# Parsing events before forwarding

**URL:** <https://discuss.elastic.co/t/parsing-events-before-forwarding/228330>\
**Category:** Logstash\
**Created:** [April 16, 2020, 1:32pm UTC](https://discuss.elastic.co/t/parsing-events-before-forwarding/228330 "2020-04-16T13:32:21Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![calebhoch](https://avatars.discourse-cdn.com/v4/letter/c/77aa72/32.png) [@calebhoch](https://discuss.elastic.co/u/calebhoch)\
**Post date:** [April 16, 2020, 1:32pm UTC](https://discuss.elastic.co/t/parsing-events-before-forwarding/228330/1 "2020-04-16T13:32:21Z")

</div>

Hi there, we're looking into leveraging Logstash to forward our system logs to our SIEM, QRadar. I wanted to know if there is a way to filter out specific events with Logstash before forwarding onto QRadar.

Any help or documentation is much appreciated!

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [April 16, 2020, 1:41pm UTC](https://discuss.elastic.co/t/parsing-events-before-forwarding/228330/2 "2020-04-16T13:41:57Z")

</div>

You can use [conditionals](https://www.elastic.co/guide/en/logstash/current/event-dependent-configuration.html) and a drop {} filter to do this.

---

<div class="post-metadata">

**Author:** ![Fabio-sama](https://avatars.discourse-cdn.com/v4/letter/f/b9e5f3/32.png) [@Fabio-sama](https://discuss.elastic.co/u/Fabio-sama)\
**Post date:** [April 16, 2020, 2:40pm UTC](https://discuss.elastic.co/t/parsing-events-before-forwarding/228330/3 "2020-04-16T14:40:48Z")

</div>

Sure there is a way, as Badger suggested. If you post here a concrete example of what your input is and how you wanna filter it we might help you even further.

---

<div class="post-metadata">

**Author:** ![calebhoch](https://avatars.discourse-cdn.com/v4/letter/c/77aa72/32.png) [@calebhoch](https://discuss.elastic.co/u/calebhoch)\
**Post date:** [April 16, 2020, 2:55pm UTC](https://discuss.elastic.co/t/parsing-events-before-forwarding/228330/4 "2020-04-16T14:55:00Z")

</div>

Thank you both! I don't have any concrete examples yet... We are looking at this to forward to our SIEM, but we don't have it setup yet. Just making sure I have the capability to filter out specific events that we don't need to ingest into the SIEM to control costs. When I do get some events, I will circle back here.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 14, 2020, 2:55pm UTC](https://discuss.elastic.co/t/parsing-events-before-forwarding/228330/5 "2020-05-14T14:55:07Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
