# Filter and return only specific fields using elasticsearch plugin with logstash

**URL:** <https://discuss.elastic.co/t/filter-and-return-only-specific-fields-using-elasticsearch-plugin-with-logstash/274599>\
**Category:** Logstash\
**Created:** [June 1, 2021, 8:51am UTC](https://discuss.elastic.co/t/filter-and-return-only-specific-fields-using-elasticsearch-plugin-with-logstash/274599 "2021-06-01T08:51:14Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![Nico3](https://avatars.discourse-cdn.com/v4/letter/n/f04885/32.png) [@Nico3](https://discuss.elastic.co/u/Nico3)\
**Post date:** [June 1, 2021, 8:51am UTC](https://discuss.elastic.co/t/filter-and-return-only-specific-fields-using-elasticsearch-plugin-with-logstash/274599/1 "2021-06-01T08:51:14Z")

</div>

Hello,  
I'm trying to create a pipeline with logstash in order to "extract" a specific metric from Elasticsearch (window\_cpu\_time\_total). Here is my pipeline:

```
input {
  elasticsearch {
        hosts => ["http://localhost:9200"]
        index => "metricbeat-7.12.0-2021.04.29-000001"
        query => '{"_source": ["@timestamp", "labels","prometheus"]}'
      }
}
output {
      elasticsearch {
        hosts => ["http://localhost:9200"]
        index => "{test3[beat]}[version]}"
      }
    }

```

I get something like that which is closer to what I want. Now I would like an additional filter where I get only the metrics "prometheus.metrics.windows\_cpu\_time\_total" and not the other metrics.

```
 {
"hits": {
    "hits": [
        {
        {
            "_source": {
                "@timestamp": "2021-04-29T15:35:57.518Z",
                "prometheus": {
                    "metrics": {
                        "windows_service_status": 0
                    },
                    "labels": {
                        "instance": "localhost:9182",
                        "name": "timebrokersvc",
                        "job": "prometheus",
                        "status": "lost comm"
                    }
                }
            }
        },
        {
            "_source": {
                "@timestamp": "2021-04-29T15:35:57.518Z",
                "prometheus": {
                    "metrics": {
                        "windows_cpu_time_total": 29480.625
                    },
                    "labels": {
                        "mode": "idle",
                        "core": "0,0",
                        "instance": "localhost:9182",
                        "job": "prometheus"
                    }
                }
            }
        }}]}}

```

Could someone help me with that ?  
Thank you in advance

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 29, 2021, 8:51am UTC](https://discuss.elastic.co/t/filter-and-return-only-specific-fields-using-elasticsearch-plugin-with-logstash/274599/2 "2021-06-29T08:51:26Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
