# Elastic-agent and postfix logs

**URL:** <https://discuss.elastic.co/t/elastic-agent-and-postfix-logs/275872>\
**Category:** Beats\
**Tags:** elastic-agent\
**Created:** [June 14, 2021, 4:27pm UTC](https://discuss.elastic.co/t/elastic-agent-and-postfix-logs/275872 "2021-06-14T16:27:11Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![jerrac](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jerrac/32/52980_2.png) [@jerrac](https://discuss.elastic.co/u/jerrac)\
**Post date:** [June 14, 2021, 4:27pm UTC](https://discuss.elastic.co/t/elastic-agent-and-postfix-logs/275872/1 "2021-06-14T16:27:11Z")

</div>

Has anyone integrated elastic-agent and postfix in a really good way? As in made the agent split the log messages up into useful fields.

I've successfully configured the Custom Logs integration to pull in my postfix logs, but there is no automatic parsing of them.

I'm guessing there is a way to do so via the advanced config, but haven't dug into how that might work yet. I'm really hoping someone else would be willing to share their solution.

Oh, and I'll throw out the suggestion that Elastic should add an official postfix integration. 🙂

Thanks in advance!

---

<div class="post-metadata">

**Author:** ![jerrac](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jerrac/32/52980_2.png) [@jerrac](https://discuss.elastic.co/u/jerrac)\
**Post date:** [June 14, 2021, 5:52pm UTC](https://discuss.elastic.co/t/elastic-agent-and-postfix-logs/275872/2 "2021-06-14T17:52:39Z")

</div>

Adding processors does work in the `Custom configurations` field.

At least for dropping some events.

I tried using the dissect processor like so:

```auto
  processors:
  - dissect:
      tokenizer: '%{log_timestamp} %{host.name} %{process}[%{pid}]: %{queueid}: %{message}'
      field: "message"
      target_prefix: ""

```

But nothing happened. I'm guessing the tokenizer splits things up on spaces, so the timestamp having spaces in it would make things not match.

I also discovered you can use [grok](https://www.elastic.co/guide/en/elasticsearch/reference/7.13/grok-processor.html) in ingest pipelines. But I am unsure how to apply a pipeline to a specific data stream. I don't think we want to apply it to every doc that gets pushed into my stack...

---

<div class="post-metadata">

**Author:** ![jerrac](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jerrac/32/52980_2.png) [@jerrac](https://discuss.elastic.co/u/jerrac)\
**Post date:** [June 16, 2021, 10:19pm UTC](https://discuss.elastic.co/t/elastic-agent-and-postfix-logs/275872/3 "2021-06-16T22:19:02Z")

</div>

Thanks to [My Elastic Stack Observability Wishlist - #2 by cjcenizal](https://discuss.elastic.co/t/my-elastic-stack-observability-wishlist/276168/2) I was able to add my pipeline to my custom logs via the Custom configurations field. 🙂

Just add `pipeline: name-of-pipeline`.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 15, 2021, 12:19am UTC](https://discuss.elastic.co/t/elastic-agent-and-postfix-logs/275872/4 "2021-07-15T00:19:59Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
