# Filter elasticsearch data with logstash

**URL:** <https://discuss.elastic.co/t/filter-elasticsearch-data-with-logstash/341077>\
**Category:** Logstash\
**Created:** [August 18, 2023, 7:17am UTC](https://discuss.elastic.co/t/filter-elasticsearch-data-with-logstash/341077 "2023-08-18T07:17:56Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![john.hoogeveen](https://avatars.discourse-cdn.com/v4/letter/j/a9a28c/32.png) [@john.hoogeveen](https://discuss.elastic.co/u/john.hoogeveen)\
**Post date:** [August 18, 2023, 7:17am UTC](https://discuss.elastic.co/t/filter-elasticsearch-data-with-logstash/341077/1 "2023-08-18T07:17:56Z")

</div>

Hello, I am trying to export some data from an elastic stack using logstash but it doesn't work.  
For this I connected it to a test stack with this config file

```auto
input {
  elasticsearch {
    hosts => "localhost:9200"
    index => "winlogbeat-6.3.2-2023.08.16"
    query => '{ "query": { "query_string": { "query": "*" } } }'
    size => 5
    scroll => "10s"
    docinfo => true
  }
}

filter {
  if "4634" in [event_id] {
    mutate { add_tag => "field in field" }
  }
}

output {
  if "field in field" in [tags] {
    stdout {
      codec => rubydebug { metadata => true }
    }
  }
}

```

If I remove the part " if "4634" in [event\_id] " from the filter it works, and the tag is added to the output as expected  
As an example, below is one of the source items being fetched from elasticsearch.

```auto
    "record_number" => "953747822",
       "event_data" => {
                "TargetLogonId" => "0x28775",
              "SubjectUserName" => "sa_fortisso",
                  "ProcessName" => "C:\\Program Files (x86)\\Fortinet\\FSAE\\collectoragent.exe",
            "SubjectDomainName" => "domain",
                    "ProcessId" => "0x1190",
        "DisabledPrivilegeList" => "SeSecurityPrivilege",
               "SubjectLogonId" => "0x28775",
               "TargetUserName" => "sa_fortisso",
             "TargetDomainName" => "domain",
               "SubjectUserSid" => "S-1-5-21-35345345345-1588684209-2680700694-2234",
         "EnabledPrivilegeList" => "-",
                "TargetUserSid" => "S-1-0-0"
    },
          "message" => "A token right was adjusted.\n\nSubject:\n\tSecurity ID:\t\tS-1-5-21-3905848510-1588684209-2680700694-2234\n\tAccount Name:\t\tsa_fortisso\n\tAccount Domain:\t\tITIS\n\tLogon ID:\t\t0x28775\n\nTarget Account:\n\tSecurity ID:\t\tS-1-0-0\n\tAccount Name:\t\tsa_fortisso\n\tAccount Domain:\t\tITIS\n\tLogon ID:\t\t0x28775\n\nProcess Information:\n\tProcess ID:\t\t0x1190\n\tProcess Name:\t\tC:\\Program Files (x86)\\Fortinet\\FSAE\\collectoragent.exe\n\nEnabled Privileges:\n\t\t\t-\n\nDisabled Privileges:\n\t\t\tSeSecurityPrivilege",
             "type" => "wineventlog",
           "opcode" => "Info",
        "thread_id" => 10148,
             "task" => "Token Right Adjusted Events",
         "event_id" => 4634,
       "@timestamp" => 2023-08-16T09:57:19.717Z,
    "provider_guid" => "{54849625-5478-4994-A5BA-3E3B0328C30D}",
         "@version" => "1",
             "host" => {
        "name" => "hostname"
    },
             "beat" => {
        "hostname" => "hostname",
            "name" => "hostname",
         "version" => "6.3.2"
    },
      "source_name" => "Microsoft-Windows-Security-Auditing"
}
{
       "process_id" => 4,
    "computer_name" => "fqdn",
         "keywords" => [
        [0] "Audit Success"
    ],
         "log_name" => "Security",
            "level" => "Information",
        "@metadata" => {
        "input" => {
            "elasticsearch" => {
                   "_id" => "nX7H_YkBspU4mehKQrcq",
                "_index" => "winlogbeat-6.3.2-2023.08.16",
                 "_type" => "doc"
            }
        }
    },

```

Any idea what I am doing wrong?

---

<div class="post-metadata">

**Author:** ![chouben](https://avatars.discourse-cdn.com/v4/letter/c/e495f1/32.png) [@chouben](https://discuss.elastic.co/u/chouben)\
**Post date:** [August 18, 2023, 9:48am UTC](https://discuss.elastic.co/t/filter-elasticsearch-data-with-logstash/341077/2 "2023-08-18T09:48:12Z")

</div>

Based on your sample provided, I can confirm that event\_id is not an array. So you must use the "==" syntax for the comparison.

cfr. [Accessing event data and fields | Logstash Reference [8.9] | Elastic](https://www.elastic.co/guide/en/logstash/current/event-dependent-configuration.html#conditionals)

---

<div class="post-metadata">

**Author:** ![john.hoogeveen](https://avatars.discourse-cdn.com/v4/letter/j/a9a28c/32.png) [@john.hoogeveen](https://discuss.elastic.co/u/john.hoogeveen)\
**Post date:** [August 18, 2023, 10:01am UTC](https://discuss.elastic.co/t/filter-elasticsearch-data-with-logstash/341077/3 "2023-08-18T10:01:33Z")

</div>

Great, this works as expected

```auto
filter {
  if [event_id] == 4634 {
    mutate { add_tag => "field in field" }
  }
}

```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 15, 2023, 10:02am UTC](https://discuss.elastic.co/t/filter-elasticsearch-data-with-logstash/341077/4 "2023-09-15T10:02:25Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
