# Logstash aggregation filter not working properly

**URL:** <https://discuss.elastic.co/t/logstash-aggregation-filter-not-working-properly/39847>\
**Category:** Logstash\
**Created:** [January 22, 2016, 6:04am UTC](https://discuss.elastic.co/t/logstash-aggregation-filter-not-working-properly/39847 "2016-01-22T06:04:50Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![nivetha](https://avatars.discourse-cdn.com/v4/letter/n/54ee81/32.png) [@nivetha](https://discuss.elastic.co/u/nivetha)\
**Post date:** [January 22, 2016, 6:04am UTC](https://discuss.elastic.co/t/logstash-aggregation-filter-not-working-properly/39847/1 "2016-01-22T06:04:50Z")

</div>

I tried aggregating events ,it gets agrregated ,but in my output I get all lines displayed ,aggregatted lines and also the other lines. I want just the aggregated lines alone in my index.  
input {  
file {  
path =\> "/opt/logs\_trial/gst\_session\_log.log\*"  
#start\_position =\> "beginning"  
type =\> "gst\_session"  
}  
}  
filter {  
if [type] == "gst\_session" {  
if [Status] == "start" {  
aggregate {  
task\_id =\> "%{SessionId}"  
code =\> "map['bitrate1']=0"  
map\_action =\> "create"  
add\_tag =\> ["aggregateStart"]  
}  
}  
if [Status] == "play" or [Status] == "success" or [Status] == "bitrate\_shift"  
{  
aggregate {  
task\_id =\> "%{SessionId}"  
code =\> "map['bitrate1'] += event['bitrate']"  
map\_action =\> "update"  
add\_tag =\> ["aggregateMiddle"]  
}  
}  
if [Status] == "close" {  
aggregate {  
task\_id =\> "%{SessionId}"  
code =\> "event['bitrate1'] = map['bitrate1']"  
map\_action =\> "update"  
end\_of\_task =\> true  
add\_tag =\> ["aggregateEnd"]  
timeout =\> 120  
}  
}  
}

}  
output {  
if [type] == "gst\_session"{  
elasticsearch{  
hosts =\> "10.126.250.45"  
#port =\> "9200"  
index =\> "gst\_summary"  
#protocol =\> "http"  
}  
}}

Did I miss any configuration?

---

<div class="post-metadata">

**Author:** ![fbaligand](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/fbaligand/32/5657_2.png) [@fbaligand](https://discuss.elastic.co/u/fbaligand)\
**Post date:** [January 30, 2016, 11:35pm UTC](https://discuss.elastic.co/t/logstash-aggregation-filter-not-working-properly/39847/2 "2016-01-30T23:35:26Z")

</div>

This is the normal aggregate filter behaviour.  
aggregate filter doesn't aim to delete existing events, but to enrich the final event of each "task".  
If you don't want other lines, you can use drop filter as last filter.

For example :

if "aggregateEnd" not in [tags] {  
drop {}  
}

---

<div class="post-metadata">

**Author:** ![nivetha](https://avatars.discourse-cdn.com/v4/letter/n/54ee81/32.png) [@nivetha](https://discuss.elastic.co/u/nivetha)\
**Post date:** [February 1, 2016, 5:31am UTC](https://discuss.elastic.co/t/logstash-aggregation-filter-not-working-properly/39847/3 "2016-02-01T05:31:47Z")

</div>

Thanks fbaligand . Its working fine

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 5:13am UTC](https://discuss.elastic.co/t/logstash-aggregation-filter-not-working-properly/39847/4 "2017-07-06T05:13:38Z")

</div>


