filter { if [program] == "yum" { grok { match => [ "message", "%{WORD:action}: %{GREEDYDATA:application_name}" ] add_tag => "linux_install" ##comment this line to disable email notification add_field => [ "Notification", "yes"] ## } } } filter { if [type] == "WindowsLog" { grok { match => [ "Message", "Installation Successful: Windows successfully installed the following update: %{GREEDYDATA:windows_installed}" ] add_tag => "windows_install" ##comment this line to disable email notification #add_field => [ "Notification", "yes"] ## } } }