# Saving request.url variable in filebeat httpjson

**URL:** <https://discuss.elastic.co/t/saving-request-url-variable-in-filebeat-httpjson/286700>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [October 14, 2021, 9:22am UTC](https://discuss.elastic.co/t/saving-request-url-variable-in-filebeat-httpjson/286700 "2021-10-14T09:22:12Z")\
**Posts on this page:** 10\
**Page:** 1

<div class="post-metadata">

**Author:** ![vladislav](https://avatars.discourse-cdn.com/v4/letter/v/bbce88/32.png) [@vladislav](https://discuss.elastic.co/u/vladislav)\
**Post date:** [October 14, 2021, 9:22am UTC](https://discuss.elastic.co/t/saving-request-url-variable-in-filebeat-httpjson/286700/1 "2021-10-14T09:22:12Z")

</div>

Good day! The question arose, is it possible to save the last received value of the request.url parameter and then read from it upon request?  
I use httpjson as an input module with the following settings:

```auto
# ============================== Filebeat inputs ===============================

filebeat.inputs:

- type: httpjson
  config_version: 2
  interval: 1m
  request.url: https://mysite.com/api/v2/data/updated?updateID=12345
  request.method: GET
  auth.basic.enabled: true
  auth.basic.user: login
  auth.basic.password: password
  request.transforms:
    - set:
        target: url.params.updateID
        value: '[[.last_response.body.updateID]]'

```

In response, I receive data, from which, using request.transforms, the updateID parameter is taken from the last received data and substituted into the original request, which allows me to receive only data starting from the last updateID. Everything works correctly, as long as there is no need to restart filebeat. Data with ID 12345 is re-received and only then actual data. Is it possible to save the received updateID value from the last request somewhere and read from it in the future?

---

<div class="post-metadata">

**Author:** ![legoguy1000](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/legoguy1000/32/54301_2.png) [@legoguy1000](https://discuss.elastic.co/u/legoguy1000)\
**Post date:** [October 16, 2021, 10:47pm UTC](https://discuss.elastic.co/t/saving-request-url-variable-in-filebeat-httpjson/286700/2 "2021-10-16T22:47:34Z")

</div>

Yes using the `cursor`. See [HTTP JSON input | Filebeat Reference [7.15] | Elastic](https://www.elastic.co/guide/en/beats/filebeat/current/filebeat-input-httpjson.html#cursor)

---

<div class="post-metadata">

**Author:** ![vladislav](https://avatars.discourse-cdn.com/v4/letter/v/bbce88/32.png) [@vladislav](https://discuss.elastic.co/u/vladislav)\
**Post date:** [October 18, 2021, 9:32am UTC](https://discuss.elastic.co/t/saving-request-url-variable-in-filebeat-httpjson/286700/3 "2021-10-18T09:32:50Z")

</div>

Thank you, it works!  
Do you know how to clear state of the cursor, to process again from the beginning?  
Where it keeps it condition?

---

<div class="post-metadata">

**Author:** ![legoguy1000](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/legoguy1000/32/54301_2.png) [@legoguy1000](https://discuss.elastic.co/u/legoguy1000)\
**Post date:** [October 18, 2021, 1:56pm UTC](https://discuss.elastic.co/t/saving-request-url-variable-in-filebeat-httpjson/286700/4 "2021-10-18T13:56:09Z")

</div>

What do u mean exactly? When u set the cursor it updates on every run based off the value you set and u can set multiple cursor variables. What would be the use case to clear it? I don't think there is a way to do that.

---

<div class="post-metadata">

**Author:** ![vladislav](https://avatars.discourse-cdn.com/v4/letter/v/bbce88/32.png) [@vladislav](https://discuss.elastic.co/u/vladislav)\
**Post date:** [October 18, 2021, 2:41pm UTC](https://discuss.elastic.co/t/saving-request-url-variable-in-filebeat-httpjson/286700/5 "2021-10-18T14:41:17Z")

</div>

If I get some data using httpjson-cursor and then delete index, containing data from it I can't get this data again. Maybe I doing something wrong?

---

<div class="post-metadata">

**Author:** ![legoguy1000](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/legoguy1000/32/54301_2.png) [@legoguy1000](https://discuss.elastic.co/u/legoguy1000)\
**Post date:** [October 18, 2021, 3:09pm UTC](https://discuss.elastic.co/t/saving-request-url-variable-in-filebeat-httpjson/286700/6 "2021-10-18T15:09:56Z")

</div>

Ohh so you're atalking about clearing it manually?? I suspect its stored in the registry file but not 100%, you'll have to try that and see.

---

<div class="post-metadata">

**Author:** ![vladislav](https://avatars.discourse-cdn.com/v4/letter/v/bbce88/32.png) [@vladislav](https://discuss.elastic.co/u/vladislav)\
**Post date:** [October 19, 2021, 8:34am UTC](https://discuss.elastic.co/t/saving-request-url-variable-in-filebeat-httpjson/286700/7 "2021-10-19T08:34:15Z")

</div>

yes, you're right, I want to clear it manually.  
In registry directory (/var/lib/filebeat/registry/filebeat) there is only log.json and meta.json and it doesn't look like zeroing one of them will give the result

---

<div class="post-metadata">

**Author:** ![legoguy1000](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/legoguy1000/32/54301_2.png) [@legoguy1000](https://discuss.elastic.co/u/legoguy1000)\
**Post date:** [October 19, 2021, 9:22am UTC](https://discuss.elastic.co/t/saving-request-url-variable-in-filebeat-httpjson/286700/8 "2021-10-19T09:22:30Z")

</div>

Based on the code it looks like the cursor is just stored in memory so idk the best way to reset it.

---

<div class="post-metadata">

**Author:** ![vladislav](https://avatars.discourse-cdn.com/v4/letter/v/bbce88/32.png) [@vladislav](https://discuss.elastic.co/u/vladislav)\
**Post date:** [October 19, 2021, 9:48am UTC](https://discuss.elastic.co/t/saving-request-url-variable-in-filebeat-httpjson/286700/9 "2021-10-19T09:48:14Z")

</div>

Ok, thank you!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 16, 2021, 11:48am UTC](https://discuss.elastic.co/t/saving-request-url-variable-in-filebeat-httpjson/286700/10 "2021-11-16T11:48:30Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
