# Jdbc in filter section

**URL:** <https://discuss.elastic.co/t/jdbc-in-filter-section/36280>\
**Category:** Logstash\
**Created:** [December 3, 2015, 11:34am UTC](https://discuss.elastic.co/t/jdbc-in-filter-section/36280 "2015-12-03T11:34:51Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![adellarocca](https://avatars.discourse-cdn.com/v4/letter/a/9fc29f/32.png) [@adellarocca](https://discuss.elastic.co/u/adellarocca)\
**Post date:** [December 3, 2015, 11:34am UTC](https://discuss.elastic.co/t/jdbc-in-filter-section/36280/1 "2015-12-03T11:34:51Z")

</div>

I need to lookup fields in a RDBMS (MySQL) during filter phase of Logstash to extract new informations.  
Neverthless jdbc plugin exists only for input section.  
I can't do this in input section because my fields are available only from the filter phase.  
How can I do?  
Thank you very much!

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [December 3, 2015, 11:47am UTC](https://discuss.elastic.co/t/jdbc-in-filter-section/36280/2 "2015-12-03T11:47:48Z")

</div>

A few options come to mind:

- The [translate filter](https://www.elastic.co/guide/en/logstash/current/plugins-filters-translate.html) might work, although tou won't be able to get real-time lookups.
- If you push the data from the relational database into an ES index you can use the [elasticsearch filter](https://www.elastic.co/guide/en/logstash/current/plugins-filters-elasticsearch.html).
- It should be possible to write a [ruby filter](https://www.elastic.co/guide/en/logstash/current/plugins-filters-elasticsearch.htmlhttps://www.elastic.co/guide/en/logstash/current/plugins-filters-ruby.html) that performs the lookups via e.g. HTTP.

---

<div class="post-metadata">

**Author:** ![wiibaa](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/wiibaa/32/44931_2.png) [@wiibaa](https://discuss.elastic.co/u/wiibaa)\
**Post date:** [December 3, 2015, 12:14pm UTC](https://discuss.elastic.co/t/jdbc-in-filter-section/36280/3 "2015-12-03T12:14:00Z")

</div>

Indeed jdbc filtering is not supported in current logstash plugin set , but there is existing work on github:

> **[pafq/logstash-filter-jdbc](https://github.com/pafq/logstash-filter-jdbc)**
>
> Contribute to logstash-filter-jdbc development by creating an account on GitHub.

  

> **[wiibaa/logstash-filter-jdbc](https://github.com/wiibaa/logstash-filter-jdbc)**
>
> logstash-filter-jdbc - Work in progress

  

> **[wiibaa/logstash-filter-jdbc\_mysql](https://github.com/wiibaa/logstash-filter-jdbc_mysql)**
>
> Contribute to logstash-filter-jdbc\_mysql development by creating an account on GitHub.

The last two are my experiments but it seems a few people are using it happily.  
If it would suits your need, can you tell me which version of logstash you are currently using,  
I would try to find some to publish the gem

---

<div class="post-metadata">

**Author:** ![adellarocca](https://avatars.discourse-cdn.com/v4/letter/a/9fc29f/32.png) [@adellarocca](https://discuss.elastic.co/u/adellarocca)\
**Post date:** [December 4, 2015, 11:20am UTC](https://discuss.elastic.co/t/jdbc-in-filter-section/36280/4 "2015-12-04T11:20:48Z")

</div>

Thank you for your help magnusbaeck!  
I've temporarily resolved with translate filter because data are small.  
In next future I believe that I will write a ruby filter.

---

<div class="post-metadata">

**Author:** ![adellarocca](https://avatars.discourse-cdn.com/v4/letter/a/9fc29f/32.png) [@adellarocca](https://discuss.elastic.co/u/adellarocca)\
**Post date:** [December 4, 2015, 11:23am UTC](https://discuss.elastic.co/t/jdbc-in-filter-section/36280/5 "2015-12-04T11:23:46Z")

</div>

Thank you wiibaa.  
I've been using logstash 2.0.0 and your plugin is very interesting but I'm not successfull to install it  
because I'm newbie to ruby and I've some problems.

---

<div class="post-metadata">

**Author:** ![wiibaa](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/wiibaa/32/44931_2.png) [@wiibaa](https://discuss.elastic.co/u/wiibaa)\
**Post date:** [December 6, 2015, 7:05am UTC](https://discuss.elastic.co/t/jdbc-in-filter-section/36280/6 "2015-12-06T07:05:00Z")

</div>

Hello again,

I have made the necessary for easy install of my plugin,  
so you could try from your logstash installation to

`bin/plugin install logstash-filter-jdbc_mysql`

and add a filter configuration section in your logstash config.  
If needed you can look at this example [https://github.com/wiibaa/logstash-filter-jdbc\_mysql/blob/master/lib/logstash/filters/jdbc\_mysql.rb#L15-L25](https://github.com/wiibaa/logstash-filter-jdbc_mysql/blob/master/lib/logstash/filters/jdbc_mysql.rb#L15-L25)

---

<div class="post-metadata">

**Author:** ![adellarocca](https://avatars.discourse-cdn.com/v4/letter/a/9fc29f/32.png) [@adellarocca](https://discuss.elastic.co/u/adellarocca)\
**Post date:** [December 9, 2015, 9:18am UTC](https://discuss.elastic.co/t/jdbc-in-filter-section/36280/7 "2015-12-09T09:18:59Z")

</div>

Hello wiibaa,  
thank you for your support!  
I've tried to install your plugin but I've received this error

Validating logstash-filter-jdbc\_mysql  
SocketError: recv: name or service not known  
recv\_reply at /home/alessandro/Scrivania/logstash-2.0.0/vendor/jruby/lib/ruby/1.9/resolv.rb:782  
request at /home/alessandro/Scrivania/logstash-2.0.0/vendor/jruby/lib/ruby/1.9/resolv.rb:664  
each\_resource at /home/alessandro/Scrivania/logstash-2.0.0/vendor/jruby/lib/ruby/1.9/resolv.rb:512  
resolv at /home/alessandro/Scrivania/logstash-2.0.0/vendor/jruby/lib/ruby/1.9/resolv.rb:0  
each at org/jruby/RubyArray.java:1613  
resolv at /home/alessandro/Scrivania/logstash-2.0.0/vendor/jruby/lib/ruby/1.9/resolv.rb:1034  
each at org/jruby/RubyArray.java:1613  
resolv at /home/alessandro/Scrivania/logstash-2.0.0/vendor/jruby/lib/ruby/1.9/resolv.rb:1033  
each at org/jruby/RubyArray.java:1613  
resolv at /home/alessandro/Scrivania/logstash-2.0.0/vendor/jruby/lib/ruby/1.9/resolv.rb:1031  
each\_resource at /home/alessandro/Scrivania/logstash-2.0.0/vendor/jruby/lib/ruby/1.9/resolv.rb:503  
getresource at /home/alessandro/Scrivania/logstash-2.0.0/vendor/jruby/lib/ruby/1.9/resolv.rb:480  
api\_endpoint at /home/alessandro/Scrivania/logstash-2.0.0/vendor/jruby/lib/ruby/shared/rubygems/remote\_fetcher.rb:92  
api\_uri at /home/alessandro/Scrivania/logstash-2.0.0/vendor/jruby/lib/ruby/shared/rubygems/source.rb:46  
load\_specs at /home/alessandro/Scrivania/logstash-2.0.0/vendor/jruby/lib/ruby/shared/rubygems/source.rb:182  
tuples\_for at /home/alessandro/Scrivania/logstash-2.0.0/vendor/jruby/lib/ruby/shared/rubygems/spec\_fetcher.rb:261  
available\_specs at /home/alessandro/Scrivania/logstash-2.0.0/vendor/jruby/lib/ruby/shared/rubygems/spec\_fetcher.rb:226  
each at org/jruby/RubyArray.java:1613  
each\_source at /home/alessandro/Scrivania/logstash-2.0.0/vendor/jruby/lib/ruby/shared/rubygems/source\_list.rb:97  
available\_specs at /home/alessandro/Scrivania/logstash-2.0.0/vendor/jruby/lib/ruby/shared/rubygems/spec\_fetcher.rb:222  
search\_for\_dependency at /home/alessandro/Scrivania/logstash-2.0.0/vendor/jruby/lib/ruby/shared/rubygems/spec\_fetcher.rb:102  
spec\_for\_dependency at /home/alessandro/Scrivania/logstash-2.0.0/vendor/jruby/lib/ruby/shared/rubygems/spec\_fetcher.rb:166  
logstash\_plugin? at /home/alessandro/Scrivania/logstash-2.0.0/lib/pluginmanager/util.rb:21  
verify\_remote! at /home/alessandro/Scrivania/logstash-2.0.0/lib/pluginmanager/install.rb:50  
each at org/jruby/RubyArray.java:1613  
verify\_remote! at /home/alessandro/Scrivania/logstash-2.0.0/lib/pluginmanager/install.rb:48  
execute at /home/alessandro/Scrivania/logstash-2.0.0/lib/pluginmanager/install.rb:26  
run at /home/alessandro/Scrivania/logstash-2.0.0/vendor/bundle/jruby/1.9/gems/clamp-0.6.5/lib/clamp/command.rb:67  
execute at /home/alessandro/Scrivania/logstash-2.0.0/vendor/bundle/jruby/1.9/gems/clamp-0.6.5/lib/clamp/subcommand/execution.rb:11  
run at /home/alessandro/Scrivania/logstash-2.0.0/vendor/bundle/jruby/1.9/gems/clamp-0.6.5/lib/clamp/command.rb:67  
run at /home/alessandro/Scrivania/logstash-2.0.0/vendor/bundle/jruby/1.9/gems/clamp-0.6.5/lib/clamp/command.rb:132  
(root) at /home/alessandro/Scrivania/logstash-2.0.0/lib/pluginmanager/main.rb:37

---

<div class="post-metadata">

**Author:** ![wiibaa](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/wiibaa/32/44931_2.png) [@wiibaa](https://discuss.elastic.co/u/wiibaa)\
**Post date:** [December 10, 2015, 12:14am UTC](https://discuss.elastic.co/t/jdbc-in-filter-section/36280/8 "2015-12-10T00:14:53Z")

</div>

> [@adellarocca](#):
>
> SocketError: recv: name or service not known

This strongly seems like a transient error with rubygems, not something related to the plugin or logstash.  
Or are you maybe on an environment with restricted/proxied access to the internet ?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 5:19am UTC](https://discuss.elastic.co/t/jdbc-in-filter-section/36280/9 "2017-07-06T05:19:15Z")

</div>


