# Output Using CEF codec and to Kafka Server

**URL:** <https://discuss.elastic.co/t/output-using-cef-codec-and-to-kafka-server/277243>\
**Category:** Logstash\
**Created:** [June 28, 2021, 2:36pm UTC](https://discuss.elastic.co/t/output-using-cef-codec-and-to-kafka-server/277243 "2021-06-28T14:36:17Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![Wilks](https://avatars.discourse-cdn.com/v4/letter/w/f475e1/32.png) [@Wilks](https://discuss.elastic.co/u/Wilks)\
**Post date:** [June 28, 2021, 2:36pm UTC](https://discuss.elastic.co/t/output-using-cef-codec-and-to-kafka-server/277243/1 "2021-06-28T14:36:17Z")

</div>

Hi,  
Is there a way to nest the Output statement so that I can first output using the CEF codec and then Output to a Kafka topic. The requirement is that I have to covert the data to CEF and then send to a Kafka topic. I feel like I can just use the server and port of the Kafka server but I am not sure how to send it to a specific topic on that server. Will just adding "topic\_id" work? or does it have to be nested differently?

```auto
output {
  tcp {
    port => "KAFKA SERVER PORT"
    host => "192,168.1.1,192.168.1.2"
    **topic_id => "mytopic"** 
    codec => cef {
      delimiter => "\r\n"
            fields => ["cs1", "cs2", "cs3"]
      version => "1"
      severity => "7"
    }
	}
}

```

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [June 28, 2021, 4:18pm UTC](https://discuss.elastic.co/t/output-using-cef-codec-and-to-kafka-server/277243/2 "2021-06-28T16:18:05Z")

</div>

Why are you not using a kafka output?

---

<div class="post-metadata">

**Author:** ![Wilks](https://avatars.discourse-cdn.com/v4/letter/w/f475e1/32.png) [@Wilks](https://discuss.elastic.co/u/Wilks)\
**Post date:** [June 28, 2021, 4:23pm UTC](https://discuss.elastic.co/t/output-using-cef-codec-and-to-kafka-server/277243/3 "2021-06-28T16:23:09Z")

</div>

Because I need the output to be in CEF format and I thought in order to output in CEF format I had to use the CEF codec. If I output just using

```auto
output {
      kafka {
        codec => json
        topic_id => "mytopic"
      }
    }

```

Will it display in CEF? or just text based? Basically want to send CEF formated data to a Kafka topic

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [June 28, 2021, 4:29pm UTC](https://discuss.elastic.co/t/output-using-cef-codec-and-to-kafka-server/277243/4 "2021-06-28T16:29:37Z")

</div>

Have you tried using a cef codec for the kafka output?

---

<div class="post-metadata">

**Author:** ![Wilks](https://avatars.discourse-cdn.com/v4/letter/w/f475e1/32.png) [@Wilks](https://discuss.elastic.co/u/Wilks)\
**Post date:** [June 28, 2021, 6:34pm UTC](https://discuss.elastic.co/t/output-using-cef-codec-and-to-kafka-server/277243/5 "2021-06-28T18:34:01Z")

</div>

Ah I see what you mean.  
Thanks

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 26, 2021, 6:34pm UTC](https://discuss.elastic.co/t/output-using-cef-codec-and-to-kafka-server/277243/6 "2021-07-26T18:34:33Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
