# Function from filter block

**URL:** <https://discuss.elastic.co/t/function-from-filter-block/277547>\
**Category:** Logstash\
**Tags:** elastic-stack-alerting\
**Created:** [July 1, 2021, 11:46am UTC](https://discuss.elastic.co/t/function-from-filter-block/277547 "2021-07-01T11:46:10Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![Velly](https://avatars.discourse-cdn.com/v4/letter/v/f04885/32.png) [@Velly](https://discuss.elastic.co/u/Velly)\
**Post date:** [July 1, 2021, 11:46am UTC](https://discuss.elastic.co/t/function-from-filter-block/277547/1 "2021-07-01T11:46:10Z")

</div>

Hello!  
I am a new user of ELK. I am trying to understand how works SIEM parser «1».  
In filter block I see:  
filter {  
load\_source\_mapper\_filters(mcsevt).

Mcs is service of agent that picks up Windows logs.  
I don’t understand what it is load\_source\_mapper\_filters. Where it can be? I don’t see some headers or include libraries in parser «1».  
Maybe there is some kind of built-in library of functions from where parsers can deliver information. Or maybe there is some library of user-defined functions.  
I didn't find a description in the official manual.  
Please, please help.  
Valentina.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 29, 2021, 11:46am UTC](https://discuss.elastic.co/t/function-from-filter-block/277547/2 "2021-07-29T11:46:41Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
