# Is there a mistake?

**URL:** <https://discuss.elastic.co/t/is-there-a-mistake/122102>\
**Category:** Logstash\
**Created:** [March 1, 2018, 2:55pm UTC](https://discuss.elastic.co/t/is-there-a-mistake/122102 "2018-03-01T14:55:36Z")\
**Posts on this page:** 20\
**Page:** 1

<div class="post-metadata">

**Author:** ![Bakkali\_Amine](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bakkali_amine/32/91129_2.png) [@Bakkali\_Amine](https://discuss.elastic.co/u/Bakkali_Amine)\
**Post date:** [March 1, 2018, 2:55pm UTC](https://discuss.elastic.co/t/is-there-a-mistake/122102/1 "2018-03-01T14:55:37Z")

</div>

is there something wrong with this config :  
input {  
file {  
type =\> "wazuh-alerts"  
path =\> "/var/ossec/logs/alerts/alerts.json"  
codec =\> "json"

}  
beats {

```
    port => 5044
    type => "apache"

```

}  
}  
filter {  
if [data][srcip] {  
mutate {  
add\_field =\> ["@src\_ip", "%{[data][srcip]}" ]  
}  
}  
if [data][aws][sourceIPAddress] {  
mutate {  
add\_field =\> ["@src\_ip", "%{[data][aws][sourceIPAddress]}" ]  
}  
}  
geoip {  
source =\> "@src\_ip"  
target =\> "GeoLocation"  
fields =\> ["city\_name", "continent\_code", "country\_code2", "country\_name", "region\_name", "location"]  
}  
date {  
match =\> ["timestamp", "ISO8601"]  
target =\> "@timestamp"  
}  
mutate {  
remove\_field =\> ["timestamp", "beat", "input\_type", "tags", "count", "@version", "log", "offset", "type","@src\_ip"]  
}  
}  
output {  
if [type] == "apache" {  
elasticsearch {  
hosts =\> ["localhost:9200"]  
index =\> "apache.x-%{+YYYY.MM.dd}"  
}  
}  
else {  
elasticsearch {  
hosts =\> ["localhost:9200"]  
index =\> "wazuh-alerts-3.x-%{+YYYY.MM.dd}"  
document\_type =\> "wazuh"

}  
}  
}

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [March 1, 2018, 8:08pm UTC](https://discuss.elastic.co/t/is-there-a-mistake/122102/2 "2018-03-01T20:08:33Z")

</div>

What makes you think there's a problem with the configuration?

---

<div class="post-metadata">

**Author:** ![Bakkali\_Amine](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bakkali_amine/32/91129_2.png) [@Bakkali\_Amine](https://discuss.elastic.co/u/Bakkali_Amine)\
**Post date:** [March 2, 2018, 8:52am UTC](https://discuss.elastic.co/t/is-there-a-mistake/122102/3 "2018-03-02T08:52:56Z")

</div>

I can't generate index on elasticsearch with that config, if I remove the "if" I can but I get all my logs mixed up.

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [March 2, 2018, 8:55am UTC](https://discuss.elastic.co/t/is-there-a-mistake/122102/4 "2018-03-02T08:55:15Z")

</div>

Have you looked in the Logstash log for clues? If it has problems sending to ES it'll tell you about it.

---

<div class="post-metadata">

**Author:** ![Bakkali\_Amine](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bakkali_amine/32/91129_2.png) [@Bakkali\_Amine](https://discuss.elastic.co/u/Bakkali_Amine)\
**Post date:** [March 2, 2018, 9:02am UTC](https://discuss.elastic.co/t/is-there-a-mistake/122102/5 "2018-03-02T09:02:04Z")

</div>

It gives any Erro just the pipeline started

---

<div class="post-metadata">

**Author:** ![Bakkali\_Amine](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bakkali_amine/32/91129_2.png) [@Bakkali\_Amine](https://discuss.elastic.co/u/Bakkali_Amine)\
**Post date:** [March 2, 2018, 9:05am UTC](https://discuss.elastic.co/t/is-there-a-mistake/122102/6 "2018-03-02T09:05:17Z")

</div>

![logs_logstash](https://us1.discourse-cdn.com/elastic/original/3X/e/b/ebd48cb427979a9a4df1cec09aa0185636245707.png)

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [March 2, 2018, 9:14am UTC](https://discuss.elastic.co/t/is-there-a-mistake/122102/7 "2018-03-02T09:14:00Z")

</div>

Okay. And how do you know Logstash is getting any events to process and eventually send to ES?

---

<div class="post-metadata">

**Author:** ![Bakkali\_Amine](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bakkali_amine/32/91129_2.png) [@Bakkali\_Amine](https://discuss.elastic.co/u/Bakkali_Amine)\
**Post date:** [March 2, 2018, 9:18am UTC](https://discuss.elastic.co/t/is-there-a-mistake/122102/8 "2018-03-02T09:18:36Z")

</div>

I'm using Filebeat in a web server to get access.log, and ossec agent to get File integrety monitoring. When I use the normal config without the "if" I get all the logs and event but all in the index "apache", but when I add the "if" it stops.

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [March 2, 2018, 9:46am UTC](https://discuss.elastic.co/t/is-there-a-mistake/122102/9 "2018-03-02T09:46:57Z")

</div>

But you're getting the events in the other index, right? What does an Apache event look like? Copy/paste from Kibana's JSON tab.

---

<div class="post-metadata">

**Author:** ![Bakkali\_Amine](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bakkali_amine/32/91129_2.png) [@Bakkali\_Amine](https://discuss.elastic.co/u/Bakkali_Amine)\
**Post date:** [March 2, 2018, 10:00am UTC](https://discuss.elastic.co/t/is-there-a-mistake/122102/10 "2018-03-02T10:00:58Z")

</div>

I got OSSEC logs in apache index :  
{  
"\_index": "apache-2018.03.02",  
"\_type": "doc",  
"\_id": "sEYj5mEBaNtzX4YdlGze",  
"\_version": 1,  
"\_score": null,  
"\_source": {  
"decoder": {  
"name": "ossec"  
},  
"location": "netstat listening ports",  
"path": "/var/ossec/logs/alerts/alerts.json",  
"full\_log": "ossec: output: 'netstat listening ports':\ntcp 0.0.0.0:22 0.0.0.0:\* 875/sshd\ntcp6 :::22 :::\* 875/sshd\nudp 0.0.0.0:68 0.0.0.0:\* 5211/dhclient\nudp 0.0.0.0:1514 0.0.0.0:\* 1223/ossec-remoted\ntcp6 :::5044 :::\* 5704/java\ntcp 0.0.0.0:5601 0.0.0.0:\* 643/node\nudp6 :::8236 :::\* 5211/dhclient\ntcp6 127.0.0.1:9200 :::\* 5478/java\ntcp6 ::1:9200 :::\* 5478/java\ntcp6 127.0.0.1:9300 :::\* 5478/java\ntcp6 ::1:9300 :::\* 5478/java\ntcp6 127.0.0.1:9600 :::\* 5704/java\nudp 0.0.0.0:20256 0.0.0.0:\* 5211/dhclient\ntcp6 :::55000 :::\* 870/node",  
"previous\_log": "ossec: output: 'netstat listening ports':\ntcp 0.0.0.0:22 0.0.0.0:\* 875/sshd\ntcp6 :::22 :::\* 875/sshd\nudp 0.0.0.0:68 0.0.0.0:\* 5211/dhclient\nudp 0.0.0.0:1514 0.0.0.0:\* 1223/ossec-remoted\ntcp6 :::5044 :::\* 640/java\ntcp 0.0.0.0:5601 0.0.0.0:\* 643/node\nudp6 :::8236 :::\* 5211/dhclient\ntcp6 127.0.0.1:9200 :::\* 868/java\ntcp6 ::1:9200 :::\* 868/java\ntcp6 127.0.0.1:9300 :::\* 868/java\ntcp6 ::1:9300 :::\* 868/java\ntcp6 127.0.0.1:9600 :::\* 640/java\nudp 0.0.0.0:20256 0.0.0.0:\* 5211/dhclient\ntcp6 :::55000 :::\* 870/node",  
"rule": {  
"description": "Listened ports status (netstat) changed (new port opened or closed).",  
"id": "533",  
"groups": [  
"ossec",  
"gpg13\_10.1"  
],  
"mail": false,  
"level": 7,  
"firedtimes": 4,  
"pci\_dss": [  
"10.2.7",  
"10.6.1"  
]  
},  
"id": "1519984545.30906",  
"manager": {  
"name": "localhost.localdomain"  
},  
"host": "localhost.localdomain",  
"agent": {  
"name": "localhost.localdomain",  
"id": "000"  
},  
"previous\_output": "ossec: output: 'netstat listening ports':\ntcp 0.0.0.0:22 0.0.0.0:\* 875/sshd\ntcp6 :::22 :::\* 875/sshd\nudp 0.0.0.0:68 0.0.0.0:\* 5211/dhclient\nudp 0.0.0.0:1514 0.0.0.0:\* 1223/ossec-remoted\ntcp6 :::5044 :::\* 640/java\ntcp 0.0.0.0:5601 0.0.0.0:\* 643/node\nudp6 :::8236 :::\* 5211/dhclient\ntcp6 127.0.0.1:9200 :::\* 868/java\ntcp6 ::1:9200 :::\* 868/java\ntcp6 127.0.0.1:9300 :::\* 868/java\ntcp6 ::1:9300 :::\* 868/java\ntcp6 127.0.0.1:9600 :::\* 640/java\nudp 0.0.0.0:20256 0.0.0.0:\* 5211/dhclient\ntcp6 :::55000 :::\* 870/node",  
"predecoder": {  
"hostname": "localhost"  
},  
"@timestamp": "2018-03-02T09:55:45.000Z"  
},  
"fields": {  
"@timestamp": [  
"2018-03-02T09:55:45.000Z"  
]  
},  
"sort": [  
1519984545000  
]  
}

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [March 2, 2018, 10:02am UTC](https://discuss.elastic.co/t/is-there-a-mistake/122102/11 "2018-03-02T10:02:42Z")

</div>

When you comment out the if conditional? Yes, that's expected. I'm more interested in what happens with the conditional in place.

---

<div class="post-metadata">

**Author:** ![Bakkali\_Amine](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bakkali_amine/32/91129_2.png) [@Bakkali\_Amine](https://discuss.elastic.co/u/Bakkali_Amine)\
**Post date:** [March 2, 2018, 10:06am UTC](https://discuss.elastic.co/t/is-there-a-mistake/122102/12 "2018-03-02T10:06:14Z")

</div>

when I use the "if" I can't get any data

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [March 2, 2018, 10:47am UTC](https://discuss.elastic.co/t/is-there-a-mistake/122102/13 "2018-03-02T10:47:23Z")

</div>

I think you're getting all events to the wazuh-alerts events. It's not likely that the presence of the conditional mean you get **nothing**. Again, what does an Apache event look like? Does it really have `type` set to "apache"

---

<div class="post-metadata">

**Author:** ![Bakkali\_Amine](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bakkali_amine/32/91129_2.png) [@Bakkali\_Amine](https://discuss.elastic.co/u/Bakkali_Amine)\
**Post date:** [March 2, 2018, 10:53am UTC](https://discuss.elastic.co/t/is-there-a-mistake/122102/14 "2018-03-02T10:53:13Z")

</div>

{  
"\_index": "wazuh-alerts-3.x-2018.03.02",  
"\_type": "wazuh",  
"\_id": "zEZS5mEBaNtzX4YdFWxK",  
"\_version": 1,  
"\_score": null,  
"\_source": {  
"host": "localhost.localdomain",  
"source": "/var/log/httpd/access\_log",  
"message": "192.168.112.1 - - [02/Mar/2018:10:46:46 +0000] "GET /noindex/css/fonts/Bold/OpenSans-Bold.ttf HTTP/1.1" 404 238 "[http://192.168.112.176/noindex/css/open-sans.css](http://192.168.112.176/noindex/css/open-sans.css)" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:58.0) Gecko/20100101 Firefox/58.0"",  
"prospector": {  
"type": "log"  
},  
"@timestamp": "2018-03-02T10:46:52.141Z"  
},  
"fields": {  
"@timestamp": [  
"2018-03-02T10:46:52.141Z"  
]  
},  
"sort": [  
1519987612141  
]  
}  
They have type Wazuh

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [March 2, 2018, 11:04am UTC](https://discuss.elastic.co/t/is-there-a-mistake/122102/15 "2018-03-02T11:04:28Z")

</div>

The `type` field contains "log" so the

```
if [type] == "apache" {

```

conditional is never true.

---

<div class="post-metadata">

**Author:** ![Bakkali\_Amine](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bakkali_amine/32/91129_2.png) [@Bakkali\_Amine](https://discuss.elastic.co/u/Bakkali_Amine)\
**Post date:** [March 2, 2018, 11:06am UTC](https://discuss.elastic.co/t/is-there-a-mistake/122102/16 "2018-03-02T11:06:20Z")

</div>

Even if I used type =\> "apache" in the input ?

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [March 2, 2018, 11:16am UTC](https://discuss.elastic.co/t/is-there-a-mistake/122102/17 "2018-03-02T11:16:12Z")

</div>

Apparently. Perhaps Filebeat sets it to "log" and the beats input doesn't overwrite the value? Since you might want to send other kinds of logs to the beats input you shouldn't set the type there anyway.

---

<div class="post-metadata">

**Author:** ![Bakkali\_Amine](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bakkali_amine/32/91129_2.png) [@Bakkali\_Amine](https://discuss.elastic.co/u/Bakkali_Amine)\
**Post date:** [March 2, 2018, 11:23am UTC](https://discuss.elastic.co/t/is-there-a-mistake/122102/18 "2018-03-02T11:23:42Z")

</div>

so the solution is to use "tags" ? but even if I put them in the input field I can't find them in the Json Table.

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [March 2, 2018, 11:33am UTC](https://discuss.elastic.co/t/is-there-a-mistake/122102/19 "2018-03-02T11:33:43Z")

</div>

You should set the kind of events in the Filebeat configuration. You can either use tags or use fields (e.g. `type`) by using the `fields` option. In the latter case you should also make sure `fields_under_root` is set to true.

---

<div class="post-metadata">

**Author:** ![Bakkali\_Amine](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bakkali_amine/32/91129_2.png) [@Bakkali\_Amine](https://discuss.elastic.co/u/Bakkali_Amine)\
**Post date:** [March 2, 2018, 11:41am UTC](https://discuss.elastic.co/t/is-there-a-mistake/122102/20 "2018-03-02T11:41:41Z")

</div>

Ok thank you a lot, I used if [fields][log\_type] == "access" and it works .

[Next page](https://discuss.elastic.co/t/is-there-a-mistake/122102.md?page=2)
