# Print logs into a file before parsing with GROK

**URL:** <https://discuss.elastic.co/t/print-logs-into-a-file-before-parsing-with-grok/323145>\
**Category:** Logstash\
**Created:** [January 13, 2023, 2:38pm UTC](https://discuss.elastic.co/t/print-logs-into-a-file-before-parsing-with-grok/323145 "2023-01-13T14:38:05Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![danishbit09](https://avatars.discourse-cdn.com/v4/letter/d/ea5d25/32.png) [@danishbit09](https://discuss.elastic.co/u/danishbit09)\
**Post date:** [January 13, 2023, 2:38pm UTC](https://discuss.elastic.co/t/print-logs-into-a-file-before-parsing-with-grok/323145/1 "2023-01-13T14:38:05Z")

</div>

Is there any option to store logs into a file before parsing it in GROK. Please suggest. Can I use logger.info() in Filter plugin.

---

<div class="post-metadata">

**Author:** ![Rios](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rios/32/95745_2.png) [@Rios](https://discuss.elastic.co/u/Rios)\
**Post date:** [January 13, 2023, 4:11pm UTC](https://discuss.elastic.co/t/print-logs-into-a-file-before-parsing-with-grok/323145/2 "2023-01-13T16:11:20Z")

</div>

There is no option AFAIK.  
What is received, will be in in the message field or in event.original with ECS v8

```auto
   "event" => {
        "sequence" => 0,
        "original" => "Some text"
    }

```

What you can do is to save in a file at the end - in the output section  
` file { path => "/path/filename_%{+YYYY-MM-dd}.txt" }`  
or use  
` stdout { codec => rubydebug{} }`  
You might ruby code to save in a file. If you have some issues with paste here a sample and what fields you expect, someone will help

---

<div class="post-metadata">

**Author:** ![Sunile\_Manjee](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sunile_manjee/32/111461_2.png) [@Sunile\_Manjee](https://discuss.elastic.co/u/Sunile_Manjee)\
**Post date:** [January 14, 2023, 4:43pm UTC](https://discuss.elastic.co/t/print-logs-into-a-file-before-parsing-with-grok/323145/3 "2023-01-14T16:43:25Z")

</div>

why not use clone for those events [Clone filter plugin | Logstash Reference [8.6] | Elastic](https://www.elastic.co/guide/en/logstash/current/plugins-filters-clone.html) and then in output section, write only cloned events to the file?

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [January 14, 2023, 5:52pm UTC](https://discuss.elastic.co/t/print-logs-into-a-file-before-parsing-with-grok/323145/4 "2023-01-14T17:52:15Z")

</div>

> [@danishbit09](#):
>
> Is there any option to store logs into a file before parsing it in GROK. Please suggest.

Use pipeline-to-pipeline communication with a [forked-path](https://www.elastic.co/guide/en/logstash/current/pipeline-to-pipeline.html#forked-path-pattern) pattern to process events in two different ways. That can also be done using a clone filter and conditionals.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 11, 2023, 5:52pm UTC](https://discuss.elastic.co/t/print-logs-into-a-file-before-parsing-with-grok/323145/5 "2023-02-11T17:52:44Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
