# How to use filter in logstash for particular field with dynamic query string value?

**URL:** <https://discuss.elastic.co/t/how-to-use-filter-in-logstash-for-particular-field-with-dynamic-query-string-value/36883>\
**Category:** Logstash\
**Created:** [December 10, 2015, 1:51pm UTC](https://discuss.elastic.co/t/how-to-use-filter-in-logstash-for-particular-field-with-dynamic-query-string-value/36883 "2015-12-10T13:51:00Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![Aravinthan\_Asokan](https://avatars.discourse-cdn.com/v4/letter/a/dfb087/32.png) [@Aravinthan\_Asokan](https://discuss.elastic.co/u/Aravinthan_Asokan)\
**Post date:** [December 10, 2015, 1:51pm UTC](https://discuss.elastic.co/t/how-to-use-filter-in-logstash-for-particular-field-with-dynamic-query-string-value/36883/1 "2015-12-10T13:51:01Z")

</div>

I just able to search to my index using below query

xx:9200/myindex/\_search?q=keyword

for above search i can able to get results .. how to do another dynamic value in the url and search into particular field dynamically  
example : status = 'active' or status = 'dynamic\_query\_string' ...

so i can able to filter my search result with another field ..

i am using jdbc input and output in logstash

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [December 10, 2015, 2:00pm UTC](https://discuss.elastic.co/t/how-to-use-filter-in-logstash-for-particular-field-with-dynamic-query-string-value/36883/2 "2015-12-10T14:00:22Z")

</div>

So you make the query using the elasticsearch filter ? You can make `%{fieldname}` references in most plugin options, so something like this should work if you have a field named `dynamic_status_string`:

```auto
filter {
  elasticsearch {
    ...
    query => "status:%{dynamic_status_string}"
  }
}

```

---

<div class="post-metadata">

**Author:** ![Aravinthan\_Asokan](https://avatars.discourse-cdn.com/v4/letter/a/dfb087/32.png) [@Aravinthan\_Asokan](https://discuss.elastic.co/u/Aravinthan_Asokan)\
**Post date:** [December 10, 2015, 2:16pm UTC](https://discuss.elastic.co/t/how-to-use-filter-in-logstash-for-particular-field-with-dynamic-query-string-value/36883/3 "2015-12-10T14:16:58Z")

</div>

hi correct me if i am wrong

from your suggestion

yes i am using elasticsearch filter plugin ,

i am using mysql jdbc .. so my db field name is "status" and it is varchar .. i want to get all search results which status is "active" ..

how to pass the dynamic value "active" while searching using below url

xyz:9200/myindex/\_search?q=xyz...

should i pass like below url ?  
xyz:9200/myindex/\_search?q=xyz&status\_param=active

and in logstash filter

filter {  
elasticsearch {  
...  
query =\> "status:%{status\_param}"  
}  
}

will this work ? or something else

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [December 10, 2015, 2:52pm UTC](https://discuss.elastic.co/t/how-to-use-filter-in-logstash-for-particular-field-with-dynamic-query-string-value/36883/4 "2015-12-10T14:52:48Z")

</div>

If the `status_param` field contains the name of the status you want the filter to find then `status:%{statusparam}` is a good query.

---

<div class="post-metadata">

**Author:** ![Yur\_Gasparyan](https://avatars.discourse-cdn.com/v4/letter/y/7c8e57/32.png) [@Yur\_Gasparyan](https://discuss.elastic.co/u/Yur_Gasparyan)\
**Post date:** [March 18, 2017, 7:19am UTC](https://discuss.elastic.co/t/how-to-use-filter-in-logstash-for-particular-field-with-dynamic-query-string-value/36883/5 "2017-03-18T07:19:42Z")

</div>

Dear Magnus and Aravinthan. I have read all in above but I can not understand one thing.  
In my db config I have code look like this

```
jdbc {
		jdbc_connection_string => "jdbc:mysql//localhost:3306/mydb"
		jdbc_user => "root"
		jdbc_password => ""
		jdbc_driver_library => "C:/servers/elasticsearch/con.mysql.jdbc_5.1.5.jar"
		jdbc_driver_class => "com.mysql.jdbc.Driver"
		parameters => { "like" => "Beethoven" }
		statement => "Select* from users where name = :like"
	}

```

This statement is test and my goal will be very larg sql with more than 4-5 join with dynamic columns and values, Please help me ? Can I pass this parameters dynamicly. For example I am using Elasticsearch PHP Client library.  
Thanks  
Yuri

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [March 20, 2017, 6:14am UTC](https://discuss.elastic.co/t/how-to-use-filter-in-logstash-for-particular-field-with-dynamic-query-string-value/36883/6 "2017-03-20T06:14:48Z")

</div>

@Yur_Gasparyan, please start a new thread for your question. When you do, please clarify exactly what you mean by "pass these parameters dynamically".

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 4:27am UTC](https://discuss.elastic.co/t/how-to-use-filter-in-logstash-for-particular-field-with-dynamic-query-string-value/36883/7 "2017-07-06T04:27:43Z")

</div>


