# From FileBeat to Logstash

**URL:** https://discuss.elastic.co/t/from-filebeat-to-logstash/276095
**Category:** Logstash
**Tags:** docker
**Created:** [June 16, 2021, 7:54am UTC](https://discuss.elastic.co/t/from-filebeat-to-logstash/276095 "2021-06-16T07:54:49Z")
**Posts on this page:** 3
**Page:** 1

<div class="post-metadata">

### Author: ![Michael\_Dylan\_McAloo](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/michael_dylan_mcaloo/32/80928_2.png) [@Michael\_Dylan\_McAloo](https://discuss.elastic.co/u/Michael_Dylan_McAloo)
#### Post date: [June 16, 2021, 7:54am UTC](https://discuss.elastic.co/t/from-filebeat-to-logstash/276095/1 "2021-06-16T07:54:49Z")

</div>

I have a dissect with filebeat, functional, but I need to pass it to logstash and I don't know how to use that same function in Logstash.  
Code:

```auto
  processors:
    - dissect:
        tokenizer: '%{timestamp} [%{trash}] [%{ip}] "%{alert}" [%{extra}} %{ip_ori}:%{port_ori} %{trash2} %{ip_dest}:%{port_dest}'

```

---

<div class="post-metadata">

### Author: ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)
#### Post date: [June 16, 2021, 4:44pm UTC](https://discuss.elastic.co/t/from-filebeat-to-logstash/276095/2 "2021-06-16T16:44:46Z")

</div>

You can do something similar in logstash using a [dissect](https://www.elastic.co/guide/en/logstash/current/plugins-filters-dissect.html) filter.

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [July 14, 2021, 4:45pm UTC](https://discuss.elastic.co/t/from-filebeat-to-logstash/276095/3 "2021-07-14T16:45:16Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
