# Filtering events by message contents / Custom Processor

**URL:** <https://discuss.elastic.co/t/filtering-events-by-message-contents-custom-processor/64795>\
**Category:** Beats\
**Tags:** winlogbeat\
**Created:** [November 3, 2016, 4:02am UTC](https://discuss.elastic.co/t/filtering-events-by-message-contents-custom-processor/64795 "2016-11-03T04:02:54Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![jojo.pornebo](https://avatars.discourse-cdn.com/v4/letter/j/c57346/32.png) [@jojo.pornebo](https://discuss.elastic.co/u/jojo.pornebo)\
**Post date:** [November 3, 2016, 4:02am UTC](https://discuss.elastic.co/t/filtering-events-by-message-contents-custom-processor/64795/1 "2016-11-03T04:02:54Z")

</div>

I'd like to ask for help on writing a processor configuration to do the following:

- filter on keyword from the event log message (example the application event log message has the word(s)/phrase - "forcibly closed")
- include the event in the output file

Or  
-filter on keyword

- include the event in the output file plus,
- run a powershell script as an extra step it has to do

Can someone give me the actual yml section script for doing this task ?

I could not find more guides for creating filtering/processing scripts for winlogbeat. Please direct me to an online article, ebook or guide to learn more and become an expert in beats/winlogbeats configuration and processing/filtering because we have a huge Windows farm.

Please help. TNX.

Jojo

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [November 3, 2016, 5:12pm UTC](https://discuss.elastic.co/t/filtering-events-by-message-contents-custom-processor/64795/2 "2016-11-03T17:12:57Z")

</div>

Here is the documentation for [`processors`](https://www.elastic.co/guide/en/beats/winlogbeat/5.0/configuration-processors.html).

You can include events based on message content by using the `drop_event` processor with a `regex` condition.

```auto
processors:                                                                                                                                                              
- drop_event.when.not.regexp.message: "forcibly closed" 

```

You cannot execute a script. What did you want to accomplish with the script? We are currently considering a feature that would allow invoking a script to collect additional information that should be added to the event. This feature is discussed here: [https://github.com/elastic/beats/issues/2186](https://github.com/elastic/beats/issues/2186)

You can write your own processor in Go and use it with Beats if you compile your own version of the beat.

---

<div class="post-metadata">

**Author:** ![jojo.pornebo](https://avatars.discourse-cdn.com/v4/letter/j/c57346/32.png) [@jojo.pornebo](https://discuss.elastic.co/u/jojo.pornebo)\
**Post date:** [November 7, 2016, 4:13pm UTC](https://discuss.elastic.co/t/filtering-events-by-message-contents-custom-processor/64795/3 "2016-11-07T16:13:41Z")

</div>

I tried that filter in WinLogBeat - it works.

However, I really wanted to pass all events to a file and at the same time trigger for any special event by keyword. I'm trying to send an alert once there is a mission critical problem and is evident by the presence of an event log entry.  
It seems that I cannot do the filtering/triggering right up-front from the onset of the creation of the event log.

Which part of ELK will be able to do trigger an alarm (like send mail) in an event there is a keyword match ?

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [November 7, 2016, 4:58pm UTC](https://discuss.elastic.co/t/filtering-events-by-message-contents-custom-processor/64795/4 "2016-11-07T16:58:15Z")

</div>

> [@jojo.pornebo](#):
>
> Which part of ELK will be able to do trigger an alarm (like send mail) in an event there is a keyword match?

This is provided by [Watcher](https://www.elastic.co/products/x-pack/alerting) which is part of [X-Pack](https://www.elastic.co/products/x-pack). You can setup a watch that will send an [email](https://www.elastic.co/guide/en/x-pack/current/actions-email.html) (or take some other action) when there is a keyword match. X-pack is free to try, some features require a [subscription](https://www.elastic.co/subscriptions) after the trial period

---

<div class="post-metadata">

**Author:** ![jojo.pornebo](https://avatars.discourse-cdn.com/v4/letter/j/c57346/32.png) [@jojo.pornebo](https://discuss.elastic.co/u/jojo.pornebo)\
**Post date:** [November 7, 2016, 5:21pm UTC](https://discuss.elastic.co/t/filtering-events-by-message-contents-custom-processor/64795/5 "2016-11-07T17:21:17Z")

</div>

> Watcher

That's what I found out too. It's too unfortunate that Windows can trigger events but only based from a an event ID and not from a keyword.

> We are currently considering a feature that would allow invoking a script ...

When will this be available ?

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [November 7, 2016, 6:55pm UTC](https://discuss.elastic.co/t/filtering-events-by-message-contents-custom-processor/64795/6 "2016-11-07T18:55:33Z")

</div>

> [@jojo.pornebo](#):
>
> It's too unfortunate that Windows can trigger events but only based from a an event ID and not from a keyword.

I'm not sure what you mean. What feature in Windows can trigger events (actions?) based on event ID?

> [@jojo.pornebo](#):
>
> When will this be available ?

We don't this feature scheduled in any release yet. It is still being evaluated and considered. It is not a generic processor for execute scripts. It's for adding time-invariant metadata to events.

---

<div class="post-metadata">

**Author:** ![jojo.pornebo](https://avatars.discourse-cdn.com/v4/letter/j/c57346/32.png) [@jojo.pornebo](https://discuss.elastic.co/u/jojo.pornebo)\
**Post date:** [November 7, 2016, 7:10pm UTC](https://discuss.elastic.co/t/filtering-events-by-message-contents-custom-processor/64795/7 "2016-11-07T19:10:25Z")

</div>

In Windows 2012 you can use the " Event Viewer “Attach Task to This Event…” feature to create the task"

> **[Trigger a PowerShell Script from a Windows Event](https://blogs.technet.microsoft.com/wincat/2011/08/25/trigger-a-powershell-script-from-a-windows-event/)**
>
> Note: Portions of this blog are taken from an old blog post titled “Reference the Event That Triggered Your Task” This example will demonstrate both how to trigger (launch) a PowerShell script from a specific Windows Event, AND pass parameters to the...

But filter options does not include by keyword.

![](https://us1.discourse-cdn.com/elastic/original/2X/a/a3bab58e4c3fc3a27a257746cd6ee390ab68d402.png)

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [November 7, 2016, 7:22pm UTC](https://discuss.elastic.co/t/filtering-events-by-message-contents-custom-processor/64795/8 "2016-11-07T19:22:53Z")

</div>

Cool, I have never used that feature. Thanks

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 28, 2016, 7:23pm UTC](https://discuss.elastic.co/t/filtering-events-by-message-contents-custom-processor/64795/9 "2016-11-28T19:23:04Z")

</div>

This topic was automatically closed 21 days after the last reply. New replies are no longer allowed.
