# Add a tag if a field exists

**URL:** <https://discuss.elastic.co/t/add-a-tag-if-a-field-exists/97634>\
**Category:** Logstash\
**Created:** [August 18, 2017, 8:04pm UTC](https://discuss.elastic.co/t/add-a-tag-if-a-field-exists/97634 "2017-08-18T20:04:11Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Bitdog](https://avatars.discourse-cdn.com/v4/letter/b/f04885/32.png) [@Bitdog](https://discuss.elastic.co/u/Bitdog)\
**Post date:** [August 18, 2017, 8:04pm UTC](https://discuss.elastic.co/t/add-a-tag-if-a-field-exists/97634/1 "2017-08-18T20:04:11Z")

</div>

I've been working with Logstash for about 6 weeks. Trying to tag a message based on a field. When the grok match fails I get a \_grokparsefailure tag. Here is the add\_tag section and the entire filter below. When I negate the if [field] every message gets tagged even if when there is no match on the field.

What am I missing?  
Should I be doing this in a Grok match?  
For learning purposes can I add a tag to each match to better understand where matches are occurring?

Humbly,

if [fac\_msg] {  
mutate {  
add\_tag =\> ["eocnetops"]  
}  
}

##########################  
filter {

```
if ([message] =~ "snmpHPTools"){
   drop {}
}
else if ([message] =~ "User:HPOpenView"){
   drop {}
}
else if ([message] =~ "NACUser"){
   drop {}
}
else if ([message] =~ "permitted 172.26.122.78"){
   drop {}
}
else if ([message] =~ "permitted 172.26.18.133"){
   drop{}
}
else if ([message] =~ "%SSH-5-SSH2"){
   drop{}
}
else if ([message] =~ "%SEC_LOGIN"){
   drop{}
}
else if ([message] =~ "%AAA-5"){
   drop{}
}
else if ([message] =~ "172.26.16.15 JACTDFPASC308 CSCOacs"){
   drop{}
}

grok {
   patterns_dir => ["/opt/logstash/patterns"]
   break_on_match => true

   match => [
      "message", "%{SYSLOG5424PRI:syslog5424_pri}%{SYSLOGTIMESTAMP:sender_time} %{IPORHOST:syslog_host} %{NONNEGINT:sender_seq}: %{NONNEGINT:log_seq}: %{SYSLOGTIMESTAMP:source_time} %{TZ:time_zone}: \%%{DATA:fac_msg}: %{DATA:fac_msg1}, %{DATA:fac_msg2}$",
      "message", "%{SYSLOG5424PRI:syslog5424_pri}%{SYSLOGTIMESTAMP:sender_time} %{IPORHOST:syslog_host} %{NONNEGINT:sender_seq}: %{NONNEGINT:log_seq}: %{SYSLOGTIMESTAMP:source_time} %{TZ:time_zone}: \%%{DATA:fac_msg}: %{DATA:fac_msg1}$",
      "message", "%{SYSLOG5424PRI:syslog5424_pri}%{SYSLOGTIMESTAMP:sender_time} %{IPORHOST:syslog_host} %{NONNEGINT:sender_seq}: %{SINCEREBOOT:uptime}: \%%{DATA:fac_msg}: %{DATA:fac_msg1}$",
      "message", "%{SYSLOG5424PRI:syslog5424_pri}%{SYSLOGTIMESTAMP:sender_time} %{IPORHOST:syslog_host} %{NONNEGINT:sender_seq}: %{SYSLOGTIMESTAMP:source_time} %{TZ:time_zone}: \%%{DATA:fac_msg}: %{DATA:fac_msg1}, %{DATA:fac_msg2}$",
      "message", "%{SYSLOG5424PRI:syslog5424_pri}%{SYSLOGTIMESTAMP:sender_time} %{IPORHOST:syslog_host} %{NONNEGINT:sender_seq}: %{SYSLOGTIMESTAMP:source_time} (%{TZ:time_zone}*+): \%%{DATA:fac_msg}: %{DATA:fac_msg1}$",
      "message", "%{SYSLOG5424PRI:syslog5424_pri}%{SYSLOGTIMESTAMP:sender_time} %{IPORHOST:syslog_host} %{NONNEGINT:sender_seq}: %{DATA:no_fac_msg1}$"
  ]
} # grok

if ![fac_msg] {
   mutate {
      add_tag => ["eocnetops"]
   }
}

```

} # Filter

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [August 20, 2017, 6:34pm UTC](https://discuss.elastic.co/t/add-a-tag-if-a-field-exists/97634/2 "2017-08-20T18:34:00Z")

</div>

> if [fac\_msg] {

Have you tried removing the spaces surrounding "fac\_msg" (assuming your field name doesn't _actually_ have leading and trailing whitespace)?

> For learning purposes can I add a tag to each match to better understand where matches are occurring?

Each match of... grok?

---

<div class="post-metadata">

**Author:** ![Bitdog](https://avatars.discourse-cdn.com/v4/letter/b/f04885/32.png) [@Bitdog](https://discuss.elastic.co/u/Bitdog)\
**Post date:** [August 23, 2017, 11:46am UTC](https://discuss.elastic.co/t/add-a-tag-if-a-field-exists/97634/3 "2017-08-23T11:46:32Z")

</div>

The space in [fac\_msg] was the issue once removed add\_tag worked.

What I mean by “each match of …grok”. If there is match a I want to add a tag or add a field to know which message matched.

Thanks for your help,

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [August 24, 2017, 11:46am UTC](https://discuss.elastic.co/t/add-a-tag-if-a-field-exists/97634/4 "2017-08-24T11:46:26Z")

</div>

> What I mean by “each match of …grok”. If there is match a I want to add a tag or add a field to know which message matched.

Just add the `add_tag` or `add_field` option to your grok filter. If the filter is successful, i.e. matches, it'll use those options, otherwise not.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 21, 2017, 11:46am UTC](https://discuss.elastic.co/t/add-a-tag-if-a-field-exists/97634/5 "2017-09-21T11:46:27Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
