# Modelling to Elastic Common Schema (ECS): Best practices in logstash

**URL:** <https://discuss.elastic.co/t/modelling-to-elastic-common-schema-ecs-best-practices-in-logstash/242597>\
**Category:** Logstash\
**Created:** [July 25, 2020, 8:22am UTC](https://discuss.elastic.co/t/modelling-to-elastic-common-schema-ecs-best-practices-in-logstash/242597 "2020-07-25T08:22:15Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![kelk](https://avatars.discourse-cdn.com/v4/letter/k/13edae/32.png) [@kelk](https://discuss.elastic.co/u/kelk)\
**Post date:** [July 25, 2020, 8:22am UTC](https://discuss.elastic.co/t/modelling-to-elastic-common-schema-ecs-best-practices-in-logstash/242597/1 "2020-07-25T08:22:15Z")

</div>

hi  
Being a big fan of ECS, I understand most of them are built-in for known products and technology if beats does it, but how to tackle it at logstash?

My scenario is like

- Data arrives to data lake via syslog and is in RFC5424
- Beats pick it up and sends without modification to logstash (So module used here)
- Logstash does the Data modelling and transformations
- If I used the patterns like "[linux syslog](https://github.com/elastic/elasticsearch/blob/7.8/libs/grok/src/main/resources/patterns/linux-syslog)" , the fields are NOT in ECS
- While the syslog fields syslog5424\_host etc are good quality extractions

So my query is

1. How to make the fields extracted from the patterns into ECS fields?
2. Should I do "mutate" in my custom filters one by one? Or is there a easier/better way?

I'm currently planning to do something like in logstash... (Just checking if this is the efficient way)

> filter {  
> mutate {  
> copy =\> { '[srcip]' =\> '[source][address]' }  
> copy =\> { '[srcip]' =\> '[source][ip]' }  
> copy =\> { '[new\_event][srcip]' =\> '[source][ip]' }  
> rename =\> { '[srcport]' =\> '[source][port]' }  
> convert =\> { '[source][port]' =\> 'integer' }  
> copy =\> { '[destip]' =\> '[destination][address]' }  
> }  
> }

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 22, 2020, 8:22am UTC](https://discuss.elastic.co/t/modelling-to-elastic-common-schema-ecs-best-practices-in-logstash/242597/2 "2020-08-22T08:22:20Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
