# Output only s3 file create events to elastic search and not the contents of the files

**URL:** <https://discuss.elastic.co/t/output-only-s3-file-create-events-to-elastic-search-and-not-the-contents-of-the-files/260697>\
**Category:** Logstash\
**Created:** [January 11, 2021, 10:32am UTC](https://discuss.elastic.co/t/output-only-s3-file-create-events-to-elastic-search-and-not-the-contents-of-the-files/260697 "2021-01-11T10:32:39Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![suhas\_1993](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/suhas_1993/32/82018_2.png) [@suhas\_1993](https://discuss.elastic.co/u/suhas_1993)\
**Post date:** [January 11, 2021, 10:32am UTC](https://discuss.elastic.co/t/output-only-s3-file-create-events-to-elastic-search-and-not-the-contents-of-the-files/260697/1 "2021-01-11T10:32:39Z")

</div>

Hello team,

Is there a config that enables Logstash s3 input plugin to output only s3 filenames under the bucket where Logstash config is polling on?

The current below config is outputting file contents with message fields excluded to elastic search. I have all the info required in log file names (as a status prefix) and the contents of the log files are not needed at this point. Kindly let me know if the same is not possible.

```auto
input {
  s3 {
    "region" => "us-east-2"
    "bucket" => "s3-bucket"
    "prefix" => "<pre-fix>"
    "interval" => "10"
"exclude_pattern" => ".txt\z|.sh\z"
"additional_settings" => {
      "force_path_style" => true
      "follow_redirects" => false
                }
  }
}

filter {
  mutate {
    remove_field => ["message"]
    add_field => {
      "file" => "%{[@metadata][s3][key]}"
    }
  }
}
output {
  elasticsearch {
    hosts => ["vcp_endpoint"]
    index => "logs-%{+YYYY.MM.dd}"
  }
}

```

---

<div class="post-metadata">

**Author:** ![suhas\_1993](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/suhas_1993/32/82018_2.png) [@suhas\_1993](https://discuss.elastic.co/u/suhas_1993)\
**Post date:** [January 11, 2021, 10:48am UTC](https://discuss.elastic.co/t/output-only-s3-file-create-events-to-elastic-search-and-not-the-contents-of-the-files/260697/2 "2021-01-11T10:48:02Z")

</div>

For example,

If **pipline\_1234/logs/done\_1213\_study.log** is the S3 key, and below are the file contents of the file

```auto
[timestamp] started pipeline for subject 1234
[timestamp] download raw data
[timestamp] processing intermediate step
[timestamp] ....... 50 intermittent log lines
[timestamp] completed processing for subject 1234

```

I just need only the log file key to be logged in to elastic search and not the contents to elastic search.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 8, 2021, 10:48am UTC](https://discuss.elastic.co/t/output-only-s3-file-create-events-to-elastic-search-and-not-the-contents-of-the-files/260697/3 "2021-02-08T10:48:07Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
