# Logstash filter plugin

**URL:** <https://discuss.elastic.co/t/logstash-filter-plugin/199359>\
**Category:** Logstash\
**Created:** [September 13, 2019, 5:59am UTC](https://discuss.elastic.co/t/logstash-filter-plugin/199359 "2019-09-13T05:59:36Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![RAM\_NATHAN](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ram_nathan/32/50393_2.png) [@RAM\_NATHAN](https://discuss.elastic.co/u/RAM_NATHAN)\
**Post date:** [September 13, 2019, 5:59am UTC](https://discuss.elastic.co/t/logstash-filter-plugin/199359/1 "2019-09-13T05:59:36Z")

</div>

Hi

I'm using logstash 7.0 . I'm having multiple events to filter. Instead of having one single config file, I prefer to have multiple filter config files for each event. As an example, I'm having a login event and I store that filter config in separate file.  
I wish to give file path in filter as below

filter  
{  
if [I]=="login\_event"  
{  
file {  
path =\> "/home/logstash/config/login\_event.txt"  
}  
}  
else if[I] == "other\_event"  
{  
file {  
path =\> "/home/logstash/config/other\_event.txt"  
}  
}  
}

but I saw there is no file plugin available in filter. Is there any other way

---

<div class="post-metadata">

**Author:** ![rugenl](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rugenl/32/12887_2.png) [@rugenl](https://discuss.elastic.co/u/rugenl)\
**Post date:** [September 14, 2019, 1:00am UTC](https://discuss.elastic.co/t/logstash-filter-plugin/199359/2 "2019-09-14T01:00:27Z")

</div>

The best way is to use logstash pipelines.

But, all files in logtash/conf.d are read in order to build the config, so just use files like these, containing fragments of the total config.

00-input  
01-filter-login  
02-filter-other  
99-output

---

<div class="post-metadata">

**Author:** ![muawanah\_Muaw](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/muawanah_muaw/32/45610_2.png) [@muawanah\_Muaw](https://discuss.elastic.co/u/muawanah_Muaw)\
**Post date:** [September 14, 2019, 1:11am UTC](https://discuss.elastic.co/t/logstash-filter-plugin/199359/3 "2019-09-14T01:11:12Z")

</div>

There is no only me

---

<div class="post-metadata">

**Author:** ![RAM\_NATHAN](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ram_nathan/32/50393_2.png) [@RAM\_NATHAN](https://discuss.elastic.co/u/RAM_NATHAN)\
**Post date:** [September 16, 2019, 5:37am UTC](https://discuss.elastic.co/t/logstash-filter-plugin/199359/4 "2019-09-16T05:37:27Z")

</div>

But I'm having a conditional behavior for login & other which is inside filter. How to achieve that?? Also should I create this conf.d??

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 14, 2019, 5:37am UTC](https://discuss.elastic.co/t/logstash-filter-plugin/199359/5 "2019-10-14T05:37:29Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
