# Logstash stdout output text as in file

**URL:** <https://discuss.elastic.co/t/logstash-stdout-output-text-as-in-file/348675>\
**Category:** Logstash\
**Created:** [December 5, 2023, 8:22pm UTC](https://discuss.elastic.co/t/logstash-stdout-output-text-as-in-file/348675 "2023-12-05T20:22:07Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![carter.kovrov](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/carter.kovrov/32/122447_2.png) [@carter.kovrov](https://discuss.elastic.co/u/carter.kovrov)\
**Post date:** [December 5, 2023, 8:22pm UTC](https://discuss.elastic.co/t/logstash-stdout-output-text-as-in-file/348675/1 "2023-12-05T20:22:07Z")

</div>

Hi all

Tell me how to display information as in a file without additional fields?

For example, there is a file app.log with the contents

```auto
12-15-2023 app running...
12-15-2023 app login user test

```

necessary information was displayed in the stdout

```auto
12-15-2023 app running...
12-15-2023 app login user test

```

Current logstash.conf

```auto
input {
  file {
    path => "/webapp/logs/app.log"
    start_position => "beginning"
    ignore_older => 0
  }
}

filter {
  mutate {
    remove_field => ["path", "host", "@version", "@timestamp"]
  }
}

output {
  stdout {
    codec => plain
  }
}

```

1. I get all the outputs in one line
2. after removal the field "host" remains in the output %{host}

```auto
12-15-2023 app running... %{host}12-15-2023 app login user test

```

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [December 5, 2023, 8:52pm UTC](https://discuss.elastic.co/t/logstash-stdout-output-text-as-in-file/348675/2 "2023-12-05T20:52:26Z")

</div>

The codec, unless the format option is used, will [call .to\_s](https://github.com/logstash-plugins/logstash-codec-plain/blob/a9134e183b7b46e7e08284e7c80b14a9bf61643e/lib/logstash/codecs/plain.rb#L58) on the event. [That](https://github.com/elastic/logstash/blob/eddd91454f35a996ea80185399897004d43a8771/logstash-core/src/main/java/org/logstash/Event.java#L418) is what adds %{host} and the timestamp. Try `stdout { codec => plain { format => "%{message}" } }`

Also, in filebeat `ignore_older => 0` turns off age based filtering. In a logstash file input it causes the input to ignore any files more than zero seconds old, so it usually ignores everything.

Or you could replace logstash with /bin/cat.

---

<div class="post-metadata">

**Author:** ![carter.kovrov](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/carter.kovrov/32/122447_2.png) [@carter.kovrov](https://discuss.elastic.co/u/carter.kovrov)\
**Post date:** [December 5, 2023, 9:09pm UTC](https://discuss.elastic.co/t/logstash-stdout-output-text-as-in-file/348675/3 "2023-12-05T21:09:28Z")

</div>

@Badger thanks with %{host} it helped

It remains to understand how to add output to a new line

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [December 5, 2023, 9:12pm UTC](https://discuss.elastic.co/t/logstash-stdout-output-text-as-in-file/348675/4 "2023-12-05T21:12:01Z")

</div>

Are you saying there is no newline written after [message]?

---

<div class="post-metadata">

**Author:** ![carter.kovrov](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/carter.kovrov/32/122447_2.png) [@carter.kovrov](https://discuss.elastic.co/u/carter.kovrov)\
**Post date:** [December 5, 2023, 10:43pm UTC](https://discuss.elastic.co/t/logstash-stdout-output-text-as-in-file/348675/6 "2023-12-05T22:43:05Z")

</div>

yes, this is just my last problem

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [December 5, 2023, 10:50pm UTC](https://discuss.elastic.co/t/logstash-stdout-output-text-as-in-file/348675/7 "2023-12-05T22:50:17Z")

</div>

Insert a literal newline in the format option

```
stdout { codec => plain { format => "%{message}
" } }

```

---

<div class="post-metadata">

**Author:** ![carter.kovrov](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/carter.kovrov/32/122447_2.png) [@carter.kovrov](https://discuss.elastic.co/u/carter.kovrov)\
**Post date:** [December 6, 2023, 11:48am UTC](https://discuss.elastic.co/t/logstash-stdout-output-text-as-in-file/348675/8 "2023-12-06T11:48:31Z")

</div>

@Badger thanks

Final config:

```auto
input {
  file {
    path => "/webapp/logs/app.log"
    start_position => "beginning"
    ignore_older => 0
  }
}

filter {
  mutate {
    remove_field => ["path", "host", "@version", "@timestamp"]
  }
}

output {
  stdout {
    codec => plain { format => "%{message}
"}
  }
}

```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 3, 2024, 11:49am UTC](https://discuss.elastic.co/t/logstash-stdout-output-text-as-in-file/348675/9 "2024-01-03T11:49:15Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
