# How to use logstash filters

**URL:** <https://discuss.elastic.co/t/how-to-use-logstash-filters/42643>\
**Category:** Logstash\
**Created:** [February 24, 2016, 9:26pm UTC](https://discuss.elastic.co/t/how-to-use-logstash-filters/42643 "2016-02-24T21:26:08Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Aron\_Pedersen](https://avatars.discourse-cdn.com/v4/letter/a/8491ac/32.png) [@Aron\_Pedersen](https://discuss.elastic.co/u/Aron_Pedersen)\
**Post date:** [February 24, 2016, 9:26pm UTC](https://discuss.elastic.co/t/how-to-use-logstash-filters/42643/1 "2016-02-24T21:26:08Z")

</div>

I am new to the whole BELK stack (or The Elastic Stack from 5.0.0) so sorry if the question is not well described.

I have logs that looks like the example below that I ship with filebeat to logstash

Log example:  
`2/24/2016 6:18:20 AM +00:00|FdsResponder|Information|18437|{"ActionName":"ResumeUpload","Exception":null,"Metadata": .. well defined JASON 2/24/2016 6:18:21 AM +00:00|FdsResponder|Information|18436|{"ActionName":"ResumeDownload","Exception":null,"Metadata": .. well defined JASON 2/24/2016 6:20:21 AM +00:00|SDS Responder|Information|0|Loading manifest Guid: .. clear text 2/24/2016 6:20:22 AM +00:00|SDS Responder|Warning|4107|No load priority found for plug-in .. clear text 2/24/2016 6:20:23 AM +00:00|FdsResponder|Information|18437|{"ActionName":"ResumeUpload","Exception":null,"Metadata": .. well defined JASON`

Logstash conf:  
`input { beats { port => 5044 } } output { stdout { codec => rubydebug } }`

Filebeat.yml:  
`filebeat:  
prospectors:  
paths:  
- D:\filebeat\input\*.log  
input\_type: log

registry\_file: "C:/ProgramData/filebeat/registry"

output:  
logstash:  
hosts: ["10.114.21.91:5044"]

shipper:

logging:  
files:  
path: D:\filebeat\logs  
rotateeverybytes: 10485760 # = 10MB  
level: debug`

What I would love to accomplish is to first of all only ship the lines in the log file where the second column = FdsResponder to Logstash. Then have Logstash only output the JSON part of the logfile but using the time/date from the logfile (column 1) as the @timestamp. Is this possible?

Thank you all for your help an input.

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [February 25, 2016, 5:32am UTC](https://discuss.elastic.co/t/how-to-use-logstash-filters/42643/2 "2016-02-25T05:32:04Z")

</div>

It's possible!  
You will need to build a grok pattern to create fields for each of the values, then use a conditional to drop anything you don't want. Once you are there you can use the date filter to do the date matching.

Check out the docs around grok, and use [http://grokdebug.herokuapp.com/](http://grokdebug.herokuapp.com/) to build your pattern.

if you run into problems we're here to help!

---

<div class="post-metadata">

**Author:** ![Aron\_Pedersen](https://avatars.discourse-cdn.com/v4/letter/a/8491ac/32.png) [@Aron\_Pedersen](https://discuss.elastic.co/u/Aron_Pedersen)\
**Post date:** [February 25, 2016, 2:09pm UTC](https://discuss.elastic.co/t/how-to-use-logstash-filters/42643/3 "2016-02-25T14:09:29Z")

</div>

I appreciate your answer Mark but could you or others possible show me an little example of how I do this just to get started? Like the Date Filter, I am not sure how to use it correctly.

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [February 25, 2016, 6:45pm UTC](https://discuss.elastic.co/t/how-to-use-logstash-filters/42643/4 "2016-02-25T18:45:00Z")

</div>

The first thing you want to do is build the grok pattern, without that you cannot use the date filter.  
So how does that look?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 5:09am UTC](https://discuss.elastic.co/t/how-to-use-logstash-filters/42643/5 "2017-07-06T05:09:44Z")

</div>


