# Office365 Logstash parser

**URL:** <https://discuss.elastic.co/t/office365-logstash-parser/141842>\
**Category:** Logstash\
**Created:** [July 26, 2018, 7:48pm UTC](https://discuss.elastic.co/t/office365-logstash-parser/141842 "2018-07-26T19:48:13Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![a899090](https://avatars.discourse-cdn.com/v4/letter/a/e99b99/32.png) [@a899090](https://discuss.elastic.co/u/a899090)\
**Post date:** [July 26, 2018, 7:48pm UTC](https://discuss.elastic.co/t/office365-logstash-parser/141842/1 "2018-07-26T19:48:13Z")

</div>

Hi

I need some help running this logstash config, when running in ubuntu it keeps on complaining about line 47 where it expected # or =\> but i can't see the problem with the below. Any help will be appreciated.

```
input {
    file { 
        path => "<tsv_moniter>/*.csv"
        type => "o365_tsv" 
        start_position => "beginning"
    }

    file { 
        path => "home/ct/Documents/office/*.csv"
        type => "o365_csv" 
        start_position => "beginning"
    }
}

filter {
    if ([type] == "o365_tsv") {
        csv {
            columns => ["CreationDate", "UserIds", "Operations", "AuditData"]
            skip_header => "true"
            add_tag => ["o365_csv_log"]
            # Insert a literal tab for a separator
            separator => " " 
        }

        date {
            match => ["CreationDate", "ISO8601"]
        }

        json {
            # Need to parse out embedded JSON
            source => "AuditData"
        }

        geoip {
            database => "home/ct/Documents/maximind/GeoLite2-Country.mmdb"
            source => "ClientIP"
            target => "client_geo"
        }
    }

    if ([type] == "o365_csv") {
        csv {
            columns => ["PSComputerName", "RunspaceId", "PSShowComputerName", "RecordType", "CreationDate", "UserIds", "Operations", "AuditData", "ResultIndex", "ResultCount", "Identity", "IsValid", "ObjectState"]
            skip_header => "true"
            
            # Need to drop that pesky second header
            if ([message] =~ /^#/) {
                drop {}
            }
        }

        date {
            match => ["CreationDate", "ISO8601"]
        }

        # Need to parse out embedded JSON
        json {
            source => "AuditData"
        }

        geoip {
            database => "home/ct/Documents/maximind/GeoLite2-Country.mmdb"
            source => "ClientIP"
            target => "client_geo"
        }
    }
}

output {
    elasticsearch {
        # Change me to reflect your Elastic server
        hosts => ["localhost:5601"]
        index => "o365_logs"
    }
}
```

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [July 26, 2018, 9:06pm UTC](https://discuss.elastic.co/t/office365-logstash-parser/141842/2 "2018-07-26T21:06:37Z")

</div>

You cannot have a conditional inside a filter. Move the if+drop outside of the csv.

---

<div class="post-metadata">

**Author:** ![yaauie](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yaauie/32/23363_2.png) [@yaauie](https://discuss.elastic.co/u/yaauie)\
**Post date:** [July 26, 2018, 10:28pm UTC](https://discuss.elastic.co/t/office365-logstash-parser/141842/3 "2018-07-26T22:28:18Z")

</div>

> [@a899090](#):
>
> ```auto
> # Need to drop that pesky second header
> if ([message] =~ /^#/) {
> drop {}
> }
> 
> ```

^ this is the conditional that @badger mentions as being inside of a filter.

You can use conditionals to determine whether or not a filter will be run on an event, but conditionals cannot exist inside of filters.

---

<div class="post-metadata">

**Author:** ![a899090](https://avatars.discourse-cdn.com/v4/letter/a/e99b99/32.png) [@a899090](https://discuss.elastic.co/u/a899090)\
**Post date:** [July 30, 2018, 11:09am UTC](https://discuss.elastic.co/t/office365-logstash-parser/141842/4 "2018-07-30T11:09:33Z")

</div>

thanks, i will try that and see what happens

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 27, 2018, 11:09am UTC](https://discuss.elastic.co/t/office365-logstash-parser/141842/5 "2018-08-27T11:09:36Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
