# Logstasch pipeline filter

**URL:** <https://discuss.elastic.co/t/logstasch-pipeline-filter/294009>\
**Category:** Logstash\
**Created:** [January 11, 2022, 9:57am UTC](https://discuss.elastic.co/t/logstasch-pipeline-filter/294009 "2022-01-11T09:57:15Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![max\_cyril](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/max_cyril/32/100067_2.png) [@max\_cyril](https://discuss.elastic.co/u/max_cyril)\
**Post date:** [January 11, 2022, 9:57am UTC](https://discuss.elastic.co/t/logstasch-pipeline-filter/294009/1 "2022-01-11T09:57:15Z")

</div>

Hi,  
I am new to ELK and struggling to write my first logstash pipeline.  
Can anyone help me to write the filter section?  
Thanks in advance.

i want to filter and only output the maximum of completion per users

 ![image (2)](https://us1.discourse-cdn.com/elastic/original/3X/f/c/fc12410b77b2707e0f043ba01305a733ae29d129.png)

for instance :  
user completion  
u2 20  
...  
u48 100

that is my trial whitout succeed.

```auto
input
{elasticsearch
{hosts => "...."
user => "..."
password => "..."
index => "index1"
codec =>"json"
docinfo => true
}}

filter {
aggregate {
task_id => "%{users}"
code => "map['completion'] = event.get('completion') ;
event.cancel if (map['completion']) != map['completion'].max()"
map_action => "create" }

}output
{elasticsearch
{hosts => "..."
user => "...l"
password => "..."
index => "index2"
document_type =>"%{[@metadata][_type]}"
document_id =>"%{[@metadata][_id]}"
}}

```

can someone helps me please, thank you!

---

<div class="post-metadata">

**Author:** ![grumo35](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/grumo35/32/59451_2.png) [@grumo35](https://discuss.elastic.co/u/grumo35)\
**Post date:** [January 11, 2022, 10:13am UTC](https://discuss.elastic.co/t/logstasch-pipeline-filter/294009/2 "2022-01-11T10:13:14Z")

</div>

Hey,

After defining all your pipelines in the pipelines.yml you'll have to set an "input" pipeline then filter the logs you want like this

```auto
output {
        if "water" in [tags] {
          pipeline { send_to => pool }
        } else if "lava" in [tags] {
          pipeline { send_to => volcano }
        } else if "tree" in [tags] or "bush" in [tags] {
          pipeline { send_to => forest }
        }
    }

```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 8, 2022, 10:14am UTC](https://discuss.elastic.co/t/logstasch-pipeline-filter/294009/3 "2022-02-08T10:14:03Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
