# Simplifying Filebeat JSON Output Format

**URL:** <https://discuss.elastic.co/t/simplifying-filebeat-json-output-format/48085>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [April 21, 2016, 6:16pm UTC](https://discuss.elastic.co/t/simplifying-filebeat-json-output-format/48085 "2016-04-21T18:16:56Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![rzaakir](https://avatars.discourse-cdn.com/v4/letter/r/71c47a/32.png) [@rzaakir](https://discuss.elastic.co/u/rzaakir)\
**Post date:** [April 21, 2016, 6:16pm UTC](https://discuss.elastic.co/t/simplifying-filebeat-json-output-format/48085/1 "2016-04-21T18:16:56Z")

</div>

Hello,

I am new working with Filebeat and think it is a wonderful tool. I am currently using it to replace a tool that pushes weblogs to Kafka, and I want to just pass the "message" through without the other values. Is this possible?

Thanks!

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [April 22, 2016, 3:20am UTC](https://discuss.elastic.co/t/simplifying-filebeat-json-output-format/48085/2 "2016-04-22T03:20:43Z")

</div>

You can use the [include\_fields](https://www.elastic.co/guide/en/beats/filebeat/master/configuration-filter.html#include-fields) filter.

```auto
filter:
 - include_fields.fields: ["message"]

```

That will leave `message`, `type`, and `@timestamp` in the event.

---

<div class="post-metadata">

**Author:** ![rzaakir](https://avatars.discourse-cdn.com/v4/letter/r/71c47a/32.png) [@rzaakir](https://discuss.elastic.co/u/rzaakir)\
**Post date:** [April 22, 2016, 1:56pm UTC](https://discuss.elastic.co/t/simplifying-filebeat-json-output-format/48085/3 "2016-04-22T13:56:44Z")

</div>

Thanks Andrew! That answers my question.I was hoping to just push the single field as my consumer has no use for the timestamp or type fields but this does get me mostly there..

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 5, 2017, 9:52pm UTC](https://discuss.elastic.co/t/simplifying-filebeat-json-output-format/48085/4 "2017-07-05T21:52:51Z")

</div>


