# Logstash - counting field entries

**URL:** <https://discuss.elastic.co/t/logstash-counting-field-entries/149111>\
**Category:** Logstash\
**Created:** [September 19, 2018, 11:08am UTC](https://discuss.elastic.co/t/logstash-counting-field-entries/149111 "2018-09-19T11:08:39Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![ifishy](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ifishy/32/63330_2.png) [@ifishy](https://discuss.elastic.co/u/ifishy)\
**Post date:** [September 19, 2018, 11:08am UTC](https://discuss.elastic.co/t/logstash-counting-field-entries/149111/1 "2018-09-19T11:08:40Z")

</div>

Hi,  
i have built a small filter, that groks a Mac-Adress out of the message of a log.

Know, i want to count the entries, how much same mac-adresses in twenty minutes, i tested with "metrics" filter, but i think, i haven't understand, how it works.  
Here my filter:

```
filter {
    if [source] == "d:\SMS_DP$\sms\logs\SMSPXE.log" {
            grok {
                    match => ["message" , "%{COMMONMAC:MacAdresse}"]
            }

            metrics {
                    meter => ["%{MacAdresse}"]
                     flush_interval => 1300
                     clear_interval => 1200
                    add_tag => "metric"
            }

    }
}

```

Somebody can give me please a hint to solve this problem?

Thank you  
Wolfgang

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 17, 2018, 11:08am UTC](https://discuss.elastic.co/t/logstash-counting-field-entries/149111/2 "2018-10-17T11:08:40Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
