# Removing fields from logstash output

**URL:** <https://discuss.elastic.co/t/removing-fields-from-logstash-output/103903>\
**Category:** Logstash\
**Created:** [October 13, 2017, 1:33pm UTC](https://discuss.elastic.co/t/removing-fields-from-logstash-output/103903 "2017-10-13T13:33:47Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![s.essa](https://avatars.discourse-cdn.com/v4/letter/s/ecb155/32.png) [@s.essa](https://discuss.elastic.co/u/s.essa)\
**Post date:** [October 13, 2017, 1:33pm UTC](https://discuss.elastic.co/t/removing-fields-from-logstash-output/103903/1 "2017-10-13T13:33:47Z")

</div>

Hello everyone, I'm new to LogStash and so I'm running into complications. I'm trying to use logstash to forward logs but the logs that are sent are completely different from the logs I expect.

When I use the syslog output plugin, I get something almost indecipherable (it has 3 or 4 timestamps?)

When I use the UDP output plugin I get something more... edible.

Here is an example:

Here's what I'm receiving:  
MM DD YYYY HH:mm:ss ELK IP \<USER:NOTE\> {"@timestamp":"YYYY-MM-DDTHH:mm:ss.000Z","syslog\_hostname":"SourceIP","syslog\_timestamp":"MMM DD HH:mm:ss","@version":"1","host":"LogGenHostIP","syslog\_program":"EVID:0000 Server3","message":"Message","type":"syslog","syslog\_message":"SyslogMessage"}

Please note that the timestamp "@timestamp" is reporting a time that is exactly 4 hours ahead of the first timestamp... I have no idea why.

So what I'd like to do is strip everything before "syslog\_hostname" but somehow anything I've tried isn't working.

Note that I'm using a log generator for the sample logs, which is why there is "host" pointing at the computer where the logs are being generated.

Any ideas are very much appreciated, about the timestamp or the field removal.

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [October 13, 2017, 2:27pm UTC](https://discuss.elastic.co/t/removing-fields-from-logstash-output/103903/2 "2017-10-13T14:27:54Z")

</div>

> Hello everyone, I'm new to LogStash and so I'm running into complications. I'm trying to use logstash to forward logs but the logs that are sent are completely different from the logs I expect.

Getting Logstash to act like a transparent syslog relay might take some effort.

> Please note that the timestamp "@timestamp" is reporting a time that is exactly 4 hours ahead of the first timestamp... I have no idea why.

`@timestamp` is always UTC.

---

<div class="post-metadata">

**Author:** ![s.essa](https://avatars.discourse-cdn.com/v4/letter/s/ecb155/32.png) [@s.essa](https://discuss.elastic.co/u/s.essa)\
**Post date:** [October 13, 2017, 2:31pm UTC](https://discuss.elastic.co/t/removing-fields-from-logstash-output/103903/3 "2017-10-13T14:31:56Z")

</div>

Indeed, I've struggled with the syslog output plugin and the udp output plugin. The former seems to be a lost cause but the latter is what I've reported above and seems much more promising.

---

<div class="post-metadata">

**Author:** ![s.essa](https://avatars.discourse-cdn.com/v4/letter/s/ecb155/32.png) [@s.essa](https://discuss.elastic.co/u/s.essa)\
**Post date:** [October 20, 2017, 3:28pm UTC](https://discuss.elastic.co/t/removing-fields-from-logstash-output/103903/4 "2017-10-20T15:28:26Z")

</div>

@magnusbaeck

Hey there, just checking in after a while. I'd really like to get this working, is there somewhere I can get a primer on removing fields or configuring the output plugins? I've looked through the documentation but I couldn't find what I need.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 17, 2017, 3:28pm UTC](https://discuss.elastic.co/t/removing-fields-from-logstash-output/103903/5 "2017-11-17T15:28:37Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
