# How to access the value in the logstash metadata

**URL:** <https://discuss.elastic.co/t/how-to-access-the-value-in-the-logstash-metadata/157200>\
**Category:** Logstash\
**Created:** [November 18, 2018, 1:59am UTC](https://discuss.elastic.co/t/how-to-access-the-value-in-the-logstash-metadata/157200 "2018-11-18T01:59:48Z")\
**Posts on this page:** 16\
**Page:** 1

<div class="post-metadata">

**Author:** ![bijay](https://avatars.discourse-cdn.com/v4/letter/b/8491ac/32.png) [@bijay](https://discuss.elastic.co/u/bijay)\
**Post date:** [November 18, 2018, 1:59am UTC](https://discuss.elastic.co/t/how-to-access-the-value-in-the-logstash-metadata/157200/1 "2018-11-18T01:59:48Z")

</div>

Hi,

I want to access the value of the dictionary in the metadata dynamically. How can I do that in logstash filter section?

e.g.

```auto
    if [@metadata][key] == "test" {
        <some action>
    }

```

Thanks  
Bijay

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [November 19, 2018, 7:29am UTC](https://discuss.elastic.co/t/how-to-access-the-value-in-the-logstash-metadata/157200/2 "2018-11-19T07:29:42Z")

</div>

Something like this?

```auto
input {
  generator {
    lines => ['message1']
    count => 1
    add_field => { "[@metadata][key]" => "test" }
  }
}

filter {
  if [@metadata][key] == "test" {
    mutate {
      add_tag => ["found"]
    }
  }
}

output {
  stdout { codec => rubydebug { metadata => true }}
}

```

---

<div class="post-metadata">

**Author:** ![bijay](https://avatars.discourse-cdn.com/v4/letter/b/8491ac/32.png) [@bijay](https://discuss.elastic.co/u/bijay)\
**Post date:** [November 19, 2018, 8:15am UTC](https://discuss.elastic.co/t/how-to-access-the-value-in-the-logstash-metadata/157200/3 "2018-11-19T08:15:12Z")

</div>

Thanks for the reply Christian.

I want to explain little bit more on that.

This is my input logline (for testing only I have used stdin and stdout) and I want to get the value of the first key dynamically.

[severity\_type][severity] can be anything, e.g. [severity\_type][info] or [severity\_type][debug] or [severity\_type][warning]

```auto
input {
    stdin { codec => json }
}
filter {
    
# if [severity_type][info] == "drop" {
# drop { }
# }

# if [severity_type][**KEY**] == "drop" {
# drop { }
# }

}
output {
    stdout { codec => rubydebug
      { metadata => true }
    }
}

```

## Input loglines

{"nodetype":"haproxy","ssinst":"001","component":"kafka","severity":"info","logsource":"log"}

{"nodetype":"haproxy","ssinst":"001","component":"logstash","severity":"info","logsource":"log"}

{"nodetype":"haproxy","ssinst":"001","component":"logstash","logsource":"log"}

{"nodetype":"haproxy","ssinst":"001","logsource":"log"}

---

<div class="post-metadata">

**Author:** ![bijay](https://avatars.discourse-cdn.com/v4/letter/b/8491ac/32.png) [@bijay](https://discuss.elastic.co/u/bijay)\
**Post date:** [November 19, 2018, 8:20am UTC](https://discuss.elastic.co/t/how-to-access-the-value-in-the-logstash-metadata/157200/4 "2018-11-19T08:20:43Z")

</div>

Works fine when I have the config like this, but I want to get the field value of the severity\_type dynamically. I meant first field value.

```auto
input {
    stdin { codec => json }
}
filter {
    
    translate {
        field => "component"
        destination => "logstat"
        dictionary_path => "/tmp/logdrop.yml"
    }
    json {
        source => "logstat"
        target => "severity_type"
    }

    if [severity_type][info] == "drop" {
        drop { }
    }

}
output {
    stdout { codec => rubydebug
      { metadata => true }
    }
}

```

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [November 19, 2018, 8:25am UTC](https://discuss.elastic.co/t/how-to-access-the-value-in-the-logstash-metadata/157200/5 "2018-11-19T08:25:09Z")

</div>

I do not understand your example. can you please clarify? The field name definition can as far as I know not be dynamic.

---

<div class="post-metadata">

**Author:** ![bijay](https://avatars.discourse-cdn.com/v4/letter/b/8491ac/32.png) [@bijay](https://discuss.elastic.co/u/bijay)\
**Post date:** [November 19, 2018, 8:29am UTC](https://discuss.elastic.co/t/how-to-access-the-value-in-the-logstash-metadata/157200/6 "2018-11-19T08:29:32Z")

</div>

Ohh, ok. Is there any work around to get the field name definition dynamic? Like in an array it can be done sometime like [arr][0] or [arr.0]

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [November 19, 2018, 8:30am UTC](https://discuss.elastic.co/t/how-to-access-the-value-in-the-logstash-metadata/157200/7 "2018-11-19T08:30:03Z")

</div>

I suspect you may need to use a ruby filter for that.

---

<div class="post-metadata">

**Author:** ![bijay](https://avatars.discourse-cdn.com/v4/letter/b/8491ac/32.png) [@bijay](https://discuss.elastic.co/u/bijay)\
**Post date:** [November 19, 2018, 8:33am UTC](https://discuss.elastic.co/t/how-to-access-the-value-in-the-logstash-metadata/157200/8 "2018-11-19T08:33:28Z")

</div>

I don't much knowledge about the ruby code. Would you please help me?

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [November 19, 2018, 8:38am UTC](https://discuss.elastic.co/t/how-to-access-the-value-in-the-logstash-metadata/157200/9 "2018-11-19T08:38:09Z")

</div>

I still do not understand your example. If possible I would probably recommend restructuring your data instead to avoid having to do this. The Ruby filter is unfortunately not something I have used to any great extent, so will not be able to help you there...

---

<div class="post-metadata">

**Author:** ![bijay](https://avatars.discourse-cdn.com/v4/letter/b/8491ac/32.png) [@bijay](https://discuss.elastic.co/u/bijay)\
**Post date:** [November 19, 2018, 8:41am UTC](https://discuss.elastic.co/t/how-to-access-the-value-in-the-logstash-metadata/157200/10 "2018-11-19T08:41:25Z")

</div>

I want to drop the logs based on the severity type by updating the dictionary path.

```auto
input {
    stdin { codec => json }
}
filter {
    
    translate {
        field => "component"
        destination => "logstat"
        dictionary_path => "/tmp/logdrop.yml"
    }
    json {
        source => "logstat"
        target => "severity_type"
    }

    if [severity_type][info] == "drop" {
        drop { }
    }

}
output {
    stdout { codec => rubydebug
      { metadata => true }
    }
}

```

This is the /tmp/logdrop.yml

```auto
sh-4.2# cat /tmp/logdrop.yml
---
logstash: '{"info":"drop"}

```

---

<div class="post-metadata">

**Author:** ![bijay](https://avatars.discourse-cdn.com/v4/letter/b/8491ac/32.png) [@bijay](https://discuss.elastic.co/u/bijay)\
**Post date:** [November 19, 2018, 8:49am UTC](https://discuss.elastic.co/t/how-to-access-the-value-in-the-logstash-metadata/157200/11 "2018-11-19T08:49:34Z")

</div>

I have another open thread related to this.

> [@Logstash translate filter for multiple fields](https://discuss.elastic.co/t/logstash-translate-filter-for-multiple-fields/156812):
>
> Hi, I want to drop the logs based on multiple fields. Below is the content of drop.yml logstash : '{"info": "drop"}' e.g. I want to drop the loglines which has contain the "component" : "logstash" and "severity": "info" I want to do this dynamically. translate { field =\> "component" destination =\> "logstat" dictionary\_path =\> "/tmp/drop.yml" } json { source =\> "logstat" target =\> "severity" } if [target] == "drop" { drop {…

---

<div class="post-metadata">

**Author:** ![bijay](https://avatars.discourse-cdn.com/v4/letter/b/8491ac/32.png) [@bijay](https://discuss.elastic.co/u/bijay)\
**Post date:** [November 19, 2018, 10:08am UTC](https://discuss.elastic.co/t/how-to-access-the-value-in-the-logstash-metadata/157200/12 "2018-11-19T10:08:52Z")

</div>

Any suggestions on this Christian?

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [November 19, 2018, 10:11am UTC](https://discuss.elastic.co/t/how-to-access-the-value-in-the-logstash-metadata/157200/13 "2018-11-19T10:11:18Z")

</div>

Please do not open multiple threads for the same problem. I still do not understand what you are trying to do and why you need dynamic field names, so do not have any suggestions at this time.

---

<div class="post-metadata">

**Author:** ![bijay](https://avatars.discourse-cdn.com/v4/letter/b/8491ac/32.png) [@bijay](https://discuss.elastic.co/u/bijay)\
**Post date:** [November 19, 2018, 10:20am UTC](https://discuss.elastic.co/t/how-to-access-the-value-in-the-logstash-metadata/157200/14 "2018-11-19T10:20:07Z")

</div>

Both are not exactly the same issue though they are related. In the other thread I wanted to get some suggestion on how to proceed and in this thread I have sought help on the generic thing, i.e. getting dynamic field names.

---

<div class="post-metadata">

**Author:** ![bijay](https://avatars.discourse-cdn.com/v4/letter/b/8491ac/32.png) [@bijay](https://discuss.elastic.co/u/bijay)\
**Post date:** [November 19, 2018, 3:42pm UTC](https://discuss.elastic.co/t/how-to-access-the-value-in-the-logstash-metadata/157200/15 "2018-11-19T15:42:40Z")

</div>

Is it possible to get the value based on the position of the parameter? Something similar as below (this doesn't work):

```auto
if [severity_type.index][0] == "drop" {
        drop { }
    }

```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 17, 2018, 3:42pm UTC](https://discuss.elastic.co/t/how-to-access-the-value-in-the-logstash-metadata/157200/16 "2018-12-17T15:42:46Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
