# Logstash input with filtered output

**URL:** <https://discuss.elastic.co/t/logstash-input-with-filtered-output/266951>\
**Category:** Logstash\
**Created:** [March 11, 2021, 1:08pm UTC](https://discuss.elastic.co/t/logstash-input-with-filtered-output/266951 "2021-03-11T13:08:52Z")\
**Posts on this page:** 10\
**Page:** 1

<div class="post-metadata">

**Author:** ![djehuty](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/djehuty/32/85386_2.png) [@djehuty](https://discuss.elastic.co/u/djehuty)\
**Post date:** [March 11, 2021, 1:08pm UTC](https://discuss.elastic.co/t/logstash-input-with-filtered-output/266951/1 "2021-03-11T13:08:52Z")

</div>

I need to divide Winlogbeat input and push it to two separate indices when a beat has a particular event ID.

I used an if statement but the indices seems to have the same data.  
This is my pipeline configuration:

```auto
    input {
  beats {
    port => 5045
  }
}

 output {
     elasticsearch {
      hosts => ["https://x1x:9200", "https://x2x:9200", "https://x3x:9200"]
      ssl => true
      ssl_certificate_verification => false
      user => admin
      password => admin:
      ilm_enabled => false
     index => "windows-%{+YYYY.MM.dd}"
   }
  }
if [winlog.event_id] == [4634] and [event.code] == [4635] {
   elasticsearch {
      hosts => ["https://x1x:9200", "https://x2x:9200", "https://x3x:9200"]
      ssl => true
      ssl_certificate_verification => false
      user => admin
      password => admin
      ilm_enabled => false
     index => "sharepoint-%{+YYYY.MM}"
   }
  }

```

---

<div class="post-metadata">

**Author:** ![ahmed\_charafouddine](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ahmed_charafouddine/32/45129_2.png) [@ahmed\_charafouddine](https://discuss.elastic.co/u/ahmed_charafouddine)\
**Post date:** [March 11, 2021, 1:30pm UTC](https://discuss.elastic.co/t/logstash-input-with-filtered-output/266951/2 "2021-03-11T13:30:18Z")

</div>

it is necessary to handle the if else conditions well so that everything is in the output block

---

<div class="post-metadata">

**Author:** ![djehuty](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/djehuty/32/85386_2.png) [@djehuty](https://discuss.elastic.co/u/djehuty)\
**Post date:** [March 11, 2021, 2:31pm UTC](https://discuss.elastic.co/t/logstash-input-with-filtered-output/266951/3 "2021-03-11T14:31:20Z")

</div>

> [@djehuty](#):
>
> `if [winlog.event_id] == [4634] and [event.code] == [4635]`

I have tried also this way but the result was that the logs (all of them) goes only in the sharepoint index.  
My goal is to send in sharepoint only the logs that have 4634 as winlog.event\_id, and the others (with different event\_id) in windows index.

````
```

    input {
      beats {
        port => 5045
      }
    }

     output {
      if [winlog.event_id] == [4634] and [event.code] == [4635] {
       elasticsearch {
          hosts => ["https://x1x:9200", "https://x2x:9200", "https://x3x:9200"] 
          ssl => true
          ssl_certificate_verification => false
          user => admin
          password => admin
          ilm_enabled => false
         index => "sharepoint-%{+YYYY.MM}" 
       }
     }
      else {
       elasticsearch {
          hosts => ["https://x1x:9200", "https://x2x:9200", "https://x3x:9200"] 
          ssl => true
          ssl_certificate_verification => false
          user => admin
          password => admin
          ilm_enabled => false
         index => "windows-%{+YYYY.MM.dd}"
       }
     }
    }

```

````

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [March 11, 2021, 3:59pm UTC](https://discuss.elastic.co/t/logstash-input-with-filtered-output/266951/4 "2021-03-11T15:59:06Z")

</div>

> [@djehuty](#):
>
> `if [winlog.event_id] == [4634] and [event.code] == [4635] {`

If the field name has a full stop in it then that will work. If the winlog field is an object that contains an event\_id field then that should be [winlog][event\_id]. Similarly for the [event] field. logstash does not use the same syntax for naming fields that elasticsearch and kibana do.

---

<div class="post-metadata">

**Author:** ![djehuty](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/djehuty/32/85386_2.png) [@djehuty](https://discuss.elastic.co/u/djehuty)\
**Post date:** [March 11, 2021, 4:36pm UTC](https://discuss.elastic.co/t/logstash-input-with-filtered-output/266951/5 "2021-03-11T16:36:26Z")

</div>

I've tried to change it a little bit but no luck. Also now the sharepoint index doesn't get data anymore.

Even the filter doesn't "filter" out that beat containing the user.

Here is the actual configuration 😶

```auto
    input {
      beats {
        port => 5045
      }
    }
    filter {
          if [user][name] == ["sqlSvcAcc"] {
            drop { }
          }
    }

    output {
         elasticsearch {
          hosts => ["https://x:9200", "https://x:9200", "https://x:9200"]
          ssl => true
          ssl_certificate_verification => false
          user => admin
          password => admin
          ilm_enabled => false
         index => "windows-%{+YYYY.MM.dd}"
       }
     if [winlog][event_id] == [4634] or [event][code] == [4634] {
         elasticsearch {
          hosts => ["https://x:9200", "https://x:9200", "https://x:9200"]
          ssl => true
          ssl_certificate_verification => false
          user => admin
          password => admin
          ilm_enabled => false
         index => "sharepoint-%{+YYYY.MM}"
       }
      }
    }

```

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [March 11, 2021, 4:40pm UTC](https://discuss.elastic.co/t/logstash-input-with-filtered-output/266951/6 "2021-03-11T16:40:57Z")

</div>

> [@djehuty](#):
>
> `if [winlog][event_id] == [4634]`

I have no idea how logstash parses that. If the event id is numeric you should use

```
if [winlog][event_id] == 4634

```

If it is a string then use

```
if [winlog][event_id] == "4634"

```

Similarly for [event][code].

---

<div class="post-metadata">

**Author:** ![djehuty](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/djehuty/32/85386_2.png) [@djehuty](https://discuss.elastic.co/u/djehuty)\
**Post date:** [March 12, 2021, 8:44am UTC](https://discuss.elastic.co/t/logstash-input-with-filtered-output/266951/7 "2021-03-12T08:44:25Z")

</div>

After a reboot, the configuration seems to be OK!

BUT, now i need to filter out the "4634" events id from windows index. (The sharepoint index is receveing only 4634 as it should.)

AND, sqlSvcAcc user is still not filtered somehow..

This is the actual configuration:

```auto
> 
> input {
> beats {
> port => 5045
> }
> }
> filter {
> if [user][name] == ["sqlSvcAcc"] or [related][user] == ["sqlSvcAcc"]{
> drop { }
> }
> }
> 
> output {
> elasticsearch {
> hosts => ["https://a:9200", "https://b:9200", "https://c:9200"]
> ssl => true
> ssl_certificate_verification => false
> user => admin
> password => admin
> ilm_enabled => false
> index => "windows-%{+YYYY.MM.dd}"
> }
> if [winlog][event_id] == 4624 or [event][code] == 4624 {
> elasticsearch {
> hosts => ["https://a:9200", "https://b:9200", "https://c:9200"]
> ssl => true
> ssl_certificate_verification => false
> user => admin
> password => admin
> ilm_enabled => false
> index => "sharepoint-%{+YYYY.MM}"
> }
> }
> }
> 

```

---

<div class="post-metadata">

**Author:** ![djehuty](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/djehuty/32/85386_2.png) [@djehuty](https://discuss.elastic.co/u/djehuty)\
**Post date:** [March 12, 2021, 11:56am UTC](https://discuss.elastic.co/t/logstash-input-with-filtered-output/266951/8 "2021-03-12T11:56:31Z")

</div>

After a morining of struggle i finally managed how to fix it, this is the last configuration, everything works fine. Thanks for the help.

```auto
input {
  beats {
    port => 5045
  }
}
filter {
      if [user][name] == "sqlSvcAcc" or [related][user] == "sqlSvcAcc" {
        drop { }
      }
}

output {

 if [winlog][event_id] != 4624 or [event][code] != 4624 {
     elasticsearch {
      hosts => ["https://host1:9200", "https://host2:9200", "https://host3:9200"]
      ssl => true
      ssl_certificate_verification => false
      user => admin
      password => admin
      ilm_enabled => false
     index => "windows-%{+YYYY.MM.dd}"
   }
 }
 else if [winlog][event_id] == 4624 or [event][code] == 4624{
     elasticsearch {
      hosts => ["https://host1:9200", "https://host2:9200", "https://host3:9200"]
      ssl => true
      ssl_certificate_verification => false
      user => admin
      password => admin
      ilm_enabled => false
     index => "sharepoint-%{+YYYY.MM}"
   }
  }
}

```

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [March 12, 2021, 3:48pm UTC](https://discuss.elastic.co/t/logstash-input-with-filtered-output/266951/9 "2021-03-12T15:48:18Z")

</div>

> [@djehuty](#):
>
> `if [user][name] == ["sqlSvcAcc"]`

That does not test if the [user][name] field is equal to "sqlSvcAcc". See [this](https://github.com/elastic/logstash/issues/9932) github issue for a discussion of what it does do. Remove the brackets.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 9, 2021, 3:48pm UTC](https://discuss.elastic.co/t/logstash-input-with-filtered-output/266951/10 "2021-04-09T15:48:21Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
