# Logstash pattern or dsl query

**URL:** <https://discuss.elastic.co/t/logstash-pattern-or-dsl-query/71203>\
**Category:** Logstash\
**Created:** [January 11, 2017, 10:39am UTC](https://discuss.elastic.co/t/logstash-pattern-or-dsl-query/71203 "2017-01-11T10:39:13Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![Lucifer\_hbp](https://avatars.discourse-cdn.com/v4/letter/l/a6a055/32.png) [@Lucifer\_hbp](https://discuss.elastic.co/u/Lucifer_hbp)\
**Post date:** [January 11, 2017, 10:39am UTC](https://discuss.elastic.co/t/logstash-pattern-or-dsl-query/71203/1 "2017-01-11T10:39:13Z")

</div>

Hi,  
I have following kind of logs:

DEBUG 20161219T172835.101-05:00 59 Client start  
DEBUG 20161219T172835.101-05:00 59 Client v=1  
DEBUG 20161219T172835.101-05:00 59 Client v=2  
DEBUG 20161219T172835.461-05:00 59 Client end  
INFO 20161219T172835.461-05:00 - Initializing v  
INFO 20161219T172835.461-05:00 - v initialized  
DEBUG 20161219T172734.179-05:00 30 Client start  
DEBUG 20161219T172734.179-05:00 30 Client v=4  
DEBUG 20161219T172734.179-05:00 30 Client v=5  
DEBUG 20161219T172734.539-05:00 30 Client end

Now i want to capture all the events occurred between keywords "start" & "end" . Could anyone suggest how write configuration for logstash or any DSL query to achieve this...  
Thanks

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [January 12, 2017, 1:57am UTC](https://discuss.elastic.co/t/logstash-pattern-or-dsl-query/71203/2 "2017-01-12T01:57:39Z")

</div>

What do you have so far?

---

<div class="post-metadata">

**Author:** ![Lucifer\_hbp](https://avatars.discourse-cdn.com/v4/letter/l/a6a055/32.png) [@Lucifer\_hbp](https://discuss.elastic.co/u/Lucifer_hbp)\
**Post date:** [January 12, 2017, 6:24am UTC](https://discuss.elastic.co/t/logstash-pattern-or-dsl-query/71203/3 "2017-01-12T06:24:53Z")

</div>

I have indexed log file into following fields: loglevel ,timestamp,client ,value

Now i want only those events that are present between consecutive start & end keywords(value field)!!!!

Right now i could find some information related to logstash aggregate-plugin that might be of help, please help if it could be done...  
Thanks

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [January 12, 2017, 6:35am UTC](https://discuss.elastic.co/t/logstash-pattern-or-dsl-query/71203/4 "2017-01-12T06:35:27Z")

</div>

Right, but what do you have, what config?  
I don't want to come across rude, but we aren't going to write if for you. We're more than happy to help you adapt what you have though 🙂

---

<div class="post-metadata">

**Author:** ![fbaligand](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/fbaligand/32/5657_2.png) [@fbaligand](https://discuss.elastic.co/u/fbaligand)\
**Post date:** [February 5, 2017, 6:01pm UTC](https://discuss.elastic.co/t/logstash-pattern-or-dsl-query/71203/5 "2017-02-05T18:01:13Z")

</div>

If you want to discard start/end lines, you can simply use something like :

if [message] =~ "start|end" {  
drop{}  
}

If you want that log lines "v=INT" are aggregated into only one document, then you have to use aggregate filter.  
And if so, what is the final expected document ?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 5, 2017, 6:01pm UTC](https://discuss.elastic.co/t/logstash-pattern-or-dsl-query/71203/6 "2017-03-05T18:01:23Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
