# Logstash - Filter events according to data from a REST API

**URL:** <https://discuss.elastic.co/t/logstash-filter-events-according-to-data-from-a-rest-api/255153>\
**Category:** Logstash\
**Created:** [November 12, 2020, 6:50am UTC](https://discuss.elastic.co/t/logstash-filter-events-according-to-data-from-a-rest-api/255153 "2020-11-12T06:50:50Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Yor\_On](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yor_on/32/73235_2.png) [@Yor\_On](https://discuss.elastic.co/u/Yor_On)\
**Post date:** [November 12, 2020, 6:50am UTC](https://discuss.elastic.co/t/logstash-filter-events-according-to-data-from-a-rest-api/255153/1 "2020-11-12T06:50:50Z")

</div>

Hi,

I've scoured the internet for someone with the same issue as I, but I haven't had much success in finding any precedent on getting what I need done.

I have a REST API that returns a response which looks like:

```auto
GET something/services/allowed
returns:
{
    "services" : [
    {
    "name" : "foo",
    other fields....
    },
    {
    "name" : "bar",
    other fields....
    },
    etc.
    ] 
}

```

And all the logs written to my Logstash look like:

```json
{
    "service_name": "foo",
    "message" : "something",
    etc.
}

```

I write logs to an index based off the `service_name` field present in all logs. I want to make sure only services that are "authorised" to write logs get their logs into my ES cluster.

So I would like to be able to drop a log if it's `service_name` value does not appear as one of the names in the `services` list that the REST API returns

I was wondering if this is possible using the http filter or something similar?

Would greatly appreciate any help, thanks!

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [November 12, 2020, 3:16pm UTC](https://discuss.elastic.co/t/logstash-filter-events-according-to-data-from-a-rest-api/255153/2 "2020-11-12T15:16:54Z")

</div>

You could make the REST call once for each event, but that is going to make it expensive to process each event.

If the set of services returned by the call is constant then I would suggest making the call outside of logstash and creating a file that has a list of acceptable service names, then using a [translate](https://www.elastic.co/guide/en/logstash/current/plugins-filters-translate.html) filter to determine whether the service\_name in the current event is in that list (you would drop the event if the destination ends up set to the fallback value).

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 10, 2020, 3:17pm UTC](https://discuss.elastic.co/t/logstash-filter-events-according-to-data-from-a-rest-api/255153/3 "2020-12-10T15:17:01Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
