# Best way to parse events (filebeat module/logstash plugin/logstash input filter)

**URL:** <https://discuss.elastic.co/t/best-way-to-parse-events-filebeat-module-logstash-plugin-logstash-input-filter/227916>\
**Category:** Logstash\
**Created:** [April 14, 2020, 12:55pm UTC](https://discuss.elastic.co/t/best-way-to-parse-events-filebeat-module-logstash-plugin-logstash-input-filter/227916 "2020-04-14T12:55:43Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![s34g4r](https://avatars.discourse-cdn.com/v4/letter/s/e95f7d/32.png) [@s34g4r](https://discuss.elastic.co/u/s34g4r)\
**Post date:** [April 14, 2020, 12:55pm UTC](https://discuss.elastic.co/t/best-way-to-parse-events-filebeat-module-logstash-plugin-logstash-input-filter/227916/1 "2020-04-14T12:55:44Z")

</div>

I've installed and configured elasticstack on CentOS 8, using the packages in the elasticsearch repos. Once of the first log sources I'm toying with is mod\_security. Of course, the format of these logs is totally brutal, so it's been challenging. I see quite a bit of work has been to make this easier, but I'm struggling with the "best" or most "efficient" way to ingest/parse these.

- I've seen a filterset for mod\_security on github ([https://github.com/bitsofinfo/logstash-modsecurity](https://github.com/bitsofinfo/logstash-modsecurity)). Can I just feed these logs via a standard filebeats module and use this logstash filter set to parse them? Do I need to create a custom filebeats module to get these logs into logstash?

- I've seen a logstash plugin to parse these ([https://github.com/isaaceindhoven/logstash-filter-modsec](https://github.com/isaaceindhoven/logstash-filter-modsec)). Does this make more sense than using the filter set? Would I need custom filebeats modules to feed these logs in?

There are just so many options and approaches, I'm not confident in which route is the more standard or the more efficient. Any advice would be helpful.

Thanks for any help!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 12, 2020, 12:55pm UTC](https://discuss.elastic.co/t/best-way-to-parse-events-filebeat-module-logstash-plugin-logstash-input-filter/227916/2 "2020-05-12T12:55:52Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
