# Management of illegal characters

**URL:** <https://discuss.elastic.co/t/management-of-illegal-characters/377159>\
**Category:** Logstash\
**Created:** [April 15, 2025, 4:36pm UTC](https://discuss.elastic.co/t/management-of-illegal-characters/377159 "2025-04-15T16:36:53Z")\
**Posts on this page:** 1\
**Showing post:** 5

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [April 15, 2025, 7:46pm UTC](https://discuss.elastic.co/t/management-of-illegal-characters/377159/5 "2025-04-15T19:46:15Z")

</div>

> [@Francesco\_Esposito](#):
>
> `codec => line { format => "%{myxml}" }`

Every output allows you to specify the codec option because it is [implemented](https://github.com/elastic/logstash/blob/49cf7acad0274f605d0a11b9e9ddcbfb4c764100/logstash-core/lib/logstash/outputs/base.rb#L35) by the base codec class that they extend. But that doesn't mean they use the codec to send the event to the destination.

The elasticsearch output ignores the codec option and [formats](https://github.com/logstash-plugins/logstash-output-elasticsearch/blob/dac08b2ea9623965166a15c98ba9fed8d4ea55d2/lib/logstash/outputs/elasticsearch/http_client.rb#L132) the event as a JSON string, because that's what the \_bulk API requires.

If you use store\_xml you have to specify a target, if you want to move the fields back up to the top-level of the event then see [this](https://discuss.elastic.co/t/how-to-dynamically-move-nested-key-value-to-root-level/180006/2) thread.

---

_[View the full topic](https://discuss.elastic.co/t/management-of-illegal-characters/377159)._
