# Picking the right charset for Filebeat

**URL:** https://discuss.elastic.co/t/picking-the-right-charset-for-filebeat/115438
**Category:** Logstash
**Created:** [January 14, 2018, 11:13am UTC](https://discuss.elastic.co/t/picking-the-right-charset-for-filebeat/115438 "2018-01-14T11:13:40Z")
**Posts on this page:** 2
**Page:** 1

<div class="post-metadata">

### Author: ![X\_Calibur](https://avatars.discourse-cdn.com/v4/letter/x/b2d939/32.png) [@X\_Calibur](https://discuss.elastic.co/u/X_Calibur)
#### Post date: [January 14, 2018, 11:13am UTC](https://discuss.elastic.co/t/picking-the-right-charset-for-filebeat/115438/1 "2018-01-14T11:13:40Z")

</div>

Hi,

In the beginning I received the following error from Logstash when attempting to send in Linux security logs:

**"Received an event that has a different character encoding than you configured".**

After checking the logs characterset I determined it was US-ASCII.  
I changed my conf as follows:

> input{
> 
> ```
> syslog {
> type => "syslog"
> port => 55556
> codec => plain { charset => "US-ASCII" }
> add_field => { "data_source" => "linux_security" }
> }
> 
> ```
> 
> }
> 
> output{  
> if [data\_source] == "linux\_security" {
> 
> ```
> elasticsearch {
> hosts => ["localhost:9200"]
> index => "lnx_sec-%{+YYYY.ww}"
> user => elastic
> password => password
> }
> }
> 
> ```
> 
> }

Now only a part of the message appears as gibberish on Kibana:

 ![Capture](https://us1.discourse-cdn.com/elastic/original/3X/2/3/23332d6df04a867d498f24f44fcaeb7f9ff9b53a.JPG)

What am I missing?

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [February 11, 2018, 11:13am UTC](https://discuss.elastic.co/t/picking-the-right-charset-for-filebeat/115438/2 "2018-02-11T11:13:45Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
