# Recreating a log file

**URL:** <https://discuss.elastic.co/t/recreating-a-log-file/37504>\
**Category:** Elasticsearch\
**Created:** [December 17, 2015, 7:45pm UTC](https://discuss.elastic.co/t/recreating-a-log-file/37504 "2015-12-17T19:45:25Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![lhorsky1](https://avatars.discourse-cdn.com/v4/letter/l/b2d939/32.png) [@lhorsky1](https://discuss.elastic.co/u/lhorsky1)\
**Post date:** [December 17, 2015, 7:45pm UTC](https://discuss.elastic.co/t/recreating-a-log-file/37504/1 "2015-12-17T19:45:25Z")

</div>

I have oracle event logs feeding into Elasticsearch. All is great, except the oracle admins have times where they want to view the whole oracle log file, not just a single event. Has anyone exported the data out of elasticsearch and back into a log format?

---

<div class="post-metadata">

**Author:** ![jakommo](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jakommo/32/6716_2.png) [@jakommo](https://discuss.elastic.co/u/jakommo)\
**Post date:** [December 18, 2015, 11:47am UTC](https://discuss.elastic.co/t/recreating-a-log-file/37504/2 "2015-12-18T11:47:12Z")

</div>

Hi lhorsky1,

I have not seen that, but here are some options:

1. Assuming you are using kibana. The admin could set a filter on the `path` field to see all the events from this file.
2. It should be possible with logstash, using [elasticsearch input](https://www.elastic.co/guide/en/logstash/current/plugins-inputs-elasticsearch.html) and [file output](https://www.elastic.co/guide/en/logstash/current/plugins-outputs-file.html). But the resulting file might not be exactly the same as it was before processing it (e.g. if you droped fields, mutated fields etc.).

Personally I would recommend having a look at the original file, directly on the server, as this is unmodified.

Cheers,  
Jakob

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 5, 2017, 11:29pm UTC](https://discuss.elastic.co/t/recreating-a-log-file/37504/3 "2017-07-05T23:29:59Z")

</div>


