# Help with logstash output

**URL:** <https://discuss.elastic.co/t/help-with-logstash-output/309011>\
**Category:** Logstash\
**Created:** [July 6, 2022, 12:46pm UTC](https://discuss.elastic.co/t/help-with-logstash-output/309011 "2022-07-06T12:46:56Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![PJss](https://avatars.discourse-cdn.com/v4/letter/p/c0e974/32.png) [@PJss](https://discuss.elastic.co/u/PJss)\
**Post date:** [July 6, 2022, 12:46pm UTC](https://discuss.elastic.co/t/help-with-logstash-output/309011/1 "2022-07-06T12:46:56Z")

</div>

Hello I'm getting ELK running node in command, that i don't configure, and this string below goes to arcsight:

**2022-07-04T12:50:30.046Z {name=TST-FT13}** Jul 4 15:50:29 TST-FT13 sshd[1872]: Accepted keyboard-interactive/pam for root from 192.168.11.11 port 58293 ssh2

Now they ask me to remove part that i marked with bold. I`m trying some remove\_field variants in filter config, but it not help, please help to find solution.

```auto
           udp {
              id => "arcsight_line"
              host => "192.168.99.99"
              port => 714
              codec => "line"
              }

```

---

<div class="post-metadata">

**Author:** ![Rios](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rios/32/95745_2.png) [@Rios](https://discuss.elastic.co/u/Rios)\
**Post date:** [July 6, 2022, 1:51pm UTC](https://discuss.elastic.co/t/help-with-logstash-output/309011/2 "2022-07-06T13:51:30Z")

</div>

What are you using to parse this line? Grok?

---

<div class="post-metadata">

**Author:** ![PJss](https://avatars.discourse-cdn.com/v4/letter/p/c0e974/32.png) [@PJss](https://discuss.elastic.co/u/PJss)\
**Post date:** [July 7, 2022, 8:13am UTC](https://discuss.elastic.co/t/help-with-logstash-output/309011/4 "2022-07-07T08:13:31Z")

</div>

Hello again, I manage to get some progress, I removed unwanted date and host info with this filter:

```auto
filter {

  clone {
    clones => ["cloned"]
  }

  if [type] == 'cloned' {
    mutate {
      add_field => { "[@metadata][type]" => "cloned" }
    remove_field => ["host", "@timestamp"]
    }
}

```

but, now I got these sign in output, can anybody say how to remove bolded part

**%{host}** Jul 7 10:52:15 PC-30PU sudo: pam\_unix(sudo:auth): conversation failed

---

<div class="post-metadata">

**Author:** ![PJss](https://avatars.discourse-cdn.com/v4/letter/p/c0e974/32.png) [@PJss](https://discuss.elastic.co/u/PJss)\
**Post date:** [July 7, 2022, 12:03pm UTC](https://discuss.elastic.co/t/help-with-logstash-output/309011/5 "2022-07-07T12:03:55Z")

</div>

Solved my problem with this strings.

```auto
    mutate {
      add_field => { "[@metadata][type]" => "cloned" }
      replace => { "host" => "" }
    remove_field => ["@timestamp"]

```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 4, 2022, 12:04pm UTC](https://discuss.elastic.co/t/help-with-logstash-output/309011/6 "2022-08-04T12:04:34Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
