# Logstash filters not working as expected

**URL:** <https://discuss.elastic.co/t/logstash-filters-not-working-as-expected/351536>\
**Category:** Logstash\
**Created:** [January 22, 2024, 11:58am UTC](https://discuss.elastic.co/t/logstash-filters-not-working-as-expected/351536 "2024-01-22T11:58:03Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![Mansi\_Kamthane](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mansi_kamthane/32/130995_2.png) [@Mansi\_Kamthane](https://discuss.elastic.co/u/Mansi_Kamthane)\
**Post date:** [January 22, 2024, 11:58am UTC](https://discuss.elastic.co/t/logstash-filters-not-working-as-expected/351536/1 "2024-01-22T11:58:03Z")

</div>

I am working with logstash filter  
no filter works here

here is the config file of logstash

`  
input {  
tcp {  
id =\> "\*\*\*"  
port =\> \*\*\*  
codec =\> json\_lines  
}  
}

filter {  
cipher {  
algorithm =\> "aes-128-cbc"  
key =\> "0123456789abcdef0123456789abcdef"  
iv =\> "0123456789abcdef"  
mode =\> "encrypt"  
key\_size =\> 128  
base64 =\> true  
source =\> "[try][name]"  
target =\> "[try][encrypted\_name]"  
}  
mutate {  
add\_field =\> {"debug\_encrypted\_name" =\> "%[[try][encrypted\_name]]"}  
}  
}

# Output section

output {  
tcp {  
id =\> "**"  
host =\> "**"  
port =\> \*\*\*  
codec =\> "json\_lines"  
}

```
# By uncommenting the “stdout” lines below, outgoing event data is written to the log which can be accessed via the UI. 
# This can be quite convenient when debugging the configuration by allowing instant access to the event data after it has passed through.
# Please note that after debugging, “stdout” has to be deactivated by setting it as comment.
 stdout {
  codec => rubydebug { metadata => true }
 }

```

}  
`

below is the python code used to push sample data to elk:  
`  
import json  
import socket  
import time  
import os, sys  
import subprocess  
import logging

import re

data = {  
'name': 'John Doe',  
'age': 35,  
'email': 'johndoe@example.com'

}  
hit\_dict = {}  
hit\_dict['try'] = data  
hit\_dict['secret'] = '\*\*\*\*' //secret key to index  
json\_string = json.dumps(hit\_dict)  
print(hit\_dict)  
try:

```
print("HI")
sock = socket.socket(socket.AF_INET, socket.SOCK_STREAM)
server_address = (' ****',*** )
sock.connect(server_address)
print("connected")
sock.sendall(json_string.encode())

#sock.post(server_address,json.dumps(hit_dict, sort_keys=True))

```

except Exception as e:  
print("An error occurred while sending the data",e)  
finally:  
print("done")  
sock.close()  
`

so results are:  
able to see the same data in discover tab of elk but couldnt add extra field

help provided is appreciated!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 19, 2024, 11:58am UTC](https://discuss.elastic.co/t/logstash-filters-not-working-as-expected/351536/2 "2024-02-19T11:58:54Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
