# Logstash filter help pleas

**URL:** <https://discuss.elastic.co/t/logstash-filter-help-pleas/327718>\
**Category:** Logstash\
**Created:** [March 15, 2023, 5:33am UTC](https://discuss.elastic.co/t/logstash-filter-help-pleas/327718 "2023-03-15T05:33:56Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![alexsamad](https://avatars.discourse-cdn.com/v4/letter/a/f9ae1b/32.png) [@alexsamad](https://discuss.elastic.co/u/alexsamad)\
**Post date:** [March 15, 2023, 5:33am UTC](https://discuss.elastic.co/t/logstash-filter-help-pleas/327718/1 "2023-03-15T05:33:56Z")

</div>

Hi

I'm in the process of trying to migrate my config from 6.7 to 8.x  
I have found I have to rewrite my logstash rules - okay probably a good time to do that.  
On that note - my filebeat 6.7 client worked fine, when i upgraded my client o 8.4 it started to fail - but all good.

what I would like some help on is

I base the index on the host name I have env dev1 dev2 dev3 etc. each inv has app1 app3 app5 db jmp rp so dev1app1 dev1app3 etc etc .

so i have a if then else with lots of else if basically doing this

```auto
if [host][name] =~ "^dev10" {
        mutate {
          add_field => { "env" => "dev10" }
        }
      } else if [host][name]=~ "^dev11" {
....

```

I was thinking it would be better if I can regex out the env from the hostname  
with something like

```auto
grok {
    match => {
      [host][name] => "^(?<env>)(app|geode|rp|db|jmp)"
    }
  }

```

But that doesn't work

help please

---

<div class="post-metadata">

**Author:** ![Cad](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/cad/32/86661_2.png) [@Cad](https://discuss.elastic.co/u/Cad)\
**Post date:** [March 17, 2023, 9:25am UTC](https://discuss.elastic.co/t/logstash-filter-help-pleas/327718/2 "2023-03-17T09:25:46Z")

</div>

Based on this code part :

> [@alexsamad](#):
>
> ```auto
> if [host][name] =~ "^dev10" {
> mutate {
> add_field => { "env" => "dev10" }
> }
> } else if [host][name]=~ "^dev11" {
> ....
> 
> ```

It seems you just do a copy of the `host.name` field into the `env` field.  
So you can use the `copy` option of the `mutate` filter

```auto
mutate {
    copy {
        copy => { "[host][name]" => "env" }
    }
}

```

But if your `host.name` can contain `dev1app3` and you just want the `dev1` part so grok is not a bad solution :

```auto
grok {
    match => {
      [host][name] => "(?<env>dev%{NUMBER})"
    }
}

```

Cad.

---

<div class="post-metadata">

**Author:** ![alexsamad](https://avatars.discourse-cdn.com/v4/letter/a/f9ae1b/32.png) [@alexsamad](https://discuss.elastic.co/u/alexsamad)\
**Post date:** [March 17, 2023, 12:10pm UTC](https://discuss.elastic.co/t/logstash-filter-help-pleas/327718/3 "2023-03-17T12:10:27Z")

</div>

Yes the bottom one makes sense

Thanks

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 14, 2023, 12:10pm UTC](https://discuss.elastic.co/t/logstash-filter-help-pleas/327718/4 "2023-04-14T12:10:57Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
