# Parsing result from custom Beats

**URL:** <https://discuss.elastic.co/t/parsing-result-from-custom-beats/275574>\
**Category:** Logstash\
**Created:** [June 10, 2021, 1:04pm UTC](https://discuss.elastic.co/t/parsing-result-from-custom-beats/275574 "2021-06-10T13:04:39Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![blackberrySherbet](https://avatars.discourse-cdn.com/v4/letter/b/7cd45c/32.png) [@blackberrySherbet](https://discuss.elastic.co/u/blackberrySherbet)\
**Post date:** [June 10, 2021, 1:04pm UTC](https://discuss.elastic.co/t/parsing-result-from-custom-beats/275574/1 "2021-06-10T13:04:39Z")

</div>

I have created my own Beats and I am passing data from that Beats to logstash.

This is what I get when I print to stdout in logstash(stdout { codec =\> "rubydebug"})

```auto
{
         "agent" => {
                "type" => "custombeat",
        "ephemeral_id" => "xxxxxxxxxxxx",
                  "id" => "xxxxxxxxxxxx",
             "version" => "8.0.0",
                "name" => "helloWorld"
    },
 
          "tags" => [
        [0] "beats_input_raw_event"
    ],
      "log_line" => {
          "datetime" => "2021-06-10 00:15:16.152713",
        "data" => {
            "value" => "4",
              "type" => "LOSS"
        }
    },
           "ecs" => {
        "version" => "1.8.0"
    },
          "host" => {
        "containerized" => false,
         "architecture" => "x86_64",
                 "name" => "helloWorld",
                  "mac" => [
            [0] "xxxxxxxx",
            [1] "xxxxxxxx",
            [2] "xxxxxxxx"
        ],
             "hostname" => "helloWorld",
                   "os" => {
              "kernel" => "5.4.72-microsoft-standard-WSL2",
              "family" => "debian",
                "name" => "Ubuntu",
            "platform" => "ubuntu",
                "type" => "linux",
            "codename" => "focal",
             "version" => "20.04.2 LTS (Focal Fossa)"
        },
                   "ip" => [
            [0] "xxxxxxxxxxx",
            [1] "xxxxxxxxxxxxxxx"
        ]
    },
      "@version" => "1",
    "@timestamp" => 2021-06-10T12:52:43.867Z
}

```

All I want to print as output is the log\_line bit and nothing else. I also want to flatten the result when I print it (Right now, log\_line is a nested json).

So for this example, I want to print-

```auto
 "datetime" => "2021-06-10 00:15:16.152713",
 "value" => "4",
 "type" => "LOSS"

```

I have been having a hard time even referring to the log\_line bit in logstash and I've tried a lot of things. At this point, I am not even sure what the correct first step is. I have been stuck for a while... I'd appreciate any help or direction with the logstash filters.

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [June 10, 2021, 3:05pm UTC](https://discuss.elastic.co/t/parsing-result-from-custom-beats/275574/2 "2021-06-10T15:05:06Z")

</div>

Use prune to delete the fields you do not want

```
prune { whitelist_names => ["log_line"] }

```

Then mutate

```
mutate {
    add_field => {
        "datetime" => "%{[log_line][datetime]}"
        "type" => "%{[log_line][date][type]}"
        "value" => "%{[log_line][date][value]}"
    }
}
mutate { remove_field => ["log_line"] }
```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 8, 2021, 3:05pm UTC](https://discuss.elastic.co/t/parsing-result-from-custom-beats/275574/3 "2021-07-08T15:05:30Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
