# Applying conditionals to grok filter

**URL:** <https://discuss.elastic.co/t/applying-conditionals-to-grok-filter/89662>\
**Category:** Logstash\
**Created:** [June 16, 2017, 7:29am UTC](https://discuss.elastic.co/t/applying-conditionals-to-grok-filter/89662 "2017-06-16T07:29:38Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![vinod\_hy](https://avatars.discourse-cdn.com/v4/letter/v/c4cdca/32.png) [@vinod\_hy](https://discuss.elastic.co/u/vinod_hy)\
**Post date:** [June 16, 2017, 7:29am UTC](https://discuss.elastic.co/t/applying-conditionals-to-grok-filter/89662/1 "2017-06-16T07:29:38Z")

</div>

Hi All,

I have log in the below format,  
2017-06-08 19:05:56.222 loglevel=DEBUG,sysId=467,package=com.MyPackage1,class=MyClass.java,method="sendMessage",Id=679,message=Hello First Message.

Below is my filter,  
filter{  
grok  
{  
match =\> {"message" =\>"%{TIMESTAMP\_ISO8601:timestamp} %{GREEDYDATA:keyval}"}  
}  
kv  
{  
source =\> "keyval"  
field\_split =\> ","  
remove\_field =\> ["keyval"]  
}  
}

Now my requirement is to send the logs to elasticsearch whose package name matches to **com.MyPackage1**. Rest all messages belonging to other packages needs to be ignored.  
For that i made the below changes,  
filter  
{  
grok  
{  
match =\> {"message" =\>"%{TIMESTAMP\_ISO8601:timestamp} %{GREEDYDATA:keyval}"}  
}  
kv  
{  
source =\> "keyval"  
field\_split =\> ","  
remove\_field =\> ["keyval"]  
}  
}  
filter{  
if "com.MyPackage1" not in [package]  
{  
drop { }  
}  
}

This solution works fine. Now my another use case is that i should be able to drop certain fields present in the logs. Say suppose i want to drop **method** or **class**. I can add those fields in **remove\_field** section of the kv filter as below,

remove\_field =\> ["keyval","method","class"]  
It takes care of it.

But if i add the **package** field in **remove\_\_field** as below,  
remove\_field =\> ["keyval","package"]

then i wont to able to perfrom drop as drop is dependent of package filter to drop the messages.

How to solve this situation. Is there a better way. Please help me

---

<div class="post-metadata">

**Author:** ![vinod\_hy](https://avatars.discourse-cdn.com/v4/letter/v/c4cdca/32.png) [@vinod\_hy](https://discuss.elastic.co/u/vinod_hy)\
**Post date:** [June 16, 2017, 10:12am UTC](https://discuss.elastic.co/t/applying-conditionals-to-grok-filter/89662/2 "2017-06-16T10:12:20Z")

</div>

Hi all,  
This is what i did to solve the issue,  
filter{  
grok  
{  
match =\> {"message" =\>"%{TIMESTAMP\_ISO8601:timestamp} %{GREEDYDATA:keyval}"}  
}  
kv  
{  
source =\> "keyval"  
field\_split =\> ","  
}  
}  
filter{  
if "com.MyPackage1" not in [package]  
{  
drop { }  
}  
else  
{  
kv  
{   
source =\> "keyval"  
remove\_field =\> ["keyval","message","method"]  
}  
}

}

---

<div class="post-metadata">

**Author:** ![vinod\_hy](https://avatars.discourse-cdn.com/v4/letter/v/c4cdca/32.png) [@vinod\_hy](https://discuss.elastic.co/u/vinod_hy)\
**Post date:** [June 16, 2017, 10:13am UTC](https://discuss.elastic.co/t/applying-conditionals-to-grok-filter/89662/3 "2017-06-16T10:13:22Z")

</div>

In the first kv filter, i am just spliting the **keyval**. In the second kv filter, i am removing the unwanted fields.  
Please let me know is there a better solution.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 14, 2017, 10:13am UTC](https://discuss.elastic.co/t/applying-conditionals-to-grok-filter/89662/4 "2017-07-14T10:13:54Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
