# Logstash URL parameter as tags

**URL:** https://discuss.elastic.co/t/logstash-url-parameter-as-tags/279285
**Category:** Logstash
**Created:** [July 21, 2021, 3:39pm UTC](https://discuss.elastic.co/t/logstash-url-parameter-as-tags/279285 "2021-07-21T15:39:48Z")
**Posts on this page:** 9
**Page:** 1

<div class="post-metadata">

### Author: ![juanmav](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/juanmav/32/40704_2.png) [@juanmav](https://discuss.elastic.co/u/juanmav)
#### Post date: [July 21, 2021, 3:39pm UTC](https://discuss.elastic.co/t/logstash-url-parameter-as-tags/279285/1 "2021-07-21T15:39:49Z")

</div>

Hi all,

I have this working configuration that receives logs from heroku and process then using grok and add a couple of tags from enviroments vars.

```auto
input {  
  http {    
    port => "${PORT}"    
    tags => ["${TAG}", "${ENV}"]  
  } 
}
filter {  
  if [headers][http_user_agent] =~/ELB-HealthChecker/ { drop {} }  
  grok {      
    match => { 
      "message" => [ 
                     "%{SYSLOG5424PRI:pri}%{NUMBER:rfc_version} %{TIMESTAMP_ISO8601:timestamp} d.%{UUID:drain_id} %{WORD:app} %{USERNAME:dyno} - - %{GREEDYDATA:message}",
                     "%{SYSLOG5424PRI:pri}%{NUMBER:rfc_version} %{TIMESTAMP_ISO8601:timestamp} %{WORD:host} %{WORD:app} %{USERNAME:dyno} - %{GREEDYDATA:message}"         
                   ]       
    }      
    overwrite => ["message"]      
    remove_field => ["pri", "rfc_version", "timestamp", "syslog5424_pri"] }
} 
output {  
  elasticsearch {    
    hosts => ["xxxxx"]  
  }
 }

```

But I would like to change the tags from enviroments variables to string parameters instead. Something like

[https://mylogstashurlhost/?env=staging&tag=myservicename](https://mylogstashurlhost/?env=staging&tag=myservicename)

This is to avoid creating a lot of logstash instances, so with only one or two instances we can collect logs from many sources. is this possible at all?

Thanks  
Regards  
JM

---

<div class="post-metadata">

### Author: ![AquaX](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/aquax/32/92006_2.png) [@AquaX](https://discuss.elastic.co/u/AquaX)
#### Post date: [July 22, 2021, 1:50pm UTC](https://discuss.elastic.co/t/logstash-url-parameter-as-tags/279285/2 "2021-07-22T13:50:37Z")

</div>

You can use another grok filter to take apart the URL.

```auto

filter {
  grok {
    match => ["message", "%{URIPARAM}"]
  }

{
  "URIPARAM": [
    [
      "?env=staging&tag=myservicename"
    ]
  ]
}

```

And then use the KVP filter to take that string apart.

> **[Kv filter plugin | Logstash Reference \[7.13\] | Elastic](https://www.elastic.co/guide/en/logstash/current/plugins-filters-kv.html)**

```auto
kv {
    source => "URIPARAM"
    field_split => "&"
  }

```

---

<div class="post-metadata">

### Author: ![juanmav](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/juanmav/32/40704_2.png) [@juanmav](https://discuss.elastic.co/u/juanmav)
#### Post date: [July 22, 2021, 4:55pm UTC](https://discuss.elastic.co/t/logstash-url-parameter-as-tags/279285/3 "2021-07-22T16:55:00Z")

</div>

Aquax,

Thanks for the reply. However the url I'm refering is not in the message it is the url where the my logstash instance is hosted. It is the request that logstash is receiving.

Thanks  
JM

---

<div class="post-metadata">

### Author: ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)
#### Post date: [July 22, 2021, 5:15pm UTC](https://discuss.elastic.co/t/logstash-url-parameter-as-tags/279285/4 "2021-07-22T17:15:53Z")

</div>

I do not think this is possible with the code as is. It is passed the full http request object, it [validates and deletes](https://github.com/logstash-plugins/logstash-input-http/blob/0589e21ae33127456cf348f58d9e5f27e1b7c1dd/src/main/java/org/logstash/plugins/inputs/http/MessageProcessor.java#L58) the authorization header, then it [builds the event](https://github.com/logstash-plugins/logstash-input-http/blob/0589e21ae33127456cf348f58d9e5f27e1b7c1dd/src/main/java/org/logstash/plugins/inputs/http/MessageProcessor.java#L75) from the req.headers and req.content. It does nothing with req.uri.

I think it would be a really useful enhancement to be able to access that.

---

<div class="post-metadata">

### Author: ![juanmav](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/juanmav/32/40704_2.png) [@juanmav](https://discuss.elastic.co/u/juanmav)
#### Post date: [July 22, 2021, 5:39pm UTC](https://discuss.elastic.co/t/logstash-url-parameter-as-tags/279285/5 "2021-07-22T17:39:55Z")

</div>

Badger,

Thanks for you reply. Sorry I'm not that familiar with Logstash code. But I was debuging it a bit and now I have a clear understaning of what I want 😛

I want to access request\_path and be able to parse it, I think with KV as Aquax mentioned.

```auto
logstash_1 | {
logstash_1 | "headers" => {
logstash_1 | "cache_control" => "no-cache",
logstash_1 | "content_length" => "19",
logstash_1 | "http_user_agent" => "PostmanRuntime/7.26.8",
logstash_1 | "accept_encoding" => "gzip, deflate, br",
logstash_1 | "request_method" => "POST",
logstash_1 | "http_host" => "localhost:1514",
logstash_1 | "connection" => "keep-alive",
logstash_1 | "request_path" => "/?enviroment=staging&service=rollio-core",
logstash_1 | "content_type" => "application/json",
logstash_1 | "http_version" => "HTTP/1.1",
logstash_1 | "http_accept" => "*/*",
logstash_1 | "postman_token" => "e000afa8-a9c4-4ce1-b313-c77421be92aa"
logstash_1 | },
logstash_1 | "host" => "172.19.0.1",
logstash_1 | "tags" => [
logstash_1 | [0] "rollio-nlp-idl",
logstash_1 | [1] "staging"
logstash_1 | ],
logstash_1 | "message" => "stuff stuff",
logstash_1 | "@version" => "1",
logstash_1 | "@timestamp" => 2021-07-22T17:31:55.733Z
logstash_1 | }

```

The formatHeader function is adding the uri to the headerobject.

> <https://github.com/logstash-plugins/logstash-input-http/blob/0589e21ae33127456cf348f58d9e5f27e1b7c1dd/src/main/java/org/logstash/plugins/inputs/http/MessageProcessor.java#L130>

---

<div class="post-metadata">

### Author: ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)
#### Post date: [July 22, 2021, 6:03pm UTC](https://discuss.elastic.co/t/logstash-url-parameter-as-tags/279285/6 "2021-07-22T18:03:16Z")

</div>

You are right, I missed that.

---

<div class="post-metadata">

### Author: ![AquaX](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/aquax/32/92006_2.png) [@AquaX](https://discuss.elastic.co/u/AquaX)
#### Post date: [July 22, 2021, 8:27pm UTC](https://discuss.elastic.co/t/logstash-url-parameter-as-tags/279285/7 "2021-07-22T20:27:59Z")

</div>

Yeah if you put the` [headers][request_path]` field into the kv filter it should help get you what you want.

---

<div class="post-metadata">

### Author: ![juanmav](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/juanmav/32/40704_2.png) [@juanmav](https://discuss.elastic.co/u/juanmav)
#### Post date: [July 23, 2021, 9:22am UTC](https://discuss.elastic.co/t/logstash-url-parameter-as-tags/279285/8 "2021-07-23T09:22:28Z")

</div>

Aquax,

Thanks for the reply just tested it and it worked great!

```auto
logstash_1 | {
logstash_1 | "host" => "172.19.0.1",
logstash_1 | "message" => "as",
logstash_1 | "headers" => {
logstash_1 | "request_method" => "POST",
logstash_1 | "http_host" => "localhost:1514",
logstash_1 | "http_version" => "HTTP/1.1",
logstash_1 | "cache_control" => "no-cache",
logstash_1 | "connection" => "keep-alive",
logstash_1 | "http_user_agent" => "PostmanRuntime/7.26.8",
logstash_1 | "request_path" => "/?enviroment=staging&service=rollio-core",
logstash_1 | "postman_token" => "d7dc5723-7f78-4519-9c8d-9d121b5a0125",
logstash_1 | "http_accept" => "*/*",
logstash_1 | "content_length" => "19",
logstash_1 | "content_type" => "application/json",
logstash_1 | "accept_encoding" => "gzip, deflate, br"
logstash_1 | },
logstash_1 | "service" => "rollio-core",
logstash_1 | "@timestamp" => 2021-07-23T09:15:58.811Z,
logstash_1 | "enviroment" => "staging",
logstash_1 | "@version" => "1"
logstash_1 | }

```

My complete working configuration, so others can benefit from this 🙂

```auto
input {  
  http {    
    port => "${PORT}"
  } 
}
filter {  
  if [headers][http_user_agent] =~/ELB-HealthChecker/ { drop {} }  
  grok {      
    match => { 
      "message" => [ 
                     "%{SYSLOG5424PRI:pri}%{NUMBER:rfc_version} %{TIMESTAMP_ISO8601:timestamp} d.%{UUID:drain_id} %{WORD:app} %{USERNAME:dyno} - - %{GREEDYDATA:message}",
                     "%{SYSLOG5424PRI:pri}%{NUMBER:rfc_version} %{TIMESTAMP_ISO8601:timestamp} %{WORD:host} %{WORD:app} %{USERNAME:dyno} - %{GREEDYDATA:message}"         
                   ]       
    }      
    overwrite => ["message"]      
    remove_field => ["pri", "rfc_version", "timestamp", "syslog5424_pri"]    
  }
}
filter { 
  kv { 
    source => "[headers][request_path]"    
    field_split => "&" 
    trim_key => "/?" 
  }
}
output {  
  elasticsearch {    
    hosts => ["xxxxx"]  
  }
 }

```

Thanks both for the help!

Regards  
Juan Manuel

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [August 20, 2021, 9:23am UTC](https://discuss.elastic.co/t/logstash-url-parameter-as-tags/279285/9 "2021-08-20T09:23:02Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
