Filter Array Values

I HAVE AN ARRAY OF MAC ADDRESS THAT I WANT TO FILTER IN LOGSTASH. I want to make it as a new document for each value. Can anybody help me ?


Use a split filter.

1 Like

i did but my elasticsearch is not getting any documents

I suggest you replace your elasticsearch output with output { stdout { codec => rubydebug } } and see what logstash prints to stdout.

Nobody here can say what is wrong with your configuration if you don't show us your configuration.

input {
port => 5044

filter {

json {
    source => "message"
split {
    field => "message"


output {
elasticsearch {
hosts => ["localhost:9200"]
manage_template => false
index => "%{[@metadata][beat]}"

The input data as posted is not valid JSON. Please use </> in the toolbar above the editing pane to quote it so that formatting is preserved.

okay my bad , im so sorry im new to this thing.

i tried removing the json its still not working

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.