# Output events from logstash as plain format

**URL:** <https://discuss.elastic.co/t/output-events-from-logstash-as-plain-format/22696>\
**Category:** Elasticsearch\
**Created:** [March 16, 2015, 7:26pm UTC](https://discuss.elastic.co/t/output-events-from-logstash-as-plain-format/22696 "2015-03-16T19:26:42Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Taylor\_Wood](https://avatars.discourse-cdn.com/v4/letter/t/dec6dc/32.png) [@Taylor\_Wood](https://discuss.elastic.co/u/Taylor_Wood)\
**Post date:** [March 16, 2015, 7:26pm UTC](https://discuss.elastic.co/t/output-events-from-logstash-as-plain-format/22696/1 "2015-03-16T19:26:42Z")

</div>

We are using logstash-forwarder to forward syslog information to a remote  
server running logstash. We would like for logstash to output the events  
from the remote servers into in plain format. The problem we have is that  
logstash outputs an event to the file like this:

{"message":"Mar 11 10:51:52 stage tayler: test", "@version":"1",  
"@timestamp":"2015-03-11T16:51:55.612Z", "file":"/var/log/messages",  
"host":"SERVERHOST", "offset":"6398", "type":"messages”}

What we want each event to look like is this:

Mar 11 10:51:52 stage user: test

Is it possible to either tell logstash to output events as plain format  
into a file or to tell the remote logstash-forwarder instances to output  
events as plain format to a remote server’s file?

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/b75c25c5-abba-4ae6-a371-61724c7372bb%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/b75c25c5-abba-4ae6-a371-61724c7372bb%40googlegroups.com).  
For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [March 16, 2015, 7:37pm UTC](https://discuss.elastic.co/t/output-events-from-logstash-as-plain-format/22696/2 "2015-03-16T19:37:53Z")

</div>

You'll get a much better response on the Logstash list 🙂  
See [Redirecting to Google Groups](https://groups.google.com/forum/?hl=en-GB#!forum/logstash-users)

On 16 March 2015 at 12:26, Taylor Wood [woodrow9003@gmail.com](mailto:woodrow9003@gmail.com) wrote:

> We are using logstash-forwarder to forward syslog information to a remote  
> server running logstash. We would like for logstash to output the events  
> from the remote servers into in plain format. The problem we have is that  
> logstash outputs an event to the file like this:
> 
> {"message":"Mar 11 10:51:52 stage tayler: test", "@version":"1",  
> "@timestamp":"2015-03-11T16:51:55.612Z", "file":"/var/log/messages",  
> "host":"SERVERHOST", "offset":"6398", "type":"messages”}
> 
> What we want each event to look like is this:
> 
> Mar 11 10:51:52 stage user: test
> 
> Is it possible to either tell logstash to output events as plain format  
> into a file or to tell the remote logstash-forwarder instances to output  
> events as plain format to a remote server’s file?
> 
> --  
> You received this message because you are subscribed to the Google Groups  
> "elasticsearch" group.  
> To unsubscribe from this group and stop receiving emails from it, send an  
> email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
> To view this discussion on the web visit  
> [https://groups.google.com/d/msgid/elasticsearch/b75c25c5-abba-4ae6-a371-61724c7372bb%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/b75c25c5-abba-4ae6-a371-61724c7372bb%40googlegroups.com)  
> [https://groups.google.com/d/msgid/elasticsearch/b75c25c5-abba-4ae6-a371-61724c7372bb%40googlegroups.com?utm\_medium=email&utm\_source=footer](https://groups.google.com/d/msgid/elasticsearch/b75c25c5-abba-4ae6-a371-61724c7372bb%40googlegroups.com?utm_medium=email&utm_source=footer)  
> .  
> For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/CAEYi1X8dxY5%2BOJGMg1VjWFa2CYy8Qug8NHErgmqrp-QTNYGK7Q%40mail.gmail.com](https://groups.google.com/d/msgid/elasticsearch/CAEYi1X8dxY5%2BOJGMg1VjWFa2CYy8Qug8NHErgmqrp-QTNYGK7Q%40mail.gmail.com).  
For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 12:26am UTC](https://discuss.elastic.co/t/output-events-from-logstash-as-plain-format/22696/3 "2017-07-06T00:26:25Z")

</div>


