# Logstash output - All messages outputing to one message field

**URL:** <https://discuss.elastic.co/t/logstash-output-all-messages-outputing-to-one-message-field/210399>\
**Category:** Logstash\
**Created:** [December 3, 2019, 4:26pm UTC](https://discuss.elastic.co/t/logstash-output-all-messages-outputing-to-one-message-field/210399 "2019-12-03T16:26:59Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![ksarpong](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ksarpong/32/101801_2.png) [@ksarpong](https://discuss.elastic.co/u/ksarpong)\
**Post date:** [December 3, 2019, 4:26pm UTC](https://discuss.elastic.co/t/logstash-output-all-messages-outputing-to-one-message-field/210399/1 "2019-12-03T16:26:59Z")

</div>

I am using a standard out with ruby for out, no codec defined for input and all messages are being send in on message field. The vendor I am working with is saying we need to get a codec that can seperate messages by new lines. I have tried CEF but got a lot of parse errors. Any suggestions?

---

<div class="post-metadata">

**Author:** ![BeMoore](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bemoore/32/58724_2.png) [@BeMoore](https://discuss.elastic.co/u/BeMoore)\
**Post date:** [December 3, 2019, 5:02pm UTC](https://discuss.elastic.co/t/logstash-output-all-messages-outputing-to-one-message-field/210399/2 "2019-12-03T17:02:19Z")

</div>

have a look here  
[https://www.elastic.co/guide/en/logstash/current/codec-plugins.html](https://www.elastic.co/guide/en/logstash/current/codec-plugins.html)

typical logstash config using a codec with look like this ( of course the codecs will be different depending on your requirements).

```
   input {
     file {
       type => "json"
       path => "/logs/mylogs.log"
       codec => "json"
        }
}
output {
          file {
          path => "/logs/out.log"
          }
}

```

there's plenty of material online for the use of codec, but to be honest, most are self explanatory. the only thing you nee to be aware of is the codec is there to "understand" the data and help in filtering and streaming data, so if you have data that dosn't fit the bill for any of the out of the box codecs, then you might have to write your own.

[https://www.elastic.co/guide/en/logstash/current/codec-new-plugin.html](https://www.elastic.co/guide/en/logstash/current/codec-new-plugin.html)

hope that helps

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 31, 2019, 5:11pm UTC](https://discuss.elastic.co/t/logstash-output-all-messages-outputing-to-one-message-field/210399/3 "2019-12-31T17:11:13Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
