# Logstash Fingerprint Plugin Target Unchanged

**URL:** https://discuss.elastic.co/t/logstash-fingerprint-plugin-target-unchanged/352247
**Category:** Logstash
**Created:** [February 1, 2024, 5:45am UTC](https://discuss.elastic.co/t/logstash-fingerprint-plugin-target-unchanged/352247 "2024-02-01T05:45:36Z")
**Posts on this page:** 5
**Page:** 1

<div class="post-metadata">

### Author: ![Cheese](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/cheese/32/131305_2.png) [@Cheese](https://discuss.elastic.co/u/Cheese)
#### Post date: [February 1, 2024, 5:45am UTC](https://discuss.elastic.co/t/logstash-fingerprint-plugin-target-unchanged/352247/1 "2024-02-01T05:45:36Z")

</div>

HI all,

Needing some help with using the Fingerprint plugin.

I use the fingerprint plugin to generate a SHA-1 signature using a base string and a key. My logstash config file is like so:

```auto
mutate {
  add_field {
    "signature" => ""
    "signature_key" => XYZ
    "base_string" => ABC&DEF&GHI
  }
}

...

  fingerprint {
    ecs_compatibility => "disabled"
    method => "SHA1"
    key => "%{signature_key}"
    source => ["%{base_string}"]
    target => "signature"
    add_field => { "sha_success" => "yay" }
  }

...

output {
    stdout { codec => rubydebug }
}

```

Upon inspection in the terminal when running the config file:

```auto
"signature" => ""
...
"sha_success" => "yay"

```

when I am expecting "signature" to be.. a signature.

Is there something wrong with how I am calling the fingerprint plugin?

EDIT: I am using Logstash 8.11.1, tested on Logstash 8.12 and same outcome

---

<div class="post-metadata">

### Author: ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)
#### Post date: [February 1, 2024, 10:37am UTC](https://discuss.elastic.co/t/logstash-fingerprint-plugin-target-unchanged/352247/2 "2024-02-01T10:37:44Z")

</div>

> [@Cheese](#):
>
> ```auto
> fingerprint {
> ecs_compatibility => "disabled"
> method => "SHA1"
> key => "%{signature_key}"
> source => ["%{base_string}"]
> target => "signature"
> add_field => { "sha_success" => "yay" }
> }
> 
> ```

The `source` option needs to be the field name.

> The name(s) of the source field(s) whose contents will be used to create the fingerprint.

So you should use it like this:

```auto
source => ["base_string"]

```

Also, I'm not sure that using `%{signature_key}` in the `key` option would get the value of the `signature_key` or use the literal value of `%{signature_key}` as the key, didn't look at the code to confirm, not every option in every filter will support sprintf of fields.

I would use the key directly in the filter to avoid any mistakes, you there is no need to create an empty `signature` field.

---

<div class="post-metadata">

### Author: ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)
#### Post date: [February 1, 2024, 6:32pm UTC](https://discuss.elastic.co/t/logstash-fingerprint-plugin-target-unchanged/352247/3 "2024-02-01T18:32:19Z")

</div>

> [@Cheese](#):
>
> Is there something wrong with how I am calling the fingerprint plugin?

Yes. Adding to what Leandro said, the filter does not sprintf the value of the source option. It just [iterates over](https://github.com/logstash-plugins/logstash-filter-fingerprint/blob/97851b890b0237bcfb28fdab2ea0ff0820357129/lib/logstash/filters/fingerprint.rb) the members of the array. If no such field exists then the filter is a no-op.

It also does not sprintf the key option. But I would question why you are using the key option at all. Do you really need a message authentication code rather than a hash? A key is a shared secret that the receiver of the fingerprint can use to authenticate it. If you just need a hash then do not set the key option.

---

<div class="post-metadata">

### Author: ![Cheese](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/cheese/32/131305_2.png) [@Cheese](https://discuss.elastic.co/u/Cheese)
#### Post date: [February 1, 2024, 9:44pm UTC](https://discuss.elastic.co/t/logstash-fingerprint-plugin-target-unchanged/352247/4 "2024-02-01T21:44:30Z")

</div>

> [@Badger](#):
>
> It also does not sprintf the key option. But I would question why you are using the key option at all. Do you really need a message authentication code rather than a hash? A key is a shared secret that the receiver of the fingerprint can use to authenticate it. If you just need a hash then do not set the key option.

Hi all, thanks for the response 🙂 I was indeed using the source field incorrectly. For context I am trying to use OAUth1 to generate a SHA1 signature within Logstash

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [February 29, 2024, 9:44pm UTC](https://discuss.elastic.co/t/logstash-fingerprint-plugin-target-unchanged/352247/5 "2024-02-29T21:44:44Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
