# DIfferent Kinds of events from filebeat to Logstash, Assorting and Parsing

**URL:** <https://discuss.elastic.co/t/different-kinds-of-events-from-filebeat-to-logstash-assorting-and-parsing/140391>\
**Category:** Logstash\
**Created:** [July 17, 2018, 8:05pm UTC](https://discuss.elastic.co/t/different-kinds-of-events-from-filebeat-to-logstash-assorting-and-parsing/140391 "2018-07-17T20:05:28Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![sdubbudu](https://avatars.discourse-cdn.com/v4/letter/s/3ab097/32.png) [@sdubbudu](https://discuss.elastic.co/u/sdubbudu)\
**Post date:** [July 17, 2018, 8:05pm UTC](https://discuss.elastic.co/t/different-kinds-of-events-from-filebeat-to-logstash-assorting-and-parsing/140391/1 "2018-07-17T20:05:28Z")

</div>

Hello,  
I am trying to use filebeat to send two different types of events each from a different log to Logstash which does a different grok parse on each and send with a different id, but the same index to elasticsearch. I will be showing my filebeat input config and pipeline config in logstash, but when I try to use it- it just gives a very unhelpful error in log. I am not sure if my syntax is wrong or if something else is the problem.

FIlebeat input config:

filebeat.inputs:

- type: log  
paths:

- type: log  
paths:

LOGSTASH PIPELINE CONFIG:  
input{  
beats{  
port =\> 5044  
host =\> "10.0.2.15"  
}  
}

filter {  
if [fields][log\_type] == "SYSSTATS" {  
grok {  
match =\> {  
"message" =\> "%{SPACE:1}%{NUMBER:pid}%{SPACE:1}%{WORD:user}%{SPACE:1}%{INT:priority}%{SPACE:1}%{INT:nice\_value}%{SPACE:1}%{NOTSPACE:virtual\_memory}%{SPACE:1}%{NOTSPACE:physical\_memory}%{SPACE:1}%{NOTSPACE:shared\_memory}%{SPACE:1}%{WORD:status}%{SPACE:1}%{BASE16FLOAT:cpu\_usage}%{SPACE:1}%{BASE16FLOAT:ram\_usage}%{SPACE:1}%{NOTSPACE:activity\_time}%{SPACE:1}%{WORD:command}%{SPACE:1}"  
}  
remove\_field =\> ["1", "host.name", "version", "\_id", "\_index", "\_score", "\_type", "beat.hostname", "beat.name", "beat.version"]  
}  
mutate { add\_field =\> { "[@metadata][test]" =\> "SYSUSAGE" } }  
}  
if [fields][log\_type] == "NETSTATS" {  
grok {  
match =\> {  
"message" =\> "%{WORD:protoc}%{SPACE:2}%{NUMBER:recv\_q}%{SPACE:2}%{NUMBER:send\_q}%{SPACE:2}%{NOTSPACE:local\_add}%{SPACE:2}%{NOTSPACE:forn\_add}%{SPACE:2}%{WORD:status}"  
}  
remove\_field =\> ["2"]  
}  
mutate { add\_field =\> { "[@metadata][test]" =\> "NETUSAGE" } }  
}  
}  
output{  
if [@metadata][test] == "NETUSAGE" {  
stdout{}  
elasticsearch {  
host =\> "10.0.2.15"  
manage\_template =\> false  
index =\> "%{[@metadata][version]-%{+YYYY.MM.dd}"  
id =\> "Network\_Usage"  
}  
}  
if [@metadata][test] == "SYSUSAGE" {  
stdout{}  
elasticsearch {  
host =\> "10.0.2.15"  
manage\_template =\> false  
index =\> "%{[@metadata][version]-%{+YYYY.MM.dd}"  
id =\> "System\_Usage"  
}  
}  
}

ERROR WAS:  
[2018-07-17T16:16:34,649][ERROR][logstash.outputs.elasticsearch] Unknown setting 'host' for elasticsearch  
[2018-07-17T16:16:34,713][ERROR][logstash.agent] Failed to execute action {:action=\>LogStash::PipelineAction::Create/pipeline\_id:main, :exception=\>"LogStash::ConfigurationError", :message=\>"Something is wrong with your configuration.", :backtrace=\>["/usr/share/logstash/logstash-core/lib/logstash/config/mixin.rb:89:in `config_init'", "/usr/share/logstash/logstash-core/lib/logstash/outputs/base.rb:62:in`initialize'", "org/logstash/config/ir/compiler/OutputStrategyExt.java:202:in `initialize'", "org/logstash/config/ir/compiler/OutputDelegatorExt.java:68:in`initialize'", "/usr/share/logstash/logstash-core/lib/logstash/plugins/plugin\_factory.rb:93:in `plugin'", "/usr/share/logstash/logstash-core/lib/logstash/pipeline.rb:110:in`plugin'", "(eval):116:in `<eval>'", "org/jruby/RubyKernel.java:994:in`eval'", "/usr/share/logstash/logstash-core/lib/logstash/pipeline.rb:82:in `initialize'", "/usr/share/logstash/logstash-core/lib/logstash/pipeline.rb:167:in`initialize'", "/usr/share/logstash/logstash-core/lib/logstash/pipeline\_action/create.rb:40:in `execute'", "/usr/share/logstash/logstash-core/lib/logstash/agent.rb:305:in`block in converge\_state'"]}

I am new here so not really been able to pick up simple mistakes, could be very helpful if u could look at it.

Thanks

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [July 17, 2018, 8:20pm UTC](https://discuss.elastic.co/t/different-kinds-of-events-from-filebeat-to-logstash-assorting-and-parsing/140391/2 "2018-07-17T20:20:53Z")

</div>

How could the error message "Unknown setting 'host' for elasticsearch" be improved? What do you find unclear about it?

host =\> "10.0.2.15" should be hosts =\> "10.0.2.15"

---

<div class="post-metadata">

**Author:** ![sdubbudu](https://avatars.discourse-cdn.com/v4/letter/s/3ab097/32.png) [@sdubbudu](https://discuss.elastic.co/u/sdubbudu)\
**Post date:** [July 17, 2018, 8:26pm UTC](https://discuss.elastic.co/t/different-kinds-of-events-from-filebeat-to-logstash-assorting-and-parsing/140391/3 "2018-07-17T20:26:48Z")

</div>

Hey thanks again Badger. host =\> was working fine for me earlier, i did not expect to change it. Thanks, it worked.  
Surya

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 14, 2018, 8:26pm UTC](https://discuss.elastic.co/t/different-kinds-of-events-from-filebeat-to-logstash-assorting-and-parsing/140391/4 "2018-08-14T20:26:52Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
