# Logstash - wrong codec in tcp input plugin?

**URL:** <https://discuss.elastic.co/t/logstash-wrong-codec-in-tcp-input-plugin/83364>\
**Category:** Logstash\
**Created:** [April 24, 2017, 7:01am UTC](https://discuss.elastic.co/t/logstash-wrong-codec-in-tcp-input-plugin/83364 "2017-04-24T07:01:41Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![leaner](https://avatars.discourse-cdn.com/v4/letter/l/96bed5/32.png) [@leaner](https://discuss.elastic.co/u/leaner)\
**Post date:** [April 24, 2017, 7:01am UTC](https://discuss.elastic.co/t/logstash-wrong-codec-in-tcp-input-plugin/83364/1 "2017-04-24T07:01:41Z")

</div>

I'm using the newest version of Logstash 5.3.1.  
While I am using a tcp input plugins, it shows that the real codec being used is not the same one with my config file.  
To confirm this question, I add a log output in the source code of tcp input plugins - tcp.rb:

 ![](https://us1.discourse-cdn.com/elastic/original/3X/6/7/67b5433420aa48721e8be695cb859bff49925e2d.png)

While my codec config is json, it actually uses json\_lines:

 ![](https://us1.discourse-cdn.com/elastic/original/3X/b/2/b20ec6965d8eec6b5f9aaefee9f2734f29abb7f3.png)

While my codec config is plain, it actually uses line:

 ![](https://us1.discourse-cdn.com/elastic/original/3X/b/8/b814270ea378d428eaa35c326434d9b6fe7fbcf5.png)

sorry for my poor english, hope you can understand my questions!

---

<div class="post-metadata">

**Author:** ![pierhugues](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/pierhugues/32/48383_2.png) [@pierhugues](https://discuss.elastic.co/u/pierhugues)\
**Post date:** [April 28, 2017, 3:06pm UTC](https://discuss.elastic.co/t/logstash-wrong-codec-in-tcp-input-plugin/83364/2 "2017-04-28T15:06:38Z")

</div>

This because the `#fix_streaming_codecs` changes it for `JSONLines` and `Lines`, see [https://github.com/elastic/logstash/blob/0d1011980efc2fdae9b8e8a261b8d04f6ff537de/logstash-core/lib/logstash/inputs/base.rb#L122-L135](https://github.com/elastic/logstash/blob/0d1011980efc2fdae9b8e8a261b8d04f6ff537de/logstash-core/lib/logstash/inputs/base.rb#L122-L135)

Because in this input we assume that an event is separated by a new line, if you were using the `plain` or the `json` codec, the plugin would never know when or where to split the events and will just keep buffering data. For the user experience we make the assumptions that your events will be split by `\n`, but you can change that behavior in both codec by configuring the `delimiter` option, see the [jsonlines documentation](https://www.elastic.co/guide/en/logstash/current/plugins-codecs-json_lines.html)

---

<div class="post-metadata">

**Author:** ![leaner](https://avatars.discourse-cdn.com/v4/letter/l/96bed5/32.png) [@leaner](https://discuss.elastic.co/u/leaner)\
**Post date:** [May 3, 2017, 3:46pm UTC](https://discuss.elastic.co/t/logstash-wrong-codec-in-tcp-input-plugin/83364/3 "2017-05-03T15:46:24Z")

</div>

Thanks a lot! u solved my confusion

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 31, 2017, 4:00pm UTC](https://discuss.elastic.co/t/logstash-wrong-codec-in-tcp-input-plugin/83364/5 "2017-05-31T16:00:04Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
