# How to filter out kernel messages by logstash?

**URL:** <https://discuss.elastic.co/t/how-to-filter-out-kernel-messages-by-logstash/160746>\
**Category:** Logstash\
**Created:** [December 13, 2018, 1:31pm UTC](https://discuss.elastic.co/t/how-to-filter-out-kernel-messages-by-logstash/160746 "2018-12-13T13:31:50Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![rishi\_shah](https://avatars.discourse-cdn.com/v4/letter/r/ea666f/32.png) [@rishi\_shah](https://discuss.elastic.co/u/rishi_shah)\
**Post date:** [December 13, 2018, 1:31pm UTC](https://discuss.elastic.co/t/how-to-filter-out-kernel-messages-by-logstash/160746/1 "2018-12-13T13:31:51Z")

</div>

I am using following logstash config to monitor our user SSH events on remote machines. I am using filebeat to send syslogs from all the servers to our ELK server. I only want user events. I want to ignore all networking and other kernel messages. How can I do that?

```
input {
	beats {
          port => 5044
          ssl => true
          ssl_certificate => "/etc/pki/tls/certs/logstash-forwarder.crt"
          ssl_key => "/etc/pki/tls/private/logstash-forwarder.key"
  	}
}

## Add your filters / logstash plugins configuration here
filter {
  	if [type] == "syslog" {
    	grok {
      		match => { "message" => "%{SYSLOGTIMESTAMP:syslog_timestamp} %{SYSLOGHOST:syslog_hostname} %{DATA:syslog_program}(?:\[%{POSINT:syslog_pid}\])?: %{GREEDYDATA:syslog_message}" }
      		add_field => ["received_at", "%{@timestamp}"]
      		add_field => ["received_from", "%{host}"]
    	}
    	syslog_pri { }
    	date {
      		match => ["syslog_timestamp", "MMM d HH:mm:ss", "MMM dd HH:mm:ss"]
    	}
    }
}

output {
	elasticsearch {
		hosts => "127.0.0.1:9200"
		sniffing => true
    	manage_template => false
    	index => "%{[@metadata][beat]}-%{+YYYY.MM.dd}"
    	document_type => "%{[@metadata][type]}"
	}
}
```

---

<div class="post-metadata">

**Author:** ![NerdSec](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nerdsec/32/22056_2.png) [@NerdSec](https://discuss.elastic.co/u/NerdSec)\
**Post date:** [December 14, 2018, 5:21am UTC](https://discuss.elastic.co/t/how-to-filter-out-kernel-messages-by-logstash/160746/2 "2018-12-14T05:21:05Z")

</div>

Hi Rishi,

What is the error or problem? How are you filtering the data you don't need?

---

<div class="post-metadata">

**Author:** ![rishi\_shah](https://avatars.discourse-cdn.com/v4/letter/r/ea666f/32.png) [@rishi\_shah](https://discuss.elastic.co/u/rishi_shah)\
**Post date:** [December 14, 2018, 7:48am UTC](https://discuss.elastic.co/t/how-to-filter-out-kernel-messages-by-logstash/160746/3 "2018-12-14T07:48:35Z")

</div>

Hi Nachiket,

There is no as such error. But there is too much data. I don't want kernel or other networking messages. I want only user informations i.e. when user logged in or which commands they ran etc.

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [December 14, 2018, 7:53am UTC](https://discuss.elastic.co/t/how-to-filter-out-kernel-messages-by-logstash/160746/4 "2018-12-14T07:53:52Z")

</div>

If you want to drop events and not have them sent on, you can use the [Logstash drop filter](https://www.elastic.co/guide/en/logstash/current/plugins-filters-drop.html) together with appropriate conditionals.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 11, 2019, 7:53am UTC](https://discuss.elastic.co/t/how-to-filter-out-kernel-messages-by-logstash/160746/5 "2019-01-11T07:53:54Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
