# How to process/filter output from SNMP input plugin for logstash

**URL:** <https://discuss.elastic.co/t/how-to-process-filter-output-from-snmp-input-plugin-for-logstash/239549>\
**Category:** Logstash\
**Created:** [July 1, 2020, 10:43pm UTC](https://discuss.elastic.co/t/how-to-process-filter-output-from-snmp-input-plugin-for-logstash/239549 "2020-07-01T22:43:50Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![gasparuben](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/gasparuben/32/50393_2.png) [@gasparuben](https://discuss.elastic.co/u/gasparuben)\
**Post date:** [July 1, 2020, 10:43pm UTC](https://discuss.elastic.co/t/how-to-process-filter-output-from-snmp-input-plugin-for-logstash/239549/1 "2020-07-01T22:43:50Z")

</div>

hi, I am retrieving SNMP data from our webcast servers. I would like to know how to process the results in a filter stage in logstash e.g

```auto
    {
          "httpClientCountGetUserQueryStr.1.1.1.1.3" => "liveoutside/smil:1234_camera_all.smil/playlist.m3u8",
                                          "@version" => "1",
        "httpClientCountGetUserQueryStr.1.1.1.1.144" => "liveoutside/1234_camera_720p/playlist.m3u8",
                                            "fields" => {
            "document_type" => "wowzasnmp"
        },
          "httpClientCountGetIsFirstChunk.1.1.1.1.3" => "118.185.62.42",
                                        "@timestamp" => 2020-07-01T22:28:48.704Z,
        "httpClientCountGetIsFirstChunk.1.1.1.1.144" => "118.141.203.207"
    }

```

I could have a big number of httpClientCountGetIsFirstChunk & httpClientCountGetUserQueryStr not always in a 1 to 1 relationship as a client could demand several streams from the server.

Just for completeness this is how I collect data:

```auto
    input {
            snmp {
                     walk => [".1.3.6.1.4.1.46706.100.70.1.1.1.5",".1.3.6.1.4.1.46706.100.70.1.1.1.28"]
                     hosts => [{host => "udp:wowzaqa.domain.com/1611" community => "public" version => "2c" retries => 2 timeout => 1000}]
                     mib_paths => ["/usr/share/snmp/mibs/WOWZASTREAMINGENGINE.dic"]
                     oid_path_length => 6
                     add_field => {"[fields][document_type]" => "wowzasnmp"}
            }
    }

```

Thank you

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [July 1, 2020, 10:59pm UTC](https://discuss.elastic.co/t/how-to-process-filter-output-from-snmp-input-plugin-for-logstash/239549/2 "2020-07-01T22:59:49Z")

</div>

> [@gasparuben](#):
>
> I would like to know how to process the results in a filter stage in logstash

That really depends on what output you want.

---

<div class="post-metadata">

**Author:** ![gasparuben](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/gasparuben/32/50393_2.png) [@gasparuben](https://discuss.elastic.co/u/gasparuben)\
**Post date:** [July 2, 2020, 8:01am UTC](https://discuss.elastic.co/t/how-to-process-filter-output-from-snmp-input-plugin-for-logstash/239549/3 "2020-07-02T08:01:26Z")

</div>

Indeed I didnt explain. What I need to do is to parse the streams and get for example: for `liveoutside/1234_camera_720p/playlist.m3u8` two fields `appname: liveoutside` and `streamname:1234_camera`. Then I need to group the different IP's that are connected to each pair `streamname` and `appname`. In the example it would be 2 IP for just one pair. But I could have a variety of results e.g.

```auto
{
                                      "@version" => "1",
    "httpClientCountGetIsFirstChunk.1.1.1.1.158" => "188.189.117.200",
    "httpClientCountGetUserQueryStr.1.1.1.1.155" => "liveoutside/smil:1234_camera_all.smil/playlist.m3u8",
    "httpClientCountGetUserQueryStr.1.1.1.1.158" => "liveoutside/smil:1234_camera_all.smil/playlist.m3u8",
                                        "fields" => {
        "document_type" => "wowzasnmp"
    },
    "httpClientCountGetIsFirstChunk.1.1.1.1.159" => "188.189.117.200",
      "httpClientCountGetIsFirstChunk.1.1.1.1.3" => "188.189.64.42",
    "httpClientCountGetIsFirstChunk.1.1.1.1.155" => "188.189.117.200",
                                    "@timestamp" => 2020-07-01T22:31:48.773Z,
    "httpClientCountGetIsFirstChunk.1.1.1.1.157" => "188.189.117.200",
      "httpClientCountGetUserQueryStr.1.1.1.1.3" => "liveoutside/smil:1234_camera_all.smil/playlist.m3u8",
    "httpClientCountGetIsFirstChunk.1.1.1.1.156" => "188.189.117.200",
    "httpClientCountGetUserQueryStr.1.1.1.1.156" => "liveoutside/smil:1234_camera_all.smil/playlist.m3u8",
    "httpClientCountGetUserQueryStr.1.1.1.1.144" => "liveoutside/1234_camera_720p/playlist.m3u8",
    "httpClientCountGetUserQueryStr.1.1.1.1.159" => "liveoutside/smil:1234_camera_all.smil/playlist.m3u8",
    "httpClientCountGetUserQueryStr.1.1.1.1.157" => "liveoutside/smil:1234_camera_all.smil/playlist.m3u8",
    "httpClientCountGetIsFirstChunk.1.1.1.1.144" => "128.171.209.207"
}

```

Thank you

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 30, 2020, 8:01am UTC](https://discuss.elastic.co/t/how-to-process-filter-output-from-snmp-input-plugin-for-logstash/239549/4 "2020-07-30T08:01:31Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
