# Parse log using logstash and make ecs format

**URL:** <https://discuss.elastic.co/t/parse-log-using-logstash-and-make-ecs-format/251980>\
**Category:** Logstash\
**Tags:** ecs-elastic-common-schema\
**Created:** [October 14, 2020, 2:51am UTC](https://discuss.elastic.co/t/parse-log-using-logstash-and-make-ecs-format/251980 "2020-10-14T02:51:50Z")\
**Posts on this page:** 1\
**Showing post:** 2

<div class="post-metadata">

**Author:** ![ebeahan](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ebeahan/32/78989_2.png) [@ebeahan](https://discuss.elastic.co/u/ebeahan)\
**Post date:** [October 14, 2020, 4:56pm UTC](https://discuss.elastic.co/t/parse-log-using-logstash-and-make-ecs-format/251980/2 "2020-10-14T16:56:47Z")

</div>

Hi @111387!

I don't have a specific example Logstash config for either a WAF or network scan log to direct you towards. I encourage you to review some of the past discussion threads discussing Logstash and ECS for general guidance, such as [here](https://discuss.elastic.co/t/migrating-logstash-filters-to-ecs/193866) and [here](https://discuss.elastic.co/t/logstash-to-ecs/193994).

As you build out your Logstash ingest pipelines, you'll want to look carefully not only at the correct field names but at the field data types as well. The ECS GitHub repo also contains some additional resources to help, including example Elasticsearch [index templates](https://github.com/elastic/ecs/tree/master/generated/elasticsearch) and [tooling](https://github.com/elastic/ecs/blob/master/USAGE.md) to help users manage their own custom field definitions.

I'd also highly recommend reviewing the following areas of the ECS documentation:

- [Guidelines and best practices](https://www.elastic.co/guide/en/ecs/current/ecs-guidelines.html)
- [Conventions](https://www.elastic.co/guide/en/ecs/current/ecs-conventions.html)
- [Custom fields](https://www.elastic.co/guide/en/ecs/current/ecs-custom-fields-in-ecs.html) (for when fields from your data source don't map into existing ECS fields)

---

_[View the full topic](https://discuss.elastic.co/t/parse-log-using-logstash-and-make-ecs-format/251980)._
