# How create a filter to my rails log?

**URL:** <https://discuss.elastic.co/t/how-create-a-filter-to-my-rails-log/43905>\
**Category:** Kibana\
**Created:** [March 9, 2016, 2:30pm UTC](https://discuss.elastic.co/t/how-create-a-filter-to-my-rails-log/43905 "2016-03-09T14:30:05Z")\
**Posts on this page:** 11\
**Page:** 1

<div class="post-metadata">

**Author:** ![Candido\_Sales\_Gomes](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/candido_sales_gomes/32/8125_2.png) [@Candido\_Sales\_Gomes](https://discuss.elastic.co/u/Candido_Sales_Gomes)\
**Post date:** [March 9, 2016, 2:30pm UTC](https://discuss.elastic.co/t/how-create-a-filter-to-my-rails-log/43905/1 "2016-03-09T14:30:05Z")

</div>

My stack is using Lograge (Gem) -\> Filebeat -\> Logstash -\> Elastic -\> KIbana.

Elastic is indexing this in format:

`{ "_index": "filebeat-2016.03.09", "_type": "log", "_id": "AVNbq1ImHUX-l-CtdIqR", "_score": null, "_source": { "message": "{\"method\":\"GET\",\"path\":\"/extract_json\",\"format\":\"html\",\"controller\":\"extracts\",\"action\":\"show_json\",\"status\":200,\"duration\":12809.6,\"view\":0.11,\"db\":22.38,\"params\":{},\"env\":\"development\",\"mdc\":\"33bcbbeb896379c07f309024e1a9c810\",\"host\":\"localhost\",\"@timestamp\":\"2016-03-09T13:57:41.119Z\",\"@version\":\"1\",\"message\":\"[200] GET /extract_json (extracts#show_json)\"}", "@version": "1", "@timestamp": "2016-03-09T13:57:42.550Z", "beat": { "hostname": "brasilct-Aspire-E5-573G", "name": "brasilct-Aspire-E5-573G" }, "count": 1, "fields": { "origin": "development", "technology": "Ruby on Rails" }, "input_type": "log", "offset": 67638, "source": "/home/brasilct/dev/ruby-projects/bonusesfera/log/lograge_development.log", "type": "log", "host": "brasilct-Aspire-E5-573G", "tags": ["beats_input_codec_plain_applied"] }, "fields": { "@timestamp": [1457531862550] }, "sort": [1457531862550] }`

However I do not want that "message" to be a string.

How do I make the field "message" in searchable fields, which are not strings? Where should I set up? Are the filters of Logstash or need to add some configuration in filebeat.yml?

---

<div class="post-metadata">

**Author:** ![Candido\_Sales\_Gomes](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/candido_sales_gomes/32/8125_2.png) [@Candido\_Sales\_Gomes](https://discuss.elastic.co/u/Candido_Sales_Gomes)\
**Post date:** [March 9, 2016, 3:18pm UTC](https://discuss.elastic.co/t/how-create-a-filter-to-my-rails-log/43905/2 "2016-03-09T15:18:47Z")

</div>

I solved stopped filebeat service and reconfigured logstash.conf like above:

input {  
file {  
type =\> "rails"  
path =\> ["/home/brasilct/dev/ruby-projects/bonusesfera/log/lograge\_development.log"]  
codec =\> json {  
charset =\> "UTF-8"  
}  
}  
}  
filter{  
grok{  
match =\> [  
"message",  
"Started %{WORD:method} (?[^]+) for.\*%{IP:ip} at %{TIMESTAMP\_ISO8601:time}"  
]  
}  
}  
output {  
stdout {  
codec =\> rubydebug  
}  
elasticsearch {  
hosts =\> ["localhost:9200"]  
}  
}

Now as the Elastic indexes my log:

{  
"\_index": "logstash-2016.03.09",  
"\_type": "rails",  
"\_id": "AVNb61syHUX-l-CtdIqZ",  
"\_score": null,  
"\_source": {  
"method": "GET",  
"path": "/extract\_json",  
"format": "html",  
"controller": "extracts",  
"action": "show\_json",  
"status": 200,  
"duration": 11923.5,  
"view": 0.41,  
"db": 228.28,  
"params": {},  
"env": "development",  
"mdc": "649326dc6cda3247c2dcc1c10531822b",  
"host": "localhost",  
"@timestamp": "2016-03-09T15:07:43.614Z",  
"@version": "1",  
"message": "[200] GET /extract\_json (extracts#show\_json)",  
"type": "rails",  
"tags": [  
"\_grokparsefailure"  
]  
},  
"fields": {  
"@timestamp": [  
1457536063614  
]  
},  
"sort": [  
1457536063614  
]  
}

But still I want to set the filebeat.

Anyone can me help?

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [March 9, 2016, 3:42pm UTC](https://discuss.elastic.co/t/how-create-a-filter-to-my-rails-log/43905/3 "2016-03-09T15:42:25Z")

</div>

> But still I want to set the filebeat.

You mean use Filebeat instead of Logstash? Use the json codec for the beats input just like you did with the file input.

---

<div class="post-metadata">

**Author:** ![Candido\_Sales\_Gomes](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/candido_sales_gomes/32/8125_2.png) [@Candido\_Sales\_Gomes](https://discuss.elastic.co/u/Candido_Sales_Gomes)\
**Post date:** [March 9, 2016, 5:52pm UTC](https://discuss.elastic.co/t/how-create-a-filter-to-my-rails-log/43905/4 "2016-03-09T17:52:04Z")

</div>

Do you say change logstash configuration as below? (Sorry for my english)

input {  
beats {  
port =\> 5044  
codec =\> json {  
charset =\> "UTF-8"  
}  
}  
}

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [March 9, 2016, 8:13pm UTC](https://discuss.elastic.co/t/how-create-a-filter-to-my-rails-log/43905/5 "2016-03-09T20:13:50Z")

</div>

Yes, that should work (assuming all messages sent to that port are JSON).

---

<div class="post-metadata">

**Author:** ![Candido\_Sales\_Gomes](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/candido_sales_gomes/32/8125_2.png) [@Candido\_Sales\_Gomes](https://discuss.elastic.co/u/Candido_Sales_Gomes)\
**Post date:** [March 9, 2016, 8:21pm UTC](https://discuss.elastic.co/t/how-create-a-filter-to-my-rails-log/43905/6 "2016-03-09T20:21:40Z")

</div>

Great, it's working! Thanks! 😄

---

<div class="post-metadata">

**Author:** ![Candido\_Sales\_Gomes](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/candido_sales_gomes/32/8125_2.png) [@Candido\_Sales\_Gomes](https://discuss.elastic.co/u/Candido_Sales_Gomes)\
**Post date:** [March 10, 2016, 2:33pm UTC](https://discuss.elastic.co/t/how-create-a-filter-to-my-rails-log/43905/7 "2016-03-10T14:33:33Z")

</div>

@magnusbaeck How to configure logstash which have two inputs, one with json codec for rails logs and other without codec for topbeat or packetbeat logs?

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [March 10, 2016, 5:54pm UTC](https://discuss.elastic.co/t/how-create-a-filter-to-my-rails-log/43905/8 "2016-03-10T17:54:00Z")

</div>

Use two beats inputs with different ports and different codec settings.

---

<div class="post-metadata">

**Author:** ![Candido\_Sales\_Gomes](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/candido_sales_gomes/32/8125_2.png) [@Candido\_Sales\_Gomes](https://discuss.elastic.co/u/Candido_Sales_Gomes)\
**Post date:** [March 14, 2016, 3:16pm UTC](https://discuss.elastic.co/t/how-create-a-filter-to-my-rails-log/43905/9 "2016-03-14T15:16:36Z")

</div>

> [@Candido\_Sales\_Gomes](#):
>
> input { beats { port =\> 5044 codec =\> json { charset =\> "UTF-8" } }}

input {  
beats {  
port =\> 5044  
codec =\> json {  
charset =\> "UTF-8"  
}  
}  
}

input {  
beats {  
port =\> 5045  
}  
}

But how do I configure the "filebeat.yml" that there will be two outputs in logstash one on port 5044 and another 5045?

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [March 14, 2016, 6:35pm UTC](https://discuss.elastic.co/t/how-create-a-filter-to-my-rails-log/43905/10 "2016-03-14T18:35:24Z")

</div>

That's a good point. I'm not sure you can do that. You might want to start a new thread in the Filebeat category to get the attention of the Filebeat experts.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 1:59pm UTC](https://discuss.elastic.co/t/how-create-a-filter-to-my-rails-log/43905/11 "2017-07-06T13:59:10Z")

</div>


