# Http header data extract

**URL:** <https://discuss.elastic.co/t/http-header-data-extract/185213>\
**Category:** Logstash\
**Created:** [June 11, 2019, 2:20pm UTC](https://discuss.elastic.co/t/http-header-data-extract/185213 "2019-06-11T14:20:47Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![muntazirabbas](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/muntazirabbas/32/65416_2.png) [@muntazirabbas](https://discuss.elastic.co/u/muntazirabbas)\
**Post date:** [June 11, 2019, 2:20pm UTC](https://discuss.elastic.co/t/http-header-data-extract/185213/1 "2019-06-11T14:20:47Z")

</div>

Hi everyone, I am new to ELK and have started with Logstash already. One of my Task it to use http as an Input and extract the Header data out of it and send it to Elasticsearch and then to Kibana in later stage. Here is my Output:

```
{
          "host" => "0:0:0:0:0:0:0:1",
      "@version" => "1",
       "message" => "hi its me",
    "@timestamp" => 2019-06-11T14:14:14.923Z,
       "headers" => {
            "http_accept" => "*/*",
          "cache_control" => "no-cache",
           "http_version" => "HTTP/1.1",
           "request_path" => "/",
         "content_length" => "9",
          "postman_token" => "9c29159c-ec34-448c-a038-673cce84e783",
              "http_host" => "localhost:8080",
         "request_method" => "GET",
        "http_user_agent" => "PostmanRuntime/7.13.0",
             "connection" => "keep-alive",
                   "user" => "muntazir",
           "content_type" => "text/plain",
        "accept_encoding" => "gzip, deflate"
    }
}

```

Can you please guide, how can i extract Information from the Header section like "http\_host", "request\_method", "user", "host" etc? What should I use, any filter or there any other ways?  
Best regards,

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [June 11, 2019, 2:56pm UTC](https://discuss.elastic.co/t/http-header-data-extract/185213/2 "2019-06-11T14:56:00Z")

</div>

Is that the output from

```
output { stdout { codec => rubydebug } }

```

If so, you can index it as-is and refer to fields like headers.http\_host in kibana. If not, what produced that text?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 9, 2019, 2:56pm UTC](https://discuss.elastic.co/t/http-header-data-extract/185213/3 "2019-07-09T14:56:13Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
