# Redis Module - Assign keys based on message content

**URL:** <https://discuss.elastic.co/t/redis-module-assign-keys-based-on-message-content/120745>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [February 21, 2018, 12:26am UTC](https://discuss.elastic.co/t/redis-module-assign-keys-based-on-message-content/120745 "2018-02-21T00:26:04Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![EMChamp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/emchamp/32/27965_2.png) [@EMChamp](https://discuss.elastic.co/u/EMChamp)\
**Post date:** [February 21, 2018, 12:26am UTC](https://discuss.elastic.co/t/redis-module-assign-keys-based-on-message-content/120745/1 "2018-02-21T00:26:04Z")

</div>

How can I create a key setting that will check if a log message contains a string and outputs to a specific redis key? I was thinking something like this

```
output.redis:
  hosts: ["localhost"]
  keys:
    - key: "info_list"
      when.contains:
        message: "INFO"
    - key: "debug_list"
      when.contains:
        message: "DEBUG"

```

My understand of this example is it is suppose to check the line it receives from a log file and apply a corresponding key (i.e. if the message is "This is a DEBUG message" then the message will be saved to redis under the DEBUG key). However in my experience this isn't what is happening, it is simply not saving the messages to any key.

---

<div class="post-metadata">

**Author:** ![EMChamp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/emchamp/32/27965_2.png) [@EMChamp](https://discuss.elastic.co/u/EMChamp)\
**Post date:** [February 22, 2018, 6:11pm UTC](https://discuss.elastic.co/t/redis-module-assign-keys-based-on-message-content/120745/2 "2018-02-22T18:11:32Z")

</div>

Still seeing the same behavior, do I need to do more configuration before filebeat can filter based on message content?

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [February 23, 2018, 3:44pm UTC](https://discuss.elastic.co/t/redis-module-assign-keys-based-on-message-content/120745/3 "2018-02-23T15:44:31Z")

</div>

> [@EMChamp](#):
>
> However in my experience this isn't what is happening, it is simply not saving the messages to any key.

Can you check if any data is stored under `filebeat`, the default key. But if message aren't being published at all then check the Filebeat log output for issues. You might even want to enable debug logging if you don't find any errors (`logging.level: debug`).

> [@EMChamp](#):
>
> (i.e. if the message is "This is a DEBUG message" then the message will be saved to redis under the DEBUG key)

Well `debug_list` rather than `DEBUG`.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 23, 2018, 3:44pm UTC](https://discuss.elastic.co/t/redis-module-assign-keys-based-on-message-content/120745/4 "2018-03-23T15:44:31Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
