# Use json and plain text beats from filebeat to output to syslog configured in logstash

**URL:** <https://discuss.elastic.co/t/use-json-and-plain-text-beats-from-filebeat-to-output-to-syslog-configured-in-logstash/257186>\
**Category:** Logstash\
**Created:** [December 1, 2020, 10:13am UTC](https://discuss.elastic.co/t/use-json-and-plain-text-beats-from-filebeat-to-output-to-syslog-configured-in-logstash/257186 "2020-12-01T10:13:05Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![Arjun\_kochhar](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/arjun_kochhar/32/79995_2.png) [@Arjun\_kochhar](https://discuss.elastic.co/u/Arjun_kochhar)\
**Post date:** [December 1, 2020, 10:13am UTC](https://discuss.elastic.co/t/use-json-and-plain-text-beats-from-filebeat-to-output-to-syslog-configured-in-logstash/257186/1 "2020-12-01T10:13:05Z")

</div>

Hi, Very new to logstash and have a use case that I want to achieve. I have two different filebeat instances that write to same logstash instance. filebeat instance 1 sends json output and also sets field as `json`, while other filebeat instance 2 sends plain text and sets field as `plain`. I have the logstash instance configured to listen to them and writes it out to syslog server:

```auto
input {
  beats {
    port => 5044
  }
}

filter{
  mutate{
    add_field => ["timestamp", "%{@timestamp}"]
  }
}

output {
  syslog {
    host => "100.100.100.100"
    port => 514
    protocol => "tcp"
    ssl_verify => "false"
    rfc => "rfc5424"
  }
}

```

But if I understand it correctly, the default codec used for syslog output is `plain`. What is the recommended approach here to handle the `json` beats being received from filebeat instance 1?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 29, 2020, 10:13am UTC](https://discuss.elastic.co/t/use-json-and-plain-text-beats-from-filebeat-to-output-to-syslog-configured-in-logstash/257186/2 "2020-12-29T10:13:08Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
