# Parsing log

**URL:** <https://discuss.elastic.co/t/parsing-log/232289>\
**Category:** Logstash\
**Created:** [May 12, 2020, 6:07pm UTC](https://discuss.elastic.co/t/parsing-log/232289 "2020-05-12T18:07:40Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Luiss\_Anggel\_Carbone](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/luiss_anggel_carbone/32/68182_2.png) [@Luiss\_Anggel\_Carbone](https://discuss.elastic.co/u/Luiss_Anggel_Carbone)\
**Post date:** [May 12, 2020, 6:07pm UTC](https://discuss.elastic.co/t/parsing-log/232289/1 "2020-05-12T18:07:41Z")

</div>

Hello greetings  
I made the configuration to integrate FileBeat, Logstash, and Elastic.  
I need to create a filter every time I find an ERROR in the log. Any solution for this?  
Where can I find documentation on this, I am starting to use these tools.

---

<div class="post-metadata">

**Author:** ![andres-perez](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andres-perez/32/136461_2.png) [@andres-perez](https://discuss.elastic.co/u/andres-perez)\
**Post date:** [May 13, 2020, 8:28am UTC](https://discuss.elastic.co/t/parsing-log/232289/2 "2020-05-13T08:28:15Z")

</div>

Hi!

You can take a look at [https://www.elastic.co/blog/a-practical-introduction-to-logstash](https://www.elastic.co/blog/a-practical-introduction-to-logstash) to start configuring logstash filters.

---

<div class="post-metadata">

**Author:** ![Luiss\_Anggel\_Carbone](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/luiss_anggel_carbone/32/68182_2.png) [@Luiss\_Anggel\_Carbone](https://discuss.elastic.co/u/Luiss_Anggel_Carbone)\
**Post date:** [May 13, 2020, 1:36pm UTC](https://discuss.elastic.co/t/parsing-log/232289/3 "2020-05-13T13:36:20Z")

</div>

Hi, thanks you.

input {  
beats {  
port =\> "5044"  
}  
}

# The filter part of this file is commented out to indicate that it is

# optional.

filter {  
grok {  
match =\> { "message" =\> "%{DATE:fecha} %{TIME:time} %{LOGLEVEL:logLevel} %{GREEDYDATA:data}" }  
}  
date {  
match =\> ["timestamp" , "dd/MMM/yyyy:HH:mm:ss Z"]  
}  
}

output {  
elasticsearch { hosts =\> ["localhost:9200"] }  
stdout { codec =\> rubydebug }  
}

I would like to know how to consume this information through a web service through elastic. Any recommendation ?

---

<div class="post-metadata">

**Author:** ![andres-perez](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andres-perez/32/136461_2.png) [@andres-perez](https://discuss.elastic.co/u/andres-perez)\
**Post date:** [May 14, 2020, 6:40pm UTC](https://discuss.elastic.co/t/parsing-log/232289/4 "2020-05-14T18:40:14Z")

</div>

> [@Luiss\_Anggel\_Carbone](#):
>
> I would like to know how to consume this information through a web service through elastic. Any recommendation ?

I think you should add more information about your intended use case.

For example, you can use alerting (depending on your elastic subscription) to search within the ingested data in elasticsearch and send information to a webservice when errors are found.

I associate the idea of consumption more with queues and other services like Redis, Kafka, etc, but for sure there are multliple solutions that fit your purpose.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 11, 2020, 6:40pm UTC](https://discuss.elastic.co/t/parsing-log/232289/5 "2020-06-11T18:40:20Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
