# One filter file for multiple filter plugins for different patterns

**URL:** <https://discuss.elastic.co/t/one-filter-file-for-multiple-filter-plugins-for-different-patterns/141365>\
**Category:** Logstash\
**Created:** [July 24, 2018, 11:39am UTC](https://discuss.elastic.co/t/one-filter-file-for-multiple-filter-plugins-for-different-patterns/141365 "2018-07-24T11:39:20Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![atgaurav](https://avatars.discourse-cdn.com/v4/letter/a/a9adbd/32.png) [@atgaurav](https://discuss.elastic.co/u/atgaurav)\
**Post date:** [July 24, 2018, 11:39am UTC](https://discuss.elastic.co/t/one-filter-file-for-multiple-filter-plugins-for-different-patterns/141365/1 "2018-07-24T11:39:20Z")

</div>

I am trying to process 2 files, each with data of different patterns.  
I have 2 individual filter configuration files which are working fine when parsing each respective file.  
I need help in consolidating one filter configuration file for logstash which should be able to parse all these 2 different pattern log files.  
Source is filebeat.  
Condition of filter plugins is path of the file on each server. e.g. /var/log/type1/\*.log.

I am thinking to use a configuration

input {  
beats {  
port =\> 5044  
}  
}

filter {  
if [path] == "custom/log/type1/\*.csv"  
{  
csv {  
autodetect\_column\_names =\> true  
separator =\> ","  
}  
mutate { add\_field =\> {"received \_at" =\> "%{@timestamp}"}}

```
}

elseif [path] == "custom/log/type2/.*log"
{
  grok {
    match => { "message" => "%{TIME:timestamp}%{SPACE}%{WORD:Log-Level}%{SPACE}%{NOTSPACE:Java-class}:%{NUMBER:line-no}%{SPACE}-%{SPACE}%{GREEDYDATA:Log-Message}"
  }

}

```

}

output {  
elasticsearch {  
hosts =\> "_._._._:9200"  
sniffing =\> true  
manage\_template =\> false  
index =\> "%{[@metadata][beat]}-%{+YYYY.MM.dd}"  
}  
stdout { codec =\> rubydebug}  
}

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 21, 2018, 11:39am UTC](https://discuss.elastic.co/t/one-filter-file-for-multiple-filter-plugins-for-different-patterns/141365/2 "2018-08-21T11:39:24Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
