# Logstash http input plugin accepting gzip file but how to detect only text format?

**URL:** <https://discuss.elastic.co/t/logstash-http-input-plugin-accepting-gzip-file-but-how-to-detect-only-text-format/240683>\
**Category:** Logstash\
**Created:** [July 10, 2020, 11:11am UTC](https://discuss.elastic.co/t/logstash-http-input-plugin-accepting-gzip-file-but-how-to-detect-only-text-format/240683 "2020-07-10T11:11:58Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![Agniv\_Gon](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/agniv_gon/32/71944_2.png) [@Agniv\_Gon](https://discuss.elastic.co/u/Agniv_Gon)\
**Post date:** [July 10, 2020, 11:11am UTC](https://discuss.elastic.co/t/logstash-http-input-plugin-accepting-gzip-file-but-how-to-detect-only-text-format/240683/1 "2020-07-10T11:11:59Z")

</div>

I am using the below conf for Logstash HTTP input plugin: I am trying to send .gz file and in header passing Content-Encoding: gzip. It is successfully doing its job but I am interested only in text format inside the gzip and not any other format. How to modify that it should accept only those .gz file which contains text format and not any other format like images/movie/pdf etc.

```auto
// Configuration
    input {
      http {
        host => "0.0.0.0"
        port => 8443
        max_pending_requests => 500
        ssl => "false"
        ssl_verify_mode => "none"
        threads => "20"
      }
    }

    output {
        file {
            path => "../../logstash-client-logs/%{[headers][application_name]}/myapplication-logstash-client-%{+yyyy-MM-dd}.log"
            codec => line { format => "%{[message]}"}
        }
    }

```

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [July 10, 2020, 5:09pm UTC](https://discuss.elastic.co/t/logstash-http-input-plugin-accepting-gzip-file-but-how-to-detect-only-text-format/240683/2 "2020-07-10T17:09:25Z")

</div>

Images are likely to contain characters that text files will not. You might be able to test this using something like

```
if [message] !~ /^[[[:alnum:]][[:space:]][[:punct:]]]*$/ { drop {} }

```

That is, if the message contains anything other than alphanumeric characters, punctuation or whitespace, discard it.

Alternatively, check for a [file signature](https://en.wikipedia.org/wiki/List_of_file_signatures) and drop anything you do not want to keep.

---

<div class="post-metadata">

**Author:** ![Agniv\_Gon](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/agniv_gon/32/71944_2.png) [@Agniv\_Gon](https://discuss.elastic.co/u/Agniv_Gon)\
**Post date:** [July 11, 2020, 1:56pm UTC](https://discuss.elastic.co/t/logstash-http-input-plugin-accepting-gzip-file-but-how-to-detect-only-text-format/240683/3 "2020-07-11T13:56:01Z")

</div>

Hi Badger,

Thanks for checking and responding to it.  
Its not working with `if [message] !~ /^[[[:alnum:]][[:space:]][[:punct:]]]*$/ { drop {} }`  
but it's working with the file signature. The only disadvantage I see with the file signature is I have to keep adding all the unwanted file signature manually in the if condition. My requirement is, I don't want anything other than text format in the logs. Do you think is there any workaround to accept only text and reject any format other than text?  
Also instead of dropping the message, is there any way to notify the client with an error message like 415 Unsupported Media Type.

```auto
// Configuration
    input {
      http {
        host => "0.0.0.0"
        port => 8443
        max_pending_requests => 500
        ssl => "false"
        ssl_verify_mode => "none"
      }
    }

    filter {
    # if [message] !~ /^[[[:alnum:]][[:space:]][[:punct:]]]*$/ { drop {} }
    if "PNG" in [message] or "%PDF-" in [message] { drop { } }
    }

    output {
        file {
            path => "../../logstash-client-logs/%{[headers][application_name]}/myapplication-logstash-client-%{+yyyy-MM-dd}.log"
            codec => line { format => "%{[message]}"}
        }

    }

```

Regards,  
Agniv

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [July 11, 2020, 5:16pm UTC](https://discuss.elastic.co/t/logstash-http-input-plugin-accepting-gzip-file-but-how-to-detect-only-text-format/240683/4 "2020-07-11T17:16:45Z")

</div>

> [@Agniv\_Gon](#):
>
> is there any way to notify the client with an error message like 415 Unsupported Media Type

No, you cannot return an error to the client.

That said, if you can write a codec (and codecs can be [quite simple](https://github.com/logstash-plugins/logstash-codec-plain/blob/master/lib/logstash/codecs/plain.rb)) you might be able to use the additional\_codecs option on the http input to run your codec for text/plain, tag the event in the codec, then drop everything that is not tagged. I am not certain it would work, but I think it is possible.

---

<div class="post-metadata">

**Author:** ![Agniv\_Gon](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/agniv_gon/32/71944_2.png) [@Agniv\_Gon](https://discuss.elastic.co/u/Agniv_Gon)\
**Post date:** [July 24, 2020, 6:51am UTC](https://discuss.elastic.co/t/logstash-http-input-plugin-accepting-gzip-file-but-how-to-detect-only-text-format/240683/5 "2020-07-24T06:51:22Z")

</div>

For files below worked, instead of beginning and ending of lines, checking for only beginning and end of the text  
`if [message] !~ /\A[[[:alnum:]][[:space:]][[:punct:]]]*\z/ { drop { } }`

Reference: [https://www.elastic.co/guide/en/beats/filebeat/current/regexp-support.html](https://www.elastic.co/guide/en/beats/filebeat/current/regexp-support.html)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 21, 2020, 6:51am UTC](https://discuss.elastic.co/t/logstash-http-input-plugin-accepting-gzip-file-but-how-to-detect-only-text-format/240683/6 "2020-08-21T06:51:23Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
