as json or plain?

---

<div class="post-metadata">

**Author:** ![hdryx](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/hdryx/32/108960_2.png) [@hdryx](https://discuss.elastic.co/u/hdryx)\
**Post date:** [August 14, 2022, 4:19pm UTC](https://discuss.elastic.co/t/logstash-filebeat-using-codec-plain-and-json-for-the-same-input/310836/6 "2022-08-14T16:19:22Z")

</div>

Yes, Logstash gets all logs from Kafka

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [August 14, 2022, 4:23pm UTC](https://discuss.elastic.co/t/logstash-filebeat-using-codec-plain-and-json-for-the-same-input/310836/7 "2022-08-14T16:23:05Z")

</div>

@hdryx Thanks but that is not what @Badger is asking

We are asking what determines the file is plain vs json how did you identify which is which?

Can you share your current filebeat configs for the 2 different types?

---

<div class="post-metadata">

**Author:** ![hdryx](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/hdryx/32/108960_2.png) [@hdryx](https://discuss.elastic.co/u/hdryx)\
**Post date:** [August 14, 2022, 4:39pm UTC](https://discuss.elastic.co/t/logstash-filebeat-using-codec-plain-and-json-for-the-same-input/310836/8 "2022-08-14T16:39:49Z")

</div>

Sorry I don't have access to filebeat config files.

I think that each input configuration defines how should data be considered (see examples of file1 and file2)

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [August 14, 2022, 4:55pm UTC](https://discuss.elastic.co/t/logstash-filebeat-using-codec-plain-and-json-for-the-same-input/310836/9 "2022-08-14T16:55:46Z")

</div>

It is not possible to use two input codecs, you can use only one, so you will need to use the `plain` codec in the beats input and use a `json` filter to parse your json messages.

You will need to be able to determine which log is a plain text message and which log is a json message, which is what was already asked.

This should be done in Filebeat, so you need to share your filebeat configuration.

The kafka inputs that you shared does not help, they are basically the same, pointing to the same topic patterns, it is not possible to know if they point to the same kafka cluster or not.

You will probably need to add a tag or a new field in each filebeat input so you can use this information in Logstash and apply the json filter.

Something like this:

```auto
if "json" in [tags] {
    json {
        source => "message"
    }
}

```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 11, 2022, 4:56pm UTC](https://discuss.elastic.co/t/logstash-filebeat-using-codec-plain-and-json-for-the-same-input/310836/10 "2022-09-11T16:56:44Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
