# Logstash + Redis

**URL:** <https://discuss.elastic.co/t/logstash-redis/289100>\
**Category:** Logstash\
**Created:** [November 12, 2021, 9:29pm UTC](https://discuss.elastic.co/t/logstash-redis/289100 "2021-11-12T21:29:41Z")\
**Posts on this page:** 10\
**Page:** 1

<div class="post-metadata">

**Author:** ![Claudio\_Ract\_Costa](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/claudio_ract_costa/32/26095_2.png) [@Claudio\_Ract\_Costa](https://discuss.elastic.co/u/Claudio_Ract_Costa)\
**Post date:** [November 12, 2021, 9:29pm UTC](https://discuss.elastic.co/t/logstash-redis/289100/1 "2021-11-12T21:29:41Z")

</div>

Hi guys,  
I am trying to figure out how to use Logstash with Redis  
Does anyone know how to configure logstash to insert a specific field in message in Redis ?

For example, I have a json message with some fields, like: Name, Passport Number, Age, ..  
I would like to insert in Redis (using redis output plugin) only the Passport Number (as Key) and Name (as Value)

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [November 12, 2021, 10:05pm UTC](https://discuss.elastic.co/t/logstash-redis/289100/2 "2021-11-12T22:05:04Z")

</div>

Simply use the mutate filter remove processor and remove the fields you do not want to send to redis

> **[Mutate filter plugin | Logstash Reference \[7.15\] | Elastic](https://www.elastic.co/guide/en/logstash/current/plugins-filters-mutate.html#plugins-filters-mutate-remove_field)**

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [November 12, 2021, 10:22pm UTC](https://discuss.elastic.co/t/logstash-redis/289100/3 "2021-11-12T22:22:21Z")

</div>

A prune filter with a whitelist\_names option is another alternative.

---

<div class="post-metadata">

**Author:** ![Claudio\_Ract\_Costa](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/claudio_ract_costa/32/26095_2.png) [@Claudio\_Ract\_Costa](https://discuss.elastic.co/u/Claudio_Ract_Costa)\
**Post date:** [November 12, 2021, 10:22pm UTC](https://discuss.elastic.co/t/logstash-redis/289100/4 "2021-11-12T22:22:57Z")

</div>

@stephenb @Badger  
I cant do it.  
There is other ouput where i need to send all the information.  
If i use mutate filter, all outputs will be affected.

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [November 12, 2021, 10:24pm UTC](https://discuss.elastic.co/t/logstash-redis/289100/5 "2021-11-12T22:24:14Z")

</div>

Use pipeline-to-pipeline communication with a [forked-path](https://www.elastic.co/guide/en/logstash/current/pipeline-to-pipeline.html#forked-path-pattern) pattern.

---

<div class="post-metadata">

**Author:** ![Claudio\_Ract\_Costa](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/claudio_ract_costa/32/26095_2.png) [@Claudio\_Ract\_Costa](https://discuss.elastic.co/u/Claudio_Ract_Costa)\
**Post date:** [November 12, 2021, 10:28pm UTC](https://discuss.elastic.co/t/logstash-redis/289100/6 "2021-11-12T22:28:28Z")

</div>

Nice, i will take a look in your suggestion.

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [November 13, 2021, 4:31am UTC](https://discuss.elastic.co/t/logstash-redis/289100/7 "2021-11-13T04:31:48Z")

</div>

I think that you can also use the `codec` option in the redis output to format the output message.

Something like this:

```auto
codec => plain { format => "%{field1} %{field2} %{fieldN}" }

```

But if you have different outputs, I would say that the pipeline-to-pipeline communication is the best approach.

---

<div class="post-metadata">

**Author:** ![Claudio\_Ract\_Costa](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/claudio_ract_costa/32/26095_2.png) [@Claudio\_Ract\_Costa](https://discuss.elastic.co/u/Claudio_Ract_Costa)\
**Post date:** [November 30, 2021, 8:22pm UTC](https://discuss.elastic.co/t/logstash-redis/289100/8 "2021-11-30T20:22:57Z")

</div>

Just to update, the solution i found to my case was put the following lines in the filter:

- to insert data in Redis (inserting data from diameter\_Session-Id and msisdn fields):

```auto
                if "3868" in [tcp_srcport] {
                    ruby {
                        init => 'require "redis"; $rc = Redis.new(host: "127.0.0.1", port: 6379)'
                        code => '
                            $rc.sadd(event.get("diameter_Session-Id"), event.get("msisdn"))
                            $rc.expire(event.get("diameter_Session-Id"), 3600)
                        '
                    }
                }

```

- to get data in Redis (retrieving data from Redis using the value of diameter\_Session-Id field as key):

```auto
                if "3868" in [tcp_dstport] {
                    ruby {
                        init => 'require "redis"; $rc = Redis.new(host: "127.0.0.1", port: 6379)'
                        code => 'event.set("msisdn_ruby", $rc.smembers(event.get("diameter_Session-Id")))'
                    }
                }

```

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [November 30, 2021, 8:44pm UTC](https://discuss.elastic.co/t/logstash-redis/289100/9 "2021-11-30T20:44:38Z")

</div>

A @@class variable should work. I don't think you ever need to use a $global variable.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 28, 2021, 8:45pm UTC](https://discuss.elastic.co/t/logstash-redis/289100/10 "2021-12-28T20:45:10Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
