# Logstash transaction processing

**URL:** <https://discuss.elastic.co/t/logstash-transaction-processing/117047>\
**Category:** Logstash\
**Created:** [January 25, 2018, 1:14pm UTC](https://discuss.elastic.co/t/logstash-transaction-processing/117047 "2018-01-25T13:14:53Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![Monica1](https://avatars.discourse-cdn.com/v4/letter/m/ea666f/32.png) [@Monica1](https://discuss.elastic.co/u/Monica1)\
**Post date:** [January 25, 2018, 1:14pm UTC](https://discuss.elastic.co/t/logstash-transaction-processing/117047/1 "2018-01-25T13:14:53Z")

</div>

Hi,

I am looking for transaction specific processing in logstash. For example., I am having Linux server having one user account 'aaa' having admin access.

Incase if 'aaa' is trying to login to one Linux server with multiple logins followed by successful login i.e., if the user 'aaa' is trying to type incorrect password for two times and during the third time he is entering the password correctly.

so in /var/log/secure, I will be having below set of logs.  
Jan 25 07:41:54 localhost sshd[2347]: pam\_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=10.0.2.2 user=s249635  
Jan 25 07:41:56 localhost sshd[2347]: Failed password for s249635 from 10.0.2.2 port 57321 ssh2  
Jan 25 07:41:59 localhost unix\_chkpwd[2350]: password check failed for user (s249635)  
Jan 25 07:42:01 localhost sshd[2347]: Failed password for s249635 from 10.0.2.2 port 57321 ssh2  
Jan 25 07:42:03 localhost sshd[2347]: Accepted password for s249635 from 10.0.2.2 port 57321 ssh2  
Jan 25 07:42:04 localhost sshd[2347]: pam\_unix(sshd:session): session opened for user s249635 by (uid=0)

My requirement is I have to capture the admin user who is trying to access server with multiple logon failures followed by successful login. and the count of failed attempts.

"message",%{SYSLOGTIMESTAMP:syslog\_date}%{SYSLOGHOST:syslog\_host} sshd([%{POSINT:pid}]):authentication failure%{GREEDYDATA}user=%{USERNAME:username}"

Can you please how can I handle it for the specific transaction

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [January 25, 2018, 9:18pm UTC](https://discuss.elastic.co/t/logstash-transaction-processing/117047/2 "2018-01-25T21:18:26Z")

</div>

Logstash can't do this without custom plugins. This kind of log analysis isn't what Logstash is primarily built to do.

---

<div class="post-metadata">

**Author:** ![Monica1](https://avatars.discourse-cdn.com/v4/letter/m/ea666f/32.png) [@Monica1](https://discuss.elastic.co/u/Monica1)\
**Post date:** [January 28, 2018, 5:45pm UTC](https://discuss.elastic.co/t/logstash-transaction-processing/117047/3 "2018-01-28T17:45:38Z")

</div>

Can you please tell me what plugin I have to use in order to process the transaction ?

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [January 28, 2018, 9:45pm UTC](https://discuss.elastic.co/t/logstash-transaction-processing/117047/4 "2018-01-28T21:45:08Z")

</div>

I don't think anyone has written and published such a plugin. That's why I indicated that you'd need a custom plugin.

---

<div class="post-metadata">

**Author:** ![guyboertje](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/guyboertje/32/31592_2.png) [@guyboertje](https://discuss.elastic.co/u/guyboertje)\
**Post date:** [January 29, 2018, 2:59pm UTC](https://discuss.elastic.co/t/logstash-transaction-processing/117047/5 "2018-01-29T14:59:52Z")

</div>

@Monica1

Further to what Magnus said, what you are looking for is a kind of Complex Event Processing - Logstash does Event Stream Processing. The scenario you describe requires a time and context window and the plugin must see **all** events **in order** , meaning single worker and other constraints.

See [this for a comparison](https://softwareengineeringdaily.com/2016/02/04/stream-processing-vs-complex-event-processing/).

We have plans to introduce a form of CEP to LS but some foundation (shared state across threads and instances) work needs to take place first.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 26, 2018, 3:00pm UTC](https://discuss.elastic.co/t/logstash-transaction-processing/117047/6 "2018-02-26T15:00:02Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
