# Netflow codec output to the root of the message

**URL:** <https://discuss.elastic.co/t/netflow-codec-output-to-the-root-of-the-message/61954>\
**Category:** Logstash\
**Created:** [September 30, 2016, 8:06pm UTC](https://discuss.elastic.co/t/netflow-codec-output-to-the-root-of-the-message/61954 "2016-09-30T20:06:13Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![GambitK](https://avatars.discourse-cdn.com/v4/letter/g/47e85d/32.png) [@GambitK](https://discuss.elastic.co/u/GambitK)\
**Post date:** [September 30, 2016, 8:06pm UTC](https://discuss.elastic.co/t/netflow-codec-output-to-the-root-of-the-message/61954/1 "2016-09-30T20:06:13Z")

</div>

I'm testing the netflow codec to receive some netflow data, but I don't want the output to be inside of a nested field, I would prefer it to be on the root of the message.

I've tried setting the field config of the codec to "message" or "@message" but that doesn't work. Is there any way to have the codec write the fields directly to the root of the message instead of a nested field?

---

<div class="post-metadata">

**Author:** ![GambitK](https://avatars.discourse-cdn.com/v4/letter/g/47e85d/32.png) [@GambitK](https://discuss.elastic.co/u/GambitK)\
**Post date:** [October 4, 2016, 11:11pm UTC](https://discuss.elastic.co/t/netflow-codec-output-to-the-root-of-the-message/61954/2 "2016-10-04T23:11:31Z")

</div>

Anyone?

---

<div class="post-metadata">

**Author:** ![GambitK](https://avatars.discourse-cdn.com/v4/letter/g/47e85d/32.png) [@GambitK](https://discuss.elastic.co/u/GambitK)\
**Post date:** [October 10, 2016, 4:26pm UTC](https://discuss.elastic.co/t/netflow-codec-output-to-the-root-of-the-message/61954/3 "2016-10-10T16:26:21Z")

</div>

Just in case anyone is interested, I was able to get the desired result using json\_enconde and the json filters. Seems like a waste of resources but I don't know enough ruby to be able to modify the filter myself.

```
input {
  udp {
  port => 9996
  codec => netflow {
    target => netflow_field
    }
  }
}

filter {
  json_encode {
    source => netflow_field
  }
  json {
    source => netflow_field
    remove_field => ["netflow_field"]
  }
}

output {
  stdout {
    codec => rubydebug
  }
}
```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 4:34am UTC](https://discuss.elastic.co/t/netflow-codec-output-to-the-root-of-the-message/61954/4 "2017-07-06T04:34:53Z")

</div>


