# Logstash Filtering logs

**URL:** <https://discuss.elastic.co/t/logstash-filtering-logs/288521>\
**Category:** Logstash\
**Tags:** painless\
**Created:** [November 5, 2021, 7:22pm UTC](https://discuss.elastic.co/t/logstash-filtering-logs/288521 "2021-11-05T19:22:22Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![John\_snow](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/john_snow/32/77761_2.png) [@John\_snow](https://discuss.elastic.co/u/John_snow)\
**Post date:** [November 5, 2021, 7:22pm UTC](https://discuss.elastic.co/t/logstash-filtering-logs/288521/1 "2021-11-05T19:22:22Z")

</div>

I want to filter logs on base of account\_id and send to different output in logstash.

```auto
Log1:
{'account_id': '1234567890',
'other data': "Some_data"}

```

```auto
Log2:
{'account_id': '0987654321',
'other data': "Some_data"}

```

i want send log1 in other output and log2 in other output.  
Is there any workaround?

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [November 5, 2021, 7:55pm UTC](https://discuss.elastic.co/t/logstash-filtering-logs/288521/2 "2021-11-05T19:55:53Z")

</div>

You can use conditionals in the output section. See [here](https://discuss.elastic.co/t/field-reference-from-source-for-conditional-output/284956/5) for an example.

---

<div class="post-metadata">

**Author:** ![John\_snow](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/john_snow/32/77761_2.png) [@John\_snow](https://discuss.elastic.co/u/John_snow)\
**Post date:** [November 5, 2021, 8:13pm UTC](https://discuss.elastic.co/t/logstash-filtering-logs/288521/3 "2021-11-05T20:13:31Z")

</div>

Nice. Thanks for responding.

Can we automatically put the logs in output account wise. Let's assume we have 1000 account and i want to separate logs in S3 bucket account wise prefix.

```auto
s3 {
                bucket => "abc"
                prefix => "abc/{account_id}"
           }

```

in prefix i'm trying to use account\_id as prefix so if we have the prefix it puts the logs into that otherwise it will create new prefix with as account\_id

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [November 5, 2021, 8:20pm UTC](https://discuss.elastic.co/t/logstash-filtering-logs/288521/4 "2021-11-05T20:20:03Z")

</div>

Yes, the prefix option [does support](https://github.com/logstash-plugins/logstash-output-s3/blob/ff423724134cb5b0f0d1848a6c99fa6e27fdeb8a/lib/logstash/outputs/s3.rb#L153) sprintf references, but note the warning in the source about the number of files created.

```
 prefix => "abc/%{account_id}"
```

---

<div class="post-metadata">

**Author:** ![John\_snow](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/john_snow/32/77761_2.png) [@John\_snow](https://discuss.elastic.co/u/John_snow)\
**Post date:** [November 10, 2021, 5:18pm UTC](https://discuss.elastic.co/t/logstash-filtering-logs/288521/5 "2021-11-10T17:18:19Z")

</div>

Thanks for response.  
can we use in operator in if condition like if i wanted to check if a filed matched to some keywords like

```auto
if [type] not in ['a', 'b', 'c'] {
                drop {}
        }

```

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [November 10, 2021, 5:46pm UTC](https://discuss.elastic.co/t/logstash-filtering-logs/288521/6 "2021-11-10T17:46:31Z")

</div>

Yes, that will work.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 8, 2021, 5:46pm UTC](https://discuss.elastic.co/t/logstash-filtering-logs/288521/7 "2021-12-08T17:46:37Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
