# Logstash how to store partial info from the log

**URL:** <https://discuss.elastic.co/t/logstash-how-to-store-partial-info-from-the-log/41495>\
**Category:** Logstash\
**Created:** [February 11, 2016, 2:54pm UTC](https://discuss.elastic.co/t/logstash-how-to-store-partial-info-from-the-log/41495 "2016-02-11T14:54:14Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Navneet\_Mathpal](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/navneet_mathpal/32/3677_2.png) [@Navneet\_Mathpal](https://discuss.elastic.co/u/Navneet_Mathpal)\
**Post date:** [February 11, 2016, 2:54pm UTC](https://discuss.elastic.co/t/logstash-how-to-store-partial-info-from-the-log/41495/1 "2016-02-11T14:54:14Z")

</div>

Hi,

I came across a use case where I need to store some value from the log in two different places

ex - parsed log is :- {"message" : "log\_message" , "source" : "internet" , "time" : "sometime" , "id" :"123" }

Now I need to store the log into elasticsearch , that I can do very easily using elasticsearch output plugin.But at the same time I want id from the above log to be stored in a file , for that  
I can use file output plugin but I do not want to store the full log , but only the id.

Is there any plugins available for that ? If no how can I achieve this ?

Thanks

---

<div class="post-metadata">

**Author:** ![wiibaa](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/wiibaa/32/44931_2.png) [@wiibaa](https://discuss.elastic.co/u/wiibaa)\
**Post date:** [February 12, 2016, 10:23am UTC](https://discuss.elastic.co/t/logstash-how-to-store-partial-info-from-the-log/41495/2 "2016-02-12T10:23:34Z")

</div>

If I understand you well, you want to configure the codec of your output  
as explained on the plugin documentation [https://www.elastic.co/guide/en/logstash/current/plugins-outputs-file.html](https://www.elastic.co/guide/en/logstash/current/plugins-outputs-file.html)

In your case to write for one event id per line, you would simply do:

```
output {
  file {
    path => ...        
    codec => line { format => "%{id}" }
  }
}
```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 5:11am UTC](https://discuss.elastic.co/t/logstash-how-to-store-partial-info-from-the-log/41495/3 "2017-07-06T05:11:50Z")

</div>


