# How to make filter in beat on the logstash

**URL:** <https://discuss.elastic.co/t/how-to-make-filter-in-beat-on-the-logstash/276992>\
**Category:** Logstash\
**Created:** [June 25, 2021, 12:27am UTC](https://discuss.elastic.co/t/how-to-make-filter-in-beat-on-the-logstash/276992 "2021-06-25T00:27:39Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Juan\_David\_Jaramillo](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/juan_david_jaramillo/32/76831_2.png) [@Juan\_David\_Jaramillo](https://discuss.elastic.co/u/Juan_David_Jaramillo)\
**Post date:** [June 25, 2021, 12:27am UTC](https://discuss.elastic.co/t/how-to-make-filter-in-beat-on-the-logstash/276992/1 "2021-06-25T00:27:39Z")

</div>

Hi, I need to create a filter to avoid duplicating the information that I have from one index to another, in the configuration of the logstash file where the data of the first index that I upload to elastic are, I already made a filter that goes to snmp logstash, but in the other logstash file where the heartbeat data is uploaded to elastic, this in the logstash configuration is in beats, I tried to make a filter for that case but it does not work, I still get the data from the other index to that one, here I show you the index that is uploading data from snmp to the heartbeat index:

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/f/a/fa83e2f04df8ab86d582555ff65767af36359629.png)  
where the red circle is the snmp data that is appearing in my heartbeat data index.

```auto
input {
  beats {
    port => 5022
# add_field => {ping-distrital => "uptime" }
  }
}

filter {
mutate {
   add_field => { "Tipo" => "Ping" }
 }
}

output {
if [Tipo] == "Ping" {
# stdout{ }
  elasticsearch {
    hosts => ["https://xxxxxxxxxxxxxxxxus-central1.gcp.cloud.es.io:9243"]
    user => "elastic"
    password => "xxxxxxxxxxxxxxx"
    index => "agenteallot"
    }
  }
}

```

here I show you the configuration that I have of beats in logstash, where it passes me the heartbeat data through logstash and uploads them to elastic. I look forward to your help and cooperation with this, thanks you... 🙂

---

<div class="post-metadata">

**Author:** ![elasticforme](https://avatars.discourse-cdn.com/v4/letter/e/f05b48/32.png) [@elasticforme](https://discuss.elastic.co/u/elasticforme)\
**Post date:** [June 25, 2021, 2:32am UTC](https://discuss.elastic.co/t/how-to-make-filter-in-beat-on-the-logstash/276992/2 "2021-06-25T02:32:46Z")

</div>

I didn't understand your question quite clearly.

you are saying you are getting data from one logstash to this index agenteallot  
and also getting data from another logstash config to this index agenteallot?

---

<div class="post-metadata">

**Author:** ![Juan\_David\_Jaramillo](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/juan_david_jaramillo/32/76831_2.png) [@Juan\_David\_Jaramillo](https://discuss.elastic.co/u/Juan_David_Jaramillo)\
**Post date:** [June 25, 2021, 1:36pm UTC](https://discuss.elastic.co/t/how-to-make-filter-in-beat-on-the-logstash/276992/3 "2021-06-25T13:36:59Z")

</div>

no, i mean that from logstash i get the data from heartbeat, logstash only uploads it to an index in kibana. so i need help to make a filter.

---

<div class="post-metadata">

**Author:** ![elasticforme](https://avatars.discourse-cdn.com/v4/letter/e/f05b48/32.png) [@elasticforme](https://discuss.elastic.co/u/elasticforme)\
**Post date:** [June 25, 2021, 2:48pm UTC](https://discuss.elastic.co/t/how-to-make-filter-in-beat-on-the-logstash/276992/4 "2021-06-25T14:48:04Z")

</div>

still please explain  
heartbeat sends data to logstash and logstash creates two entry?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 23, 2021, 4:49pm UTC](https://discuss.elastic.co/t/how-to-make-filter-in-beat-on-the-logstash/276992/5 "2021-07-23T16:49:01Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
