# Output to json saving only specific fields

**URL:** <https://discuss.elastic.co/t/output-to-json-saving-only-specific-fields/280098>\
**Category:** Logstash\
**Created:** [July 30, 2021, 7:28pm UTC](https://discuss.elastic.co/t/output-to-json-saving-only-specific-fields/280098 "2021-07-30T19:28:23Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Hamza\_El\_Aouane](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/hamza_el_aouane/32/82411_2.png) [@Hamza\_El\_Aouane](https://discuss.elastic.co/u/Hamza_El_Aouane)\
**Post date:** [July 30, 2021, 7:28pm UTC](https://discuss.elastic.co/t/output-to-json-saving-only-specific-fields/280098/1 "2021-07-30T19:28:23Z")

</div>

Hello everyone

I am new logstash and I am sorry if the question is so basic.

I have been saving my syslog into a csv file, as follow:

```auto
 csv {
    path => "C:\path\Desktop\Adib\adib-syslogs-%{+yyyy.MM.dd}.csv"
    csv_options => {
        "write_headers" => true
        "headers" => ["@timestamp", "message", "name","userID", "deviceAction"]

}
    fields => ["@timestamp", "message", "name", "userID", "deviceAction"]
 }

```

but the output is frankly something I can't take, because for each entry, it save the headers. I have been reading here that there is no option to save the header only once, so I want to start saving the output to a json file.

following the logstash documentation, I found that I can use this command:

```auto
output {
 file {
   path => ...
   codec => json
 }
}

```

but I am a bit confused about the next step.

as you can see in my csv configuration, I am saving specific fields, as all the other I don't need them and I want to save space on my VM

is there a way how I can output my logstash logs to a json and specify only the fields I want to write to the file?

thank you very much for any help

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [July 30, 2021, 7:52pm UTC](https://discuss.elastic.co/t/output-to-json-saving-only-specific-fields/280098/2 "2021-07-30T19:52:56Z")

</div>

You could try using a prune filter with a whitelist\_names option.

---

<div class="post-metadata">

**Author:** ![Hamza\_El\_Aouane](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/hamza_el_aouane/32/82411_2.png) [@Hamza\_El\_Aouane](https://discuss.elastic.co/u/Hamza_El_Aouane)\
**Post date:** [July 30, 2021, 7:55pm UTC](https://discuss.elastic.co/t/output-to-json-saving-only-specific-fields/280098/3 "2021-07-30T19:55:49Z")

</div>

thank you so much for your reply. I am using grafana to visualise the data, and with the white names I won't see all the fields in grafana as I will see only the whitelisted. Is there any option to just filter the fields to save in json while I am still able to visualise the logs fully in grafana?

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [July 30, 2021, 7:57pm UTC](https://discuss.elastic.co/t/output-to-json-saving-only-specific-fields/280098/4 "2021-07-30T19:57:42Z")

</div>

Use pipeline-to-pipeline communication with a [forked path pattern](https://www.elastic.co/guide/en/logstash/current/pipeline-to-pipeline.html#forked-path-pattern).

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 27, 2021, 7:58pm UTC](https://discuss.elastic.co/t/output-to-json-saving-only-specific-fields/280098/5 "2021-08-27T19:58:25Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
