# Logstash microsoft-sentinel-logstash-output-plugin

**URL:** <https://discuss.elastic.co/t/logstash-microsoft-sentinel-logstash-output-plugin/324787>\
**Category:** Logstash\
**Created:** [February 6, 2023, 11:07am UTC](https://discuss.elastic.co/t/logstash-microsoft-sentinel-logstash-output-plugin/324787 "2023-02-06T11:07:14Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![shadu88](https://avatars.discourse-cdn.com/v4/letter/s/e19b73/32.png) [@shadu88](https://discuss.elastic.co/u/shadu88)\
**Post date:** [February 6, 2023, 11:07am UTC](https://discuss.elastic.co/t/logstash-microsoft-sentinel-logstash-output-plugin/324787/1 "2023-02-06T11:07:14Z")

</div>

Hello ELKs,  
Hope you doing well!!  
has anyone tried IF ELSE condition in "microsoft-sentinel-logstash-output-plugin" output logstash plugin?  
I'm trying to forward the logs based on log source type to respective DCR endpoint.

Any leads or reference will be appreciated !  
thank You!!

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [February 6, 2023, 6:00pm UTC](https://discuss.elastic.co/t/logstash-microsoft-sentinel-logstash-output-plugin/324787/2 "2023-02-06T18:00:51Z")

</div>

There is an example of a conditional around (not in) an output [here](https://discuss.elastic.co/t/problem-with-conditional-in-output-definition/74302/2).

---

<div class="post-metadata">

**Author:** ![shadu88](https://avatars.discourse-cdn.com/v4/letter/s/e19b73/32.png) [@shadu88](https://discuss.elastic.co/u/shadu88)\
**Post date:** [February 7, 2023, 5:27am UTC](https://discuss.elastic.co/t/logstash-microsoft-sentinel-logstash-output-plugin/324787/3 "2023-02-07T05:27:30Z")

</div>

Hello @magnusbaeck,

Thank you for your response.

Here is my config:  
output {  
if [message] =~ "MSWinEventLog" {  
microsoft-sentinel-logstash-output-plugin {  
client\_app\_Id =\> "abc"  
client\_app\_secret =\> "xyz"  
tenant\_id =\> "qaz"  
data\_collection\_endpoint =\> "rty"  
dcr\_immutable\_id =\> "nmo"  
dcr\_stream\_name =\> "Custom-SecurityEventStream"  
}  
}  
else if [message] =~ "junos@" {  
microsoft-sentinel-logstash-output-plugin {  
client\_app\_Id =\> "abc"  
client\_app\_secret =\> "xyz"  
tenant\_id =\> "qaz"  
data\_collection\_endpoint =\> "rty"  
dcr\_immutable\_id =\> "nm"  
dcr\_stream\_name =\> "Custom-CommonSecurityLogStream"

```
    }

```

}  
else {  
microsoft-sentinel-logstash-output-plugin {  
client\_app\_Id =\> "abc"  
client\_app\_secret =\> "xyz"  
tenant\_id =\> "qaz"  
data\_collection\_endpoint =\> "rty"  
dcr\_immutable\_id =\> "nmo"  
dcr\_stream\_name =\> "Custom-SyslogStream"

```
     }

```

}  
}

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 7, 2023, 5:27am UTC](https://discuss.elastic.co/t/logstash-microsoft-sentinel-logstash-output-plugin/324787/4 "2023-03-07T05:27:48Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
