# Should we use filebeat include\_lines to pre-filter messages before sent it to logstash?

**URL:** <https://discuss.elastic.co/t/should-we-use-filebeat-include-lines-to-pre-filter-messages-before-sent-it-to-logstash/329914>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [April 13, 2023, 9:28am UTC](https://discuss.elastic.co/t/should-we-use-filebeat-include-lines-to-pre-filter-messages-before-sent-it-to-logstash/329914 "2023-04-13T09:28:53Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![atline](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/atline/32/119772_2.png) [@atline](https://discuss.elastic.co/u/atline)\
**Post date:** [April 13, 2023, 9:28am UTC](https://discuss.elastic.co/t/should-we-use-filebeat-include-lines-to-pre-filter-messages-before-sent-it-to-logstash/329914/1 "2023-04-13T09:28:53Z")

</div>

Usually in logstash we could use next to filter messages:

```auto
filter {
    grok {
        match => {
            "message" => "%{TIMESTAMP_ISO8601:logtime}.*] %{NOTSPACE:device}: place acquired by %{NOTSPACE:user}"
        }
    }

```

So, if we use filterbeat to collect the log and sent to logstash, should we use next in filebeat to filter the log first before sent to logstash? What's the advantage or disadvantage compared to filter them only in logstash? Thanks!

```auto
include_lines: ['place acquired by']

```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 11, 2023, 11:28am UTC](https://discuss.elastic.co/t/should-we-use-filebeat-include-lines-to-pre-filter-messages-before-sent-it-to-logstash/329914/2 "2023-05-11T11:28:55Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
