# Filter based on input (Filebeat/Winlogbeat) in logstash

**URL:** <https://discuss.elastic.co/t/filter-based-on-input-filebeat-winlogbeat-in-logstash/194189>\
**Category:** Logstash\
**Created:** [August 7, 2019, 9:10am UTC](https://discuss.elastic.co/t/filter-based-on-input-filebeat-winlogbeat-in-logstash/194189 "2019-08-07T09:10:07Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![rplus](https://avatars.discourse-cdn.com/v4/letter/r/34f0e0/32.png) [@rplus](https://discuss.elastic.co/u/rplus)\
**Post date:** [August 7, 2019, 9:10am UTC](https://discuss.elastic.co/t/filter-based-on-input-filebeat-winlogbeat-in-logstash/194189/1 "2019-08-07T09:10:07Z")

</div>

Hello!

I've configured winlogbeat and filebeat on a windows host. Both filebeat and winlogbeat have the same logstash output. What I would like to do, and I what I am having trouble with is that I would like to apply different grok filters for each type, i.e one grok filter for all filbeat input and another grok filter for all winlogbeat input.

This is my current configuration.

```
input {
      beats {
        port => 5044
    }
 }

filter {
    if [type] == "filebeat" {
       grok {
        match => ["message", "%{TIMESTAMP_ISO8601:log_timestamp} %{IP:serverIP} %{WORD:method} %{URIPATH:uriStem} %{NOTSPACE:uriQuery} %{NUMBER:port} %{NOTSPACE:username} %{IPORHOST:clientIP} %{NOTSPACE:userAgent} %{NOTSPACE:referer} %{NUMBER:response} %{NUMBER:subresponse} %{NUMBER:win32response} %{NUMBER:timetaken}"]
    }
 }
}
output {
   elasticsearch {
     hosts => "X.X.X.X:XXXX
     manage_template => false
     index => "%{[@metadata][beat]}-%{[@metadata][version]}-%{+YYYY.MM.dd}"
     document_type => "%{[@metadata][type]}"
   }
}

```

I changed the output to : { codec =\> rubydebug { metadata =\> true } } and saw that there was a type field that contained "filebeat". However, it doesn't seem to work either. It just seem to "ignore" the filbeat input.

If I run without the if-condition it correctly parses the message field from the filebeat input.

Any tips would be welcome.

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [August 7, 2019, 10:40am UTC](https://discuss.elastic.co/t/filter-based-on-input-filebeat-winlogbeat-in-logstash/194189/2 "2019-08-07T10:40:01Z")

</div>

If you have to enable metadata =\> true to see the type field then you are referring to [@metadata][type] and that is what you should be testing, not [type].

---

<div class="post-metadata">

**Author:** ![rplus](https://avatars.discourse-cdn.com/v4/letter/r/34f0e0/32.png) [@rplus](https://discuss.elastic.co/u/rplus)\
**Post date:** [August 7, 2019, 11:15am UTC](https://discuss.elastic.co/t/filter-based-on-input-filebeat-winlogbeat-in-logstash/194189/3 "2019-08-07T11:15:30Z")

</div>

Hi,

Thanks for your reply.

I updated my config with:

filter {  
if [@metadata][type] == "filebeat" {

I still get the same result.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 4, 2019, 11:15am UTC](https://discuss.elastic.co/t/filter-based-on-input-filebeat-winlogbeat-in-logstash/194189/4 "2019-09-04T11:15:36Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
