# How can Filebeat send match rules to Logstash

**URL:** <https://discuss.elastic.co/t/how-can-filebeat-send-match-rules-to-logstash/176814>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [April 15, 2019, 3:15am UTC](https://discuss.elastic.co/t/how-can-filebeat-send-match-rules-to-logstash/176814 "2019-04-15T03:15:10Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Gary.Pan](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/gary.pan/32/44295_2.png) [@Gary.Pan](https://discuss.elastic.co/u/Gary.Pan)\
**Post date:** [April 15, 2019, 3:15am UTC](https://discuss.elastic.co/t/how-can-filebeat-send-match-rules-to-logstash/176814/1 "2019-04-15T03:15:11Z")

</div>

I want to let Logstash'gork filter use the match rules which Filebeat give

Here is my Filebeat config:

```
filebeat.inputs:
- type: log
  enabled: true
  paths:
    - /root/Log-test/test.log
  fields:
    "@metadata":
        formatter: "%{TIMESTAMP_ISO8601:timestamp} - %{NOTSPACE:module} - %{LOGLEVEL:level} - %{NOTSPACE:filename} - %{GREEDYDATA:log_message}"
  fields_under_root: true

output.logstash:
  hosts: ["localhost:5045"]

```

Here is my Logstash config:

```
input {
    beats {
        port => "5045"
    }
}

filter {
  grok {
    match => { "message" => "%{[@metadata][formatter]}" }
  }
}

output {
  file {
    path => "/tmp/log-test.log"
    codec => rubydebug { metadata => true }
  }
}

```

So, i want the grok know my match rules content (the `message` field) is `"%{TIMESTAMP_ISO8601:timestamp} - %{NOTSPACE:module} - %{LOGLEVEL:level} - %{NOTSPACE:filename} - %{GREEDYDATA:log_message}"`

But the setting above do not work, I want to know how can i implement the funciton like this? or is it possible to make it?

Thanks!

---

<div class="post-metadata">

**Author:** ![jsoriano](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jsoriano/32/27920_2.png) [@jsoriano](https://discuss.elastic.co/u/jsoriano)\
**Post date:** [April 16, 2019, 9:12am UTC](https://discuss.elastic.co/t/how-can-filebeat-send-match-rules-to-logstash/176814/2 "2019-04-16T09:12:31Z")

</div>

Hi @Gary.Pan and welcome 🙂

This is not possible, because grok patterns are compiled on start time, so this field is not going to be read when events are being processed.

You should be able to parse this data by using an ingest node pipeline: [https://www.elastic.co/guide/en/beats/filebeat/7.0/configuring-ingest-node.html](https://www.elastic.co/guide/en/beats/filebeat/7.0/configuring-ingest-node.html)

---

<div class="post-metadata">

**Author:** ![Gary.Pan](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/gary.pan/32/44295_2.png) [@Gary.Pan](https://discuss.elastic.co/u/Gary.Pan)\
**Post date:** [April 23, 2019, 7:45am UTC](https://discuss.elastic.co/t/how-can-filebeat-send-match-rules-to-logstash/176814/3 "2019-04-23T07:45:33Z")

</div>

Get it, thanks!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 21, 2019, 7:45am UTC](https://discuss.elastic.co/t/how-can-filebeat-send-match-rules-to-logstash/176814/4 "2019-05-21T07:45:34Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
