# Is it available logstash "environment" filter plugin in Windows?

**URL:** <https://discuss.elastic.co/t/is-it-available-logstash-environment-filter-plugin-in-windows/236897>\
**Category:** Logstash\
**Created:** [June 12, 2020, 12:54pm UTC](https://discuss.elastic.co/t/is-it-available-logstash-environment-filter-plugin-in-windows/236897 "2020-06-12T12:54:51Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![eizquierdo](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/eizquierdo/32/68877_2.png) [@eizquierdo](https://discuss.elastic.co/u/eizquierdo)\
**Post date:** [June 12, 2020, 12:54pm UTC](https://discuss.elastic.co/t/is-it-available-logstash-environment-filter-plugin-in-windows/236897/1 "2020-06-12T12:54:51Z")

</div>

I have this simple configuration:

```
input { stdin { } }
filter {
  environment {
    add_metadata_from_env => {"test" => "TEST_ENV"}
    add_field => ["my_test", "%{[@metadata][test]}"]
  }
}
output { stdout { codec => rubydebug { metadata => true } } }

```

When I run: bin\logstash.bat -f config\test-env.conf  
logstash (version 7.7.1) cannot start and produces these messages:

'Sending Logstash logs to C:/data/sw/elk/logstash-7.7.1/logs which is now configured via log4j2.properties'  
'[2020-06-12T14:42:24,077][WARN][logstash.config.source.multilocal] Ignoring the 'pipelines.yml' file because modules or command line options are specified'  
'[2020-06-12T14:42:24,199][INFO][logstash.runner] Starting Logstash {"logstash.version"=\>"7.7.1"}'  
'[2020-06-12T14:42:26,113][INFO][org.reflections.Reflections] Reflections took 35 ms to scan 1 urls, producing 21 keys and 41 values'  
'[2020-06-12T14:42:26,740][ERROR][logstash.plugins.registry] Tried to load a plugin's code, but failed. {:exception=\>#\<LoadError: no such file to load -- logstash/filters/environment\>, :path=\>"logstash/filters/environment", :type=\>"filter", :name=\>"environment"}'

Am I missing some configuration for my install?

---

<div class="post-metadata">

**Author:** ![eizquierdo](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/eizquierdo/32/68877_2.png) [@eizquierdo](https://discuss.elastic.co/u/eizquierdo)\
**Post date:** [June 12, 2020, 1:20pm UTC](https://discuss.elastic.co/t/is-it-available-logstash-environment-filter-plugin-in-windows/236897/2 "2020-06-12T13:20:42Z")

</div>

Solved, in fact the environment plugin was not installed with the windows package.  
After "bin\logstash-plugin.bat install logstash-filter-environment" it worked.

By the way, ¿does anybody know if is possible to use part of the message in the environment variable name?

Like this:

```
filter {
  environment {
    add_metadata_from_env => {"test" => "TEST_%{sufix}"}
    add_field => ["my_test", "%{[@metadata][test]}"]
  }
}

```

Is not working for me, the result is nil value in [@metadata][test]

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [June 12, 2020, 2:27pm UTC](https://discuss.elastic.co/t/is-it-available-logstash-environment-filter-plugin-in-windows/236897/3 "2020-06-12T14:27:10Z")

</div>

> [@eizquierdo](#):
>
> `add_metadata_from_env => {"test" => "TEST_%{sufix}"}`

I would expect a sprintf reference to work in the field name because it calls event.set, but not in the environment variable name, since it is a [simple lookup](https://github.com/logstash-plugins/logstash-filter-environment/blob/05beecb5f891870a975d8db5753a01daa8f38dc0/lib/logstash/filters/environment.rb#L53).

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 10, 2020, 2:27pm UTC](https://discuss.elastic.co/t/is-it-available-logstash-environment-filter-plugin-in-windows/236897/4 "2020-07-10T14:27:15Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
