# Common filter code, called from another filter?

**URL:** <https://discuss.elastic.co/t/common-filter-code-called-from-another-filter/181601>\
**Category:** Logstash\
**Created:** [May 17, 2019, 1:31pm UTC](https://discuss.elastic.co/t/common-filter-code-called-from-another-filter/181601 "2019-05-17T13:31:41Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![ghost3h](https://avatars.discourse-cdn.com/v4/letter/g/bc8723/32.png) [@ghost3h](https://discuss.elastic.co/u/ghost3h)\
**Post date:** [May 17, 2019, 1:31pm UTC](https://discuss.elastic.co/t/common-filter-code-called-from-another-filter/181601/1 "2019-05-17T13:31:41Z")

</div>

I have 2 different filters that come in on different ports. Each one gets send several input types, 3 of these are common across the two files.

Current processing I have "if" blocks looking at tags, and then blocks of code for data manipulations. This code is obviously common across the two filters, which is wasteful. Is it possible to reference another filter file with just the code for that type, where both could call that file?

Thanks

---

<div class="post-metadata">

**Author:** ![pastechecker](https://avatars.discourse-cdn.com/v4/letter/p/0ea827/32.png) [@pastechecker](https://discuss.elastic.co/u/pastechecker)\
**Post date:** [May 17, 2019, 1:39pm UTC](https://discuss.elastic.co/t/common-filter-code-called-from-another-filter/181601/2 "2019-05-17T13:39:37Z")

</div>

Can you share your config snippet?

I understand that you meant (simplified logic):  
input {  
tcp { port =\> 11, tag\_11}  
tcp { port =\> 12, tag\_12}  
}  
filter {  
if [tag] = "tag\_11 { do\_stuff\_1}  
if [tag] = "tag\_12 {do\_stuff\_1}  
}

And you want to take the do\_stuff\_1 to one place like a function and reference it within your if condition?

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [May 17, 2019, 2:22pm UTC](https://discuss.elastic.co/t/common-filter-code-called-from-another-filter/181601/3 "2019-05-17T14:22:29Z")

</div>

If they are running in separate pipelines they can certainly both reference a common file amongst their configuration files.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 14, 2019, 2:22pm UTC](https://discuss.elastic.co/t/common-filter-code-called-from-another-filter/181601/4 "2019-06-14T14:22:30Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
