# How to set a schedule on Filter or reuse the content of a event

**URL:** https://discuss.elastic.co/t/how-to-set-a-schedule-on-filter-or-reuse-the-content-of-a-event/314520
**Category:** Logstash
**Created:** [September 15, 2022, 2:44pm UTC](https://discuss.elastic.co/t/how-to-set-a-schedule-on-filter-or-reuse-the-content-of-a-event/314520 "2022-09-15T14:44:54Z")
**Posts on this page:** 6
**Page:** 1

<div class="post-metadata">

### Author: ![SamuelSMendes](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/samuelsmendes/32/104246_2.png) [@SamuelSMendes](https://discuss.elastic.co/u/SamuelSMendes)
#### Post date: [September 15, 2022, 2:44pm UTC](https://discuss.elastic.co/t/how-to-set-a-schedule-on-filter-or-reuse-the-content-of-a-event/314520/1 "2022-09-15T14:44:55Z")

</div>

Hello everyone, need a share of your help again. This time with Logstash.

The context of the problem is:

I got a pipeline which goes into an API to retrieve a token with a POST, once I got this token I use it on another request (this time a GET) which will return a list of devices. So far I could make it happen by using the plugin HTTP POLLER on input and HTTP on Filter. The problem here is that this token have a duration of 3hours so theres no need to generate one that quickly, but theres a need to have the list of devices as soon as possible, such as 1minute at max.

Here is my config file:

```auto
input {
    http_poller{
        urls => {
           app => {
            method => post
            url => "[url to get the token]"
            headers => {
                
                "Content-Type" => "application/json"
                }
            body => '{ "client": "xxxxx","secret": "xxxxxx","tenant": xxxxx }'
           }
            
         }
        cacert => "cert/certificate.crt"
        request_timeout => 60
        schedule => {every => "1m"}
        codec => "json"
    }
    
}
filter{
  http {
    body_format => "json"
    url => "url to get the devices"
    verb => "GET"
    headers => { 
        "Authorization" => "Bearer %{access_token}"
        }
    cacert => "cert/certificate.crt"
    ecs_compatibility => disabled
  }

    split{
        field => "body"
    }
}

```

The dilemma is: I need the token generated to apply on the GET request, but I can only reuse it with the "%" on the header of the next request because is on the filter. If I could make that GET in another input I would be able to set a different schedule, but by doing it I can't access the token because it refers to another event.

The possible solutions I thought of were:

1 - Find a way to set a individual schedule for the filter to act (which I'm pretty sure it doesn't exist).  
2 - Find a way to get that token generated in the first request into a kind of variable? So I can use it on another input with a individual schedule.

Open to new ideas, will be glad if anyone can help me pull this out.

---

<div class="post-metadata">

### Author: ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)
#### Post date: [September 15, 2022, 3:31pm UTC](https://discuss.elastic.co/t/how-to-set-a-schedule-on-filter-or-reuse-the-content-of-a-event/314520/2 "2022-09-15T15:31:54Z")

</div>

It could probably be done....

Run an http\_poller on a long schedule (3 hours). Run a heartbeat input on a short schedule (once a minute). Use a ruby filter with logic like [this](https://discuss.elastic.co/t/method-to-timestamp-my-logstash-events/135888/3) to copy the token to heartbeat events.

---

<div class="post-metadata">

### Author: ![SamuelSMendes](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/samuelsmendes/32/104246_2.png) [@SamuelSMendes](https://discuss.elastic.co/u/SamuelSMendes)
#### Post date: [September 15, 2022, 7:18pm UTC](https://discuss.elastic.co/t/how-to-set-a-schedule-on-filter-or-reuse-the-content-of-a-event/314520/3 "2022-09-15T19:18:24Z")

</div>

Thank you for the fast reply.

Would you have some example of the heartbeat input being used as you say? I checked arround how I could use it but couldn't find hints execpt for the schedule.

Looking arround the link you sent was really useful. I belive that the token would come out with something like this?

```auto
ruby { code => "@token = event.get('access_token')" }

```

That being said, if that's right the filter session maybe could be like:

```auto
filter{
  if [type] == "heartbeat"{ # To ensure the input of the http_poller wont trigger it.
  http {
    body_format => "json"
    url => "url to get the devices"
    verb => "GET"
    headers => { 
        "Authorization" => "Bearer @token?(not sure how to fit it here)"
        }
    cacert => "cert/certificate.crt"
    ecs_compatibility => disabled
  }

    split{
        field => "body"
    }
}
}

```

Please correct me if something is terrible wrong on this 😅

---

<div class="post-metadata">

### Author: ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)
#### Post date: [September 16, 2022, 4:26pm UTC](https://discuss.elastic.co/t/how-to-set-a-schedule-on-filter-or-reuse-the-content-of-a-event/314520/4 "2022-09-16T16:26:47Z")

</div>

I was thinking of something like

```
input {
    http_poller {
        ...
    }
    heartbeat {
        interval => 60
        tags => ["heartbeat"]
    }
}
filter {
    if "heartbeat" in [tags] {
        ruby { code => 'event.set("tokenField", @@saveToken)" }
    } else {
        ruby { code => '@@saveToken = event.get("tokenField")' }
    }
    if [tokenField] {
        http {
            ...
        }
    }
}

```

---

<div class="post-metadata">

### Author: ![SamuelSMendes](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/samuelsmendes/32/104246_2.png) [@SamuelSMendes](https://discuss.elastic.co/u/SamuelSMendes)
#### Post date: [September 21, 2022, 3:49pm UTC](https://discuss.elastic.co/t/how-to-set-a-schedule-on-filter-or-reuse-the-content-of-a-event/314520/5 "2022-09-21T15:49:42Z")

</div>

Thanks a lot, that logic worked just like magic!

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [October 19, 2022, 3:50pm UTC](https://discuss.elastic.co/t/how-to-set-a-schedule-on-filter-or-reuse-the-content-of-a-event/314520/6 "2022-10-19T15:50:20Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
