# Logstash filter section

**URL:** <https://discuss.elastic.co/t/logstash-filter-section/176941>\
**Category:** Logstash\
**Created:** [April 15, 2019, 5:05pm UTC](https://discuss.elastic.co/t/logstash-filter-section/176941 "2019-04-15T17:05:22Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Michalis\_Kyprianou](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/michalis_kyprianou/32/43461_2.png) [@Michalis\_Kyprianou](https://discuss.elastic.co/u/Michalis_Kyprianou)\
**Post date:** [April 15, 2019, 5:05pm UTC](https://discuss.elastic.co/t/logstash-filter-section/176941/1 "2019-04-15T17:05:22Z")

</div>

Hi all

i'm just very curious to have you input on the below quotation.

find my logstash conf file

input {  
beats {  
port =\> "5044"  
client\_inactivity\_timeout =\> "600"  
ssl =\> false  
}  
}

filter {  
if [fileset][module] == "nginx" {  
if [fileset][name] == "access" {  
grok {  
match =\> { "message" =\> ["%{IPORHOST:[nginx][access][remote\_ip]} - %{DATA:[nginx][access][user\_name]} [%{HTTPDATE:[nginx][access][time]}] "%{WORD:[nginx][access][method]} %{DATA:[nginx][access][url]} HTTP/%{NUMBER:[nginx][access][http\_version]}" %{NUMBER:[nginx][access][response\_code]} %{NUMBER:[nginx][access][body\_sent][bytes]} "%{DATA:[nginx][access][referrer]}" "%{DATA:[nginx][access][agent]}""] }  
remove\_field =\> "message"  
}  
mutate {  
add\_field =\> { "read\_timestamp" =\> "%{@timestamp}" }  
convert =\> ["[geoip][coordinates]", "float"]  
}  
date {  
match =\> ["[nginx][access][time]", "dd/MMM/YYYY:H:m:s Z" ]  
remove\_field =\> "[nginx][access][time]"  
}  
useragent {  
source =\> "[nginx][access][agent]"  
target =\> "[nginx][access][user\_agent]"  
remove\_field =\> "[nginx][access][agent]"  
}  
geoip {  
source =\> "[nginx][access][remote\_ip]"  
target =\> "[geoip]"  
add\_field =\> ["[geoip][coordinates]", "%{[geoip][longitude]}" ]  
add\_field =\> ["[geoip][coordinates]", "%{[geoip][latitude]}" ]  
}  
}  
if [nginx][access][user\_agent][name] =~ "._PingdomBot_." {  
drop { }  
}  
if [nginx][access][remote\_ip] =~ "172.31.\*." {  
drop { }  
}  
else if [fileset][name] == "error" {  
grok {  
match =\> { "message" =\> ["%{DATA:[nginx][error][time]} [%{DATA:[nginx][error][level]}] %{NUMBER:[nginx][error][pid]}#%{NUMBER:[nginx][error][tid]}: (\*%{NUMBER:[nginx][error][connection\_id]} )?%{GREEDYDATA:[nginx][error][message]}"] }  
remove\_field =\> "message"  
}  
mutate {  
add\_field =\> { "read\_timestamp" =\> "%{@timestamp}" }  
}  
date {  
match =\> ["[nginx][error][time]", "YYYY/MM/dd H:m:s" ]  
remove\_field =\> "[nginx][error][time]"  
}  
}  
}  
}

filter {  
if [fileset][module] == "apache2" {  
if [fileset][name] == "access" {  
if [message] =~ "._ELB-HealthChecker_." or [message] =~ "._server-status_." {  
drop { }  
}  
grok {  
match =\> { "message" =\> ["%{IPORHOST:[apache2][access][remote\_ip]} - %{DATA:[apache2][access][user\_name]} [%{HTTPDATE:[apache2][access][time]}] "%{WORD:[apache2][access][method]} %{DATA:[apache2][access][url]} HTTP/%{NUMBER:[apache2][access][http\_version]}" %{NUMBER:[apache2][access][response\_code]} %{NUMBER:[apache2][access][body\_sent][bytes]}( "%{DATA:[apache2][access][referrer]}")?( "%{DATA:[apache2][access][agent]}")?",  
"%{IPORHOST:[apache2][access][remote\_ip]} - %{DATA:[apache2][access][user\_name]} \[%{HTTPDATE:[apache2][access][time]}\] "-" %{NUMBER:[apache2][access][response\_code]} -" ] }  
remove\_field =\> "message"  
}  
mutate {  
add\_field =\> { "read\_timestamp" =\> "%{@timestamp}" }  
}  
date {  
match =\> ["[apache2][access][time]", "dd/MMM/YYYY:H:m:s Z" ]  
remove\_field =\> "[apache2][access][time]"  
}  
useragent {  
source =\> "[apache2][access][agent]"  
target =\> "[apache2][access][user\_agent]"  
remove\_field =\> "[apache2][access][agent]"  
}  
geoip {  
source =\> "[apache2][access][remote\_ip]"  
target =\> "[geoip]"  
}  
}  
else if [fileset][name] == "error" {  
grok {  
match =\> { "message" =\> ["[%{APACHE\_TIME:[apache2][error][timestamp]}] [%{LOGLEVEL:[apache2][error][level]}]( [client %{IPORHOST:[apache2][error][client]}])? %{GREEDYDATA:[apache2][error][message]}",  
"[%{APACHE\_TIME:[apache2][error][timestamp]}] [%{DATA:[apache2][error][module]}:%{LOGLEVEL:[apache2][error][level]}] [pid %{NUMBER:[apache2][error][pid]}(:tid %{NUMBER:[apache2][error][tid]})?]( [client %{IPORHOST:[apache2][error][client]}])? %{GREEDYDATA:[apache2][error][message1]}" ] }  
pattern\_definitions =\> {  
"APACHE\_TIME" =\> "%{DAY} %{MONTH} %{MONTHDAY} %{TIME} %{YEAR}"  
}  
remove\_field =\> "message"  
}  
mutate {  
rename =\> { "[apache2][error][message1]" =\> "[apache2][error][message]" }  
}  
date {  
match =\> ["[apache2][error][timestamp]", "EEE MMM dd H:m:s YYYY", "EEE MMM dd H:m:s.SSSSSS YYYY" ]  
remove\_field =\> "[apache2][error][timestamp]"  
}  
}  
}  
}

filter {  
if [fileset][module] == "iis" {  
if [fileset][name] == "access" {  
if ([message] =~ "._ELB-HealthChecker_."){  
drop { }  
}  
grok {  
# check that fields match your IIS log settings  
match =\> ["message", "%{TIMESTAMP\_ISO8601:logtime} %{IPORHOST:s-ip} %{WORD:cs-method} %{NOTSPACE:cs-uri-stem} %{NOTSPACE:cs-uri-query} %{NUMBER:s-port} %{NOTSPACE:useragent} %{NOTSPACE:sc-status} %{NUMBER:response} %{NUMBER:subresponse} %{NUMBER:scstatus} %{NUMBER:sc-win32-status} %{IPORHOST:OriginalIP}"]  
}  
date {  
match =\> ["log\_timestamp", "YYYY-MM-dd HH:mm:ss"]  
timezone =\> "Etc/UTC"  
}  
useragent {  
source=\> "useragent"  
prefix=\> "browser"  
}  
geoip {  
source =\> "OriginalIP"  
target =\> "[geoip]"  
add\_field =\> ["[geoip][coordinates]", "%{[geoip][longitude]}" ]  
add\_field =\> ["[geoip][coordinates]", "%{[geoip][latitude]}" ]  
}  
mutate {  
#add\_field =\> ["[geoip][location]","%{[geoip][longitude]"]  
#add\_field =\> ["[geoip][location]","%{[geoip][latitude]"]  
remove\_field =\> ["log\_timestamp"]  
remove\_field =\> ["useragent"]  
remove\_field =\> ["OriginalIP"]  
#convert =\> ["[geoip][location]", "float" ]  
}  
}  
}  
}

output {

if [fileset][module] == "nginx" {  
elasticsearch {  
hosts =\> "xxxxxxxxxxxx:443"  
ssl =\> "true"  
manage\_template =\> false  
index =\> "nginx-%{+YYYY.MM.dd}"  
}  
}  
if [fileset][module] == "apache2" {  
elasticsearch {  
hosts =\> "xxxxxxxxxxxx:443"  
ssl =\> "true"  
manage\_template =\> false  
index =\> "apache2-%{+YYYY.MM.dd}"  
}  
}  
if [fields][log\_type] == "apache2" {  
elasticsearch {  
hosts =\> "xxxxxxxxxxxx:443"  
ssl =\> "true"  
manage\_template =\> false  
index =\> "apache2-errors-%{+YYYY.MM.dd}"  
}  
}  
else {  
elasticsearch {  
hosts =\> "xxxxxxxxxxxx:443"  
ssl =\> "true"  
manage\_template =\> false  
index =\> "test-%{+YYYY.MM.dd}"  
}  
}  
}

my problem

if [fileset][module] == "nginx" {  
if [fileset][name] == "access" {

this section works perfectly i can see the index nginx however the

else if [fileset][name] == "error" {

it saved in to "test-%{+YYYY.MM.dd}" index.

its correct that i have multiple filter ?

thanks  
M

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [April 15, 2019, 6:59pm UTC](https://discuss.elastic.co/t/logstash-filter-section/176941/2 "2019-04-15T18:59:23Z")

</div>

It's impossible to read your configuration when it is all left aligned. Edit your post, select the text of your configuration and click \</\> in the toolbar above the edit pane. That way it will be block-quoted and indentation will be preserved.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 13, 2019, 6:59pm UTC](https://discuss.elastic.co/t/logstash-filter-section/176941/3 "2019-05-13T18:59:24Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
