Skip to main content

lscl – Logstash configuration language handling

lscl is a Python module for parsing and rendering Logstash configurations in its own language, named LSCL for “LogStash Configuration Language”.

The project is present at the following locations:

As described in Reading Logstash configurations and Rendering Logstash configurations, you can use this module to create, parse, update and render Logstash pipelines. Here is an example where lscl is used to add an add_field operation on an existing pipeline:

from lscl.lang import LsclAttribute, LsclBlock
from lscl.parser import parse_lscl
from lscl.renderer import render_as_lscl


SOURCE = """
input {
    stdin { }
}
filter {
    dissect {
        mapping => {
            "message" => "[%{ts}] %{message}"
        }
    }
}
output {
    elasticsearch { codec => rubydebug }
}
"""

content = parse_lscl(SOURCE)

# Find the 'filter' block at top level.
# If the block is not found, create it.
for el in content:
    if isinstance(el, LsclBlock) and el.name == "filter":
        break
else:
    el = LsclBlock(name="filter")
    content.append(el)

# Add the add_field filter.
el.content.append(
    LsclBlock(
        name="mutate",
        content=[
            LsclAttribute(name="add_field", content={"mytag": "myvalue"}),
        ],
    )
)

print(render_as_lscl(content), end="")

The script will output the following:

input {
  stdin {}
}
filter {
  dissect {
    mapping => {
      message => "[%{ts}] %{message}"
    }
  }
  mutate {
    add_field => {
      mytag => myvalue
    }
  }
}
output {
  elasticsearch {
    codec => rubydebug
  }
}

Metadata

Release files for lscl 0.5

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for lscl 0.5
File Size Uploaded
lscl-0.5.tar.gz 24.7 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for lscl 0.5
File Interpreter ABI Platform
lscl-0.5-py3-none-any.whl Python 3 none any Details

Total release size: 53.6 kB

Release files / lscl-0.5.tar.gz

Download URL lscl-0.5.tar.gz
Size 24.7 kB
Tags Source
SHA-256 checksum
How to use checksums
a85c2ad19dcdc694458783091f7da76ef37d0d11d5862d4af9bed907c75cf276
BLAKE2b-256 checksum
How to use checksums
7459c0ce5d4d21afea3cdbdb7a1f6ac0ee9d47d06630be7f84233cd2fd638aef
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/6.1.0 CPython/3.11.12

Release files / lscl-0.5-py3-none-any.whl

Download URL lscl-0.5-py3-none-any.whl
Size 28.9 kB
Tags Python 3
SHA-256 checksum
How to use checksums
f711d052f98dcdb0c6fcd776761191e19c91a25cdbc7de5893f8e45311a3f5b8
BLAKE2b-256 checksum
How to use checksums
a0414e0324103945a8ef033f7adb12077df22539d5b2e5358b33cd12d0533d93
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/6.1.0 CPython/3.11.12

Release history Release notifications | RSS feed

This release

0.5 This release

2 release files

0.4

2 release files

0.3

2 release files

0.2.2

2 release files

0.2.1

2 release files

0.2

2 release files

0.1

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page