# Remove default fields from logstash output

**URL:** <https://discuss.elastic.co/t/remove-default-fields-from-logstash-output/45576>\
**Category:** Logstash\
**Created:** [March 28, 2016, 10:09am UTC](https://discuss.elastic.co/t/remove-default-fields-from-logstash-output/45576 "2016-03-28T10:09:26Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![valjohn1647](https://avatars.discourse-cdn.com/v4/letter/v/7bcc69/32.png) [@valjohn1647](https://discuss.elastic.co/u/valjohn1647)\
**Post date:** [March 28, 2016, 10:09am UTC](https://discuss.elastic.co/t/remove-default-fields-from-logstash-output/45576/1 "2016-03-28T10:09:26Z")

</div>

Hi all

Im going to use the logstash to send my logfiles to s3 and later Archie it via Glacier .

But my issue was logstash by default add the @timestamp and "host" parameter details to the output log

Eg:

# Input log:

195.88.209.245 - - [28/Mar/2016:14:53:18 +0530] "POST /xmlrpc.php HTTP/1.0" 200 665 "-" "Mozilla/4.0 (compatible: MSIE 7.0; Windows NT 6.0)"

# Output Log of logstahsh

2016-03-28T09:25:32.624Z [logstash.ihk.com](http://logstash.ihk.com) 195.88.209.245 - - [28/Mar/2016:14:53:18 +0530] "POST /xmlrpc.php HTTP/1.0" 200 665 "-" "Mozilla/4.0 (compatible: MSIE 7.0; Windows NT 6.0)"

Basically i want to remove the ,

@timestamp - \> 2016-03-28T09:25:32.624Z and host : [logstash.ihk.com](http://logstash.ihk.com) value from the output log so that i can copy the original log file to s3

is there any way to achieve it , please advice

---

<div class="post-metadata">

**Author:** ![kirill\_polishchuk](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kirill_polishchuk/32/6489_2.png) [@kirill\_polishchuk](https://discuss.elastic.co/u/kirill_polishchuk)\
**Post date:** [March 28, 2016, 11:04am UTC](https://discuss.elastic.co/t/remove-default-fields-from-logstash-output/45576/2 "2016-03-28T11:04:41Z")

</div>

Hello

by default S3 output plugin use the codec `line`, which encodes your event in simple string.  
But you can specify format for the line codec, that will be sprintfed to string. For example:

```
output {
   s3{
     access_key_id => "crazy_key" (required)
     secret_access_key => "monkey_access_key" (required)
     endpoint_region => "eu-west-1" (required)
     bucket => "boss_please_open_your_bucket" (required)
     size_file => 2048 (optional)
     time_file => 5 (optional)
     codec => line {
        format => "%{message}"
     }
 }
```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 5:05am UTC](https://discuss.elastic.co/t/remove-default-fields-from-logstash-output/45576/3 "2017-07-06T05:05:11Z")

</div>


