# Executing bash script in logstash's filter and geting data back to field

**URL:** <https://discuss.elastic.co/t/executing-bash-script-in-logstashs-filter-and-geting-data-back-to-field/313297>\
**Category:** Logstash\
**Created:** [August 30, 2022, 9:27pm UTC](https://discuss.elastic.co/t/executing-bash-script-in-logstashs-filter-and-geting-data-back-to-field/313297 "2022-08-30T21:27:45Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![rayg00n](https://avatars.discourse-cdn.com/v4/letter/r/9de0a6/32.png) [@rayg00n](https://discuss.elastic.co/u/rayg00n)\
**Post date:** [August 30, 2022, 9:27pm UTC](https://discuss.elastic.co/t/executing-bash-script-in-logstashs-filter-and-geting-data-back-to-field/313297/1 "2022-08-30T21:27:45Z")

</div>

Hello friends!  
I need some help with my logstash config.

I want to get event field "winlog.event\_data.ObjectName" and take it to a bash script.  
Then I want to get the result back and put it in the "winlog.event\_data.ObjectName".  
Is it possible with rub filter or smth like that?

Here is the config:

```auto
input {
   beats {
      port => 5140
    }
  }

filter {
    if [winlog.event_data.ObjectType] {
        ruby {
          code => 'require "open3"
          winlog = event.get("winlog.event_data.ObjectName")
          cmd = "/etc/logstash/script/ldap_search.sh #{winlog}"
          stdin, stdout, stderr = Open3.popen3(cmd)
          event.set("winlog.event_data.ObjectType", stdout.read)
          err = stderr.read
          if err.to_s.empty?
            filter_matched(event)
          else
            event.set("winlog.event_data.ObjectType", err)
          end'
        remove_field => ["tags"]
       }
    }
}

```

PS:  
"ldap\_search.sh" script does:  
Turns the value like this "%{1ee131bd-72b1-47ae-8d79-ba4bd881a86b}"  
Into the value like that "DC=AgentSmith,[DC=example.ru](http://DC=example.ru),DC=ru"  
It can be used to get the "DistingushedName" of an Active Directory object that was last changed.  
Example:  
/etc/logstash/script/ldap\_search.sh %{1ee131bd-72b1-47ae-8d79-ba4bd881a86b}  
stdout:  
"DC=AgentSmith,[DC=example.ru](http://DC=example.ru),DC=ru

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [August 30, 2022, 9:40pm UTC](https://discuss.elastic.co/t/executing-bash-script-in-logstashs-filter-and-geting-data-back-to-field/313297/2 "2022-08-30T21:40:36Z")

</div>

> [@rayg00n](#):
>
> `[winlog.event_data.ObjectType]`

logstash supports periods in field names, so to refer to fields that contain other objects you must use [winlog][event\_data][ObjectType]. That is true in the ruby filter too.

---

<div class="post-metadata">

**Author:** ![rayg00n](https://avatars.discourse-cdn.com/v4/letter/r/9de0a6/32.png) [@rayg00n](https://discuss.elastic.co/u/rayg00n)\
**Post date:** [August 30, 2022, 10:07pm UTC](https://discuss.elastic.co/t/executing-bash-script-in-logstashs-filter-and-geting-data-back-to-field/313297/3 "2022-08-30T22:07:13Z")

</div>

Thanks!  
I will try it and go back soon.

---

<div class="post-metadata">

**Author:** ![rayg00n](https://avatars.discourse-cdn.com/v4/letter/r/9de0a6/32.png) [@rayg00n](https://discuss.elastic.co/u/rayg00n)\
**Post date:** [August 30, 2022, 10:17pm UTC](https://discuss.elastic.co/t/executing-bash-script-in-logstashs-filter-and-geting-data-back-to-field/313297/4 "2022-08-30T22:17:47Z")

</div>

You are my savior!  
The config like that is working!

```auto
input {
   beats {
      port => 5140
    }
  }

filter {
# if [winlog][event_data][ObjectType] {
        ruby {
         code => 'require "open3"
         win = event.get("[winlog][event_data][ObjectName]")
         cmd = "/usr/bin/bash /etc/logstash/script/ldap_search.sh #{win}"
         stdin, stdout, stderr = Open3.popen3(cmd)
         event.set("[winlog][event_data][ObjectName]", stdout.read)
         err = stderr.read
         if err.to_s.empty?
           filter_matched(event)
         else
           event.set("[winlog][event_data][ObjectName]", err)
         end'
        remove_field => ["tags"]
       }
    }
#}

```

PS:  
I would be glad to include that filter into the official logstash-plugins, because there are no any plugins we can use to change the winlog.event\_data.ObjectName to readable string while parsing Microsoft Security Log, but later . . .

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 27, 2022, 10:18pm UTC](https://discuss.elastic.co/t/executing-bash-script-in-logstashs-filter-and-geting-data-back-to-field/313297/5 "2022-09-27T22:18:42Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
