Hacktoberfest 2026: the issues maintainers tagged for October, open and beginner-friendly. Browse Hacktoberfest issues

RFE: Add config option to skip the event.cancel at the end of the filter flow

Open
#38 0 comments 1 reaction 0 assignees View on GitHub

Nobody has claimed this yet.

Assessment

Difficulty
3/5
Estimated time
1-2 days
Newbie friendliness
35/100
Issue type
Feature
Clarity
Mostly clear
Activity status
Stale
Tech stack
ruby
Domain
backend

Research direction

The issue names no files or tests. Start by locating the split filter entry point and the handling of event.cancel, then reproduce the three sequential split calls with keep_original enabled. Done means the requested configuration option supports repeated splits while preserving existing behavior by default.

Written by the indexing model from the issue text.

Description

I'm using the split filter along with the logstash-input-snmp to gather SNMP data and ingest into Elastic.

In order to ingest data on a per-core, per-interface, per-filesystem basis, I'm using separate input blocks with tagging and then using the split filter based on the tags.

What I'd like to be able to do is use a single snmp input to walk a device and then use the split filter on the original event multiple times to split out the various tables of data.

e.g. Based on a rough format of:

    "device_name": "mydevice.my.domain",
    "device_version": "1.2.3.4",
    "device_uptime": 123456,
    "cpu": {
        1 => "data",
        2 => "data",
        3 => "data"
   },
   "mem": {
        1 => "data",
        2 => "data",
        3 => "data"
   },
   "int": {
        1 => "data",
        2 => "data",
        3 => "data"
   }

I could use a pipeline with:

if "cpu_split" in [tags] {
    #do cpu related parsing and cleanup (drop non cpu fields)
} else if "mem_split" in [tags] {
    #do mem related parsing and cleanup (drop non mem fields)
} else if "int_split" in [tags] {
    #do int related parsing and cleanup (drop non int fields)
} else {
    split {
        field => "cpu"
        keep_original => true
        add_tag => [ "cpu_split" ]
    }
    split {
        field => "mem"
        keep_original => true
        add_tag => [ "mem_split" ]
    }
    split {
        field => "int"
        keep_original => true
        add_tag => [ "int_split" ]
    }
   # Drop cpu/mem/int fields and parse the rest of results (or just drop{} if nothing left)
}
Dominant language
Ruby
Stars
6
Forks
29
PR merge metrics
No merged PRs in 30d

Getting set up

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

More from logstash-plugins/logstash-filter-split

All issues in logstash-plugins/logstash-filter-split

Similar issues

More Ruby issues

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.