# Use Office 365 module in Logstash?

**URL:** <https://discuss.elastic.co/t/use-office-365-module-in-logstash/276528>\
**Category:** Logstash\
**Created:** [June 21, 2021, 11:00am UTC](https://discuss.elastic.co/t/use-office-365-module-in-logstash/276528 "2021-06-21T11:00:50Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![riahc3](https://avatars.discourse-cdn.com/v4/letter/r/d6d6ee/32.png) [@riahc3](https://discuss.elastic.co/u/riahc3)\
**Post date:** [June 21, 2021, 11:00am UTC](https://discuss.elastic.co/t/use-office-365-module-in-logstash/276528/1 "2021-06-21T11:00:50Z")

</div>

Hello

Is it possible to use the Office 365 module with Logstash?

Thanks

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [June 21, 2021, 10:07pm UTC](https://discuss.elastic.co/t/use-office-365-module-in-logstash/276528/2 "2021-06-21T22:07:33Z")

</div>

Do you mean the Filebeat module?

---

<div class="post-metadata">

**Author:** ![riahc3](https://avatars.discourse-cdn.com/v4/letter/r/d6d6ee/32.png) [@riahc3](https://discuss.elastic.co/u/riahc3)\
**Post date:** [June 22, 2021, 7:25am UTC](https://discuss.elastic.co/t/use-office-365-module-in-logstash/276528/3 "2021-06-22T07:25:02Z")

</div>

Yup.

I followed this

> **[Example: Set up Filebeat modules to work with Kafka and Logstash | Logstash...](https://www.elastic.co/guide/en/logstash/7.13/use-filebeat-modules-kafka.html)**

To attempt to do it but it doesnt seem to work correctly (Kibana doesnt display anything)

Here is my logstash:

```auto
input {
  beats {
     client_inactivity_timeout => 1200
     port => 5061
     ssl => false
# tags => ["filebeat"]
  }
}

#filter

#{

 # if [event][category] != "authentication"

 # {

 # drop { }

 # }
#geoip {
# source => "[o365][audit][ClientIP]"
# }

# }

output {
  if [@metadata][pipeline] {
    elasticsearch {
      hosts => "http://MYELASTICSTACK:9200"
      manage_template => false
      index => "filebeat-o365-login-%{+yyyy.MM.dd}"
      pipeline => "%{[@metadata][pipeline]}"
      user => "elastic"
      password => "mypassword"
    }
  } else {
    elasticsearch {
      hosts => "http://MYELASTICSTACK:9200"
      manage_template => false
      index => "filebeat-o365-login-%{+yyyy.MM.dd}"
      user => "elastic"
      password => "mypassword"
    }
  }
}

```

Kibana says:

Saved field "event.code" is invalid for use with the "Terms" aggregation. Please select a new field.  
Saved field "event.kind" is invalid for use with the "Terms" aggregation. Please select a new field  
Saved field "event.outcome" is invalid for use with the "Terms" aggregation. Please select a new field.

---

<div class="post-metadata">

**Author:** ![riahc3](https://avatars.discourse-cdn.com/v4/letter/r/d6d6ee/32.png) [@riahc3](https://discuss.elastic.co/u/riahc3)\
**Post date:** [June 29, 2021, 7:21am UTC](https://discuss.elastic.co/t/use-office-365-module-in-logstash/276528/4 "2021-06-29T07:21:00Z")

</div>

I think the modules wizard should be a bit more dynamic in the sense that you should be able to choose the index pattern you want to use and it should give you a list of fields where it can read data from.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 27, 2021, 7:21am UTC](https://discuss.elastic.co/t/use-office-365-module-in-logstash/276528/5 "2021-07-27T07:21:34Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
