# Sending log payload to ES

**URL:** <https://discuss.elastic.co/t/sending-log-payload-to-es/98912>\
**Category:** Elasticsearch\
**Created:** [August 30, 2017, 8:36pm UTC](https://discuss.elastic.co/t/sending-log-payload-to-es/98912 "2017-08-30T20:36:23Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Souciance\_Eqdam\_Rash](https://avatars.discourse-cdn.com/v4/letter/s/50afbb/32.png) [@Souciance\_Eqdam\_Rash](https://discuss.elastic.co/u/Souciance_Eqdam_Rash)\
**Post date:** [August 30, 2017, 8:36pm UTC](https://discuss.elastic.co/t/sending-log-payload-to-es/98912/1 "2017-08-30T20:36:23Z")

</div>

Hello,

We have an application that generates logs which contain data payload. The data payload itself can be json, xml, some random CSV or any other format.

Is it possible to send the logs with the included payload to ES via normal tcp or http and then search view the data (including the data in the payload) in Kibana?

Do we need to configure any filters in logstash?

We are not interested in generating an output but simply to feed to ES data of varying format and be able to search it.

Thanks,

Best  
Souciance

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [August 30, 2017, 9:35pm UTC](https://discuss.elastic.co/t/sending-log-payload-to-es/98912/2 "2017-08-30T21:35:55Z")

</div>

You can do it but the results may not be the best due to the varied formats.  
Using Logstash would be better.

---

<div class="post-metadata">

**Author:** ![Souciance\_Eqdam\_Rash](https://avatars.discourse-cdn.com/v4/letter/s/50afbb/32.png) [@Souciance\_Eqdam\_Rash](https://discuss.elastic.co/u/Souciance_Eqdam_Rash)\
**Post date:** [August 31, 2017, 6:59am UTC](https://discuss.elastic.co/t/sending-log-payload-to-es/98912/3 "2017-08-31T06:59:23Z")

</div>

But even with logstash, how would you go about doing that? Basically we have logs that have the structure:

blabalbla xml-payload

or  
blablalba json-payload  
or  
blablalba\<random CSV or other similar format payload

If we were to send this via TCP, would logstash "automagically" parse this?

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [August 31, 2017, 11:19pm UTC](https://discuss.elastic.co/t/sending-log-payload-to-es/98912/4 "2017-08-31T23:19:47Z")

</div>

No it wouldn't, you'd need to figure out a way to run a conditional on it.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 28, 2017, 11:20pm UTC](https://discuss.elastic.co/t/sending-log-payload-to-es/98912/5 "2017-09-28T23:20:07Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
