# Regroupe LDAP log lines with same id on the same DataTable

**URL:** https://discuss.elastic.co/t/regroupe-ldap-log-lines-with-same-id-on-the-same-datatable/157871
**Category:** Logstash
**Created:** [November 22, 2018, 12:09pm UTC](https://discuss.elastic.co/t/regroupe-ldap-log-lines-with-same-id-on-the-same-datatable/157871 "2018-11-22T12:09:58Z")
**Posts on this page:** 7
**Page:** 1

<div class="post-metadata">

### Author: ![Noureddine\_Brahmi](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/noureddine_brahmi/32/62092_2.png) [@Noureddine\_Brahmi](https://discuss.elastic.co/u/Noureddine_Brahmi)
#### Post date: [November 22, 2018, 12:09pm UTC](https://discuss.elastic.co/t/regroupe-ldap-log-lines-with-same-id-on-the-same-datatable/157871/1 "2018-11-22T12:09:58Z")

</div>

Hello,

I'm currently working on an ElasticSearch project that monitors LDAP logs.

In the LDAP logs, related events shares the same id (connection\_number). I was wondering is there is a solution to regroupe the various fieds in different documents that shares the same id.

Ex:

[04/Aug/2018:22:34:15 +0200] conn=184214 op=0 msgId=1 - BIND dn="cn=XOPOY,ou=programs,o=psa" method=128 version=3

[04/Aug/2018:22:34:15 +0200] conn=184214 op=0 msgId=1 - RESULT err=0 tag=97 nentries=0 etime=0.000450 dn="cn=mwplim02,ou=programs,o=psa"

[04/Aug/2018:22:34:15 +0200] conn=184214 op=2 msgId=3 - UNBIND

The goal is to have a datatable with:

**TIMESTAMP | conn | dn (from the BIND) | err | etime**

PS: I already have a grok filter in place that sperates the various fields

Thank you !

(I already posted this question in the Kibana Forum, and I was asked to rather ask it here)

---

<div class="post-metadata">

### Author: ![Eniqmatic](https://avatars.discourse-cdn.com/v4/letter/e/ea5d25/32.png) [@Eniqmatic](https://discuss.elastic.co/u/Eniqmatic)
#### Post date: [November 22, 2018, 12:28pm UTC](https://discuss.elastic.co/t/regroupe-ldap-log-lines-with-same-id-on-the-same-datatable/157871/2 "2018-11-22T12:28:14Z")

</div>

Would the aggregate filter work?

[https://www.elastic.co/guide/en/logstash/current/plugins-filters-aggregate.html](https://www.elastic.co/guide/en/logstash/current/plugins-filters-aggregate.html)

---

<div class="post-metadata">

### Author: ![Noureddine\_Brahmi](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/noureddine_brahmi/32/62092_2.png) [@Noureddine\_Brahmi](https://discuss.elastic.co/u/Noureddine_Brahmi)
#### Post date: [November 22, 2018, 12:37pm UTC](https://discuss.elastic.co/t/regroupe-ldap-log-lines-with-same-id-on-the-same-datatable/157871/4 "2018-11-22T12:37:36Z")

</div>

It might but the problem is :

Most of the time between a **BIND** and an **UNBIND** thousands of lines and operation would come in between, and even other conn with different conn IDs. So I don't know if it's a viable solution.

I thought about adding the dn ( from the BIND ) to each line that has the same conn ID. But I don't if/how I can implement it in logstash.

---

<div class="post-metadata">

### Author: ![Eniqmatic](https://avatars.discourse-cdn.com/v4/letter/e/ea5d25/32.png) [@Eniqmatic](https://discuss.elastic.co/u/Eniqmatic)
#### Post date: [November 22, 2018, 12:39pm UTC](https://discuss.elastic.co/t/regroupe-ldap-log-lines-with-same-id-on-the-same-datatable/157871/5 "2018-11-22T12:39:19Z")

</div>

Is there a clear start and end event though? If so then aggregate should work?

---

<div class="post-metadata">

### Author: ![Noureddine\_Brahmi](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/noureddine_brahmi/32/62092_2.png) [@Noureddine\_Brahmi](https://discuss.elastic.co/u/Noureddine_Brahmi)
#### Post date: [November 22, 2018, 12:49pm UTC](https://discuss.elastic.co/t/regroupe-ldap-log-lines-with-same-id-on-the-same-datatable/157871/7 "2018-11-22T12:49:00Z")

</div>

Yes there is a clear start and end .

The start event is operation\_type = BIND, the end is operation\_type = UNBIND.

(the seperated fields of each log line are already in place)

---

<div class="post-metadata">

### Author: ![Eniqmatic](https://avatars.discourse-cdn.com/v4/letter/e/ea5d25/32.png) [@Eniqmatic](https://discuss.elastic.co/u/Eniqmatic)
#### Post date: [November 22, 2018, 1:09pm UTC](https://discuss.elastic.co/t/regroupe-ldap-log-lines-with-same-id-on-the-same-datatable/157871/8 "2018-11-22T13:09:28Z")

</div>

So do you not think aggregate would work?

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [December 20, 2018, 1:09pm UTC](https://discuss.elastic.co/t/regroupe-ldap-log-lines-with-same-id-on-the-same-datatable/157871/9 "2018-12-20T13:09:32Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
