# Filtering rows from a log based in their last status

**URL:** <https://discuss.elastic.co/t/filtering-rows-from-a-log-based-in-their-last-status/232858>\
**Category:** Logstash\
**Created:** [May 15, 2020, 5:14pm UTC](https://discuss.elastic.co/t/filtering-rows-from-a-log-based-in-their-last-status/232858 "2020-05-15T17:14:25Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![ManuelChaverra](https://avatars.discourse-cdn.com/v4/letter/m/b38774/32.png) [@ManuelChaverra](https://discuss.elastic.co/u/ManuelChaverra)\
**Post date:** [May 15, 2020, 5:14pm UTC](https://discuss.elastic.co/t/filtering-rows-from-a-log-based-in-their-last-status/232858/1 "2020-05-15T17:14:26Z")

</div>

Hello everyone, this is my first time using Elastic Stack so I'm trying to learn a lot of things that I'd like to implement in my work.

I'm using Filebeat to send logs files to logstash, then I'm filtering information and sending it to elasticsearch to finally be able to review it in Kibana (So Filebeat \> Logstash \> Elasticsearch \> Kibana)

But I'm have the following problem:  
My log file looks like this:

 ![imagen](https://us1.discourse-cdn.com/elastic/original/3X/a/0/a0a90411f437a40bc2e6d4363bb9ed32aa0f645c.png)

I need to extract the rows corresponding to the last status of each process, for example, if I have the following rows:

05/15/2020 09:10:41|Maquina\_18|RPA202\_Elastic|ElasticLogGenerator.atmx|https://3gjn1nu1.ce.automationanywhere.digital|Info|0 - Proceso finalizado correctamente  
05/15/2020 10:15:27|Maquina\_18|RPA202\_Elastic|ElasticLogGenerator.atmx|https://3gjn1nu1.ce.automationanywhere.digital|Error|574 - Error crítico no controlado  
05/15/2020 09:47:47|Maquina\_5|RPA313\_Elastic|ElasticLogGenerator.atmx|https://3gjn1nu1.ce.automationanywhere.digital|Warning|100 - Error controlado  
05/15/2020 10:07:33|Maquina\_5|RPA313\_Elastic|ElasticLogGenerator.atmx|https://3gjn1nu1.ce.automationanywhere.digital|Info|0 - Proceso finalizado correctamente

I need to return the following since they contain the last status (based on the date) of the process (RPA202 and RPA313 respectively) and ran in the same machine (Maquina\_18 and Maquina\_5 respectively):

05/15/2020 10:15:27|Maquina\_18|RPA202\_Elastic|ElasticLogGenerator.atmx|https://3gjn1nu1.ce.automationanywhere.digital|Error|574 - Error crítico no controlado  
05/15/2020 10:07:33|Maquina\_5|RPA313\_Elastic|ElasticLogGenerator.atmx|https://3gjn1nu1.ce.automationanywhere.digital|Info|0 - Proceso finalizado correctamente

So, to achieve this, I tried a dissect filter in the logstash config file to indicate the pipes as separators and then use Kibana filters to get the information as I need it, but I haven't achieve it.

My configuration file looks like this:

 ![Captura2](https://us1.discourse-cdn.com/elastic/original/3X/f/3/f3b90ff7aed8a814ffc89c17f52cf08c9096acb0.png)

I would appreciate a lot any advice or hint to achieve it

Thanks in advance! I hope I make myself clear because English is not my first language, so I'm sorry If I had any mistake writing this.

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [May 15, 2020, 9:44pm UTC](https://discuss.elastic.co/t/filtering-rows-from-a-log-based-in-their-last-status/232858/2 "2020-05-15T21:44:00Z")

</div>

If you want to do it in logstash (rather than by using an elasticsearch query) then you could use an aggregate filter to determine the last message. See [example 3](https://www.elastic.co/guide/en/logstash/current/plugins-filters-aggregate.html#plugins-filters-aggregate-example3).

Make sure you set pipeline.workers to 1 and [disable java\_execution](https://github.com/elastic/logstash/issues/10938), otherwise events get processed out of order and last is no longer last.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 12, 2020, 9:45pm UTC](https://discuss.elastic.co/t/filtering-rows-from-a-log-based-in-their-last-status/232858/3 "2020-06-12T21:45:57Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
