# \[LOGSTASH\] - Plugin input-udp and message charset

**URL:** https://discuss.elastic.co/t/logstash-plugin-input-udp-and-message-charset/313617
**Category:** Logstash
**Created:** [September 4, 2022, 10:23am UTC](https://discuss.elastic.co/t/logstash-plugin-input-udp-and-message-charset/313617 "2022-09-04T10:23:21Z")
**Posts on this page:** 3
**Page:** 1

<div class="post-metadata">

### Author: ![manunc](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/manunc/32/48340_2.png) [@manunc](https://discuss.elastic.co/u/manunc)
#### Post date: [September 4, 2022, 10:23am UTC](https://discuss.elastic.co/t/logstash-plugin-input-udp-and-message-charset/313617/1 "2022-09-04T10:23:21Z")

</div>

Hello,

I have a an issue with the message charset received from the input-udp plugin.  
A raw trace taken using tcpdmp command on linux show the message of the UDP packat like this:  
Data: 8689630446410580020000001f46e00000000000000000

BUT on Logstash/Elasticsearch/Kibana discover menu, the message is the following:  
\x86\x89c\u0004FA\u0005\x80\u0002\u0000\u0000\u0000-F\xA0\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000

I see no error message on the logstash-plain.log file.

## Configuration tried:

input {

udp{  
port =\> 7979  
tags =\> ["nbiot","udp"]  
#codec =\> json  
codec =\> plain { charset =\> "UTF-8" }  
#codec =\> plain { charset =\> "ISO-8859-1" }  
#codec =\> plain { charset =\> "locale" }  
#codec =\> line { charset =\> "ISO-8859-1" }  
}

}

Question: I don't see the charset value 'raw', how to display the raw data as seen in the wireshark/tcpdump trace ? This is Logstash that interpret the message differently.

---

<div class="post-metadata">

### Author: ![manunc](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/manunc/32/48340_2.png) [@manunc](https://discuss.elastic.co/u/manunc)
#### Post date: [September 4, 2022, 10:47am UTC](https://discuss.elastic.co/t/logstash-plugin-input-udp-and-message-charset/313617/2 "2022-09-04T10:47:18Z")

</div>

FYI, same issue as the following post unsolved:

> [@Input on UDP converting to default UTF-8 but want Hex Strings](https://discuss.elastic.co/t/input-on-udp-converting-to-default-utf-8-but-want-hex-strings/271513):
>
> Why is logstash converting input stream by default to UTF-8, ASCII, Unsigned Char, I want the data either converted full or do not touch it.. There is no codec to format the received data on UDP port. Example: This is the Stream Buffer : 0000 00 00 03 04 00 06 00 00 00 00 00 00 08 00 08 00 0010 45 00 01 44 5a 0b 40 00 40 11 0d 3f c0 a8 28 87 0020 c0 a8 28 87 b5 1c 1f 72 01 30 d3 a0 36 e8 df a6 0030 00 00 00 00 00 76 00 9e 00 09 01 04 41 4d 46 31 0040 3a 6d 65 74 68 6f 64 00 50 4f 53 54 …

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [October 2, 2022, 10:47am UTC](https://discuss.elastic.co/t/logstash-plugin-input-udp-and-message-charset/313617/3 "2022-10-02T10:47:41Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
