# Check for more than one text from the grok filtered message?

**URL:** <https://discuss.elastic.co/t/check-for-more-than-one-text-from-the-grok-filtered-message/60286>\
**Category:** Logstash\
**Created:** [September 12, 2016, 12:07pm UTC](https://discuss.elastic.co/t/check-for-more-than-one-text-from-the-grok-filtered-message/60286 "2016-09-12T12:07:47Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Kulasangar\_Gowrisang](https://avatars.discourse-cdn.com/v4/letter/k/ce73a5/32.png) [@Kulasangar\_Gowrisang](https://discuss.elastic.co/u/Kulasangar_Gowrisang)\
**Post date:** [September 12, 2016, 12:07pm UTC](https://discuss.elastic.co/t/check-for-more-than-one-text-from-the-grok-filtered-message/60286/1 "2016-09-12T12:07:48Z")

</div>

I'm trying to find two log types from every single line of the log file, and if it match i'm assigning a log type to it by adding a log\_type field.

This is a piece of snippet from the `logstash config`:

```
    filter {
    		
    		grok {
    			patterns_dir => ["/home/chamith/work/ELK/logstash/logstash-2.3.4/bin/patterns"]
    			match => { "message" => "^%{LOGTIMESTAMP:logtimestamp}%{GREEDYDATA}" }	
    		}
    		
                mutate {
    			add_field => { "log_type" => "" }
    		}
    		
    		if "Auth" and "CHARGE_EXCEEDS_LIMIT" in ["message"]{
    			mutate {
    				add_field => { "log_type" => "Auth CHARGE_EXCEEDS_LIMIT" }
    			}
    		
    		}
    		
    		if "Auth" and "INSUFFICIENT_FUNDS" in ["message"]{
    			mutate {
    				add_field => { "log_type" => "Auth INSUFFICIENT_FUNDS" }
    			}
    		
    		}

```

After trying this, when i checked it from Kibana, nothing has been assigned to the new field log\_type, even though it has been created.

 ![](https://us1.discourse-cdn.com/elastic/original/2X/2/2b9ed42427578d682a0acf4e6525f99719d765fc.png)

Where am i going wrong? Any help would be appreciated.

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [September 12, 2016, 1:28pm UTC](https://discuss.elastic.co/t/check-for-more-than-one-text-from-the-grok-filtered-message/60286/2 "2016-09-12T13:28:15Z")

</div>

> ```
> if "Auth" and "CHARGE_EXCEEDS_LIMIT" in ["message"]{
> 
> ```

If this is supposed to mean "if the `message` field contains both 'Auth' and 'CHARGE\_EXCEEDS\_LIMIT'" you need to write it like this:

```
 if "Auth" in [message] and "CHARGE_EXCEEDS_LIMIT" in [message] {

```

---

<div class="post-metadata">

**Author:** ![Kulasangar\_Gowrisang](https://avatars.discourse-cdn.com/v4/letter/k/ce73a5/32.png) [@Kulasangar\_Gowrisang](https://discuss.elastic.co/u/Kulasangar_Gowrisang)\
**Post date:** [September 12, 2016, 3:19pm UTC](https://discuss.elastic.co/t/check-for-more-than-one-text-from-the-grok-filtered-message/60286/3 "2016-09-12T15:19:04Z")

</div>

Thanks, it works! 🙂

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 4:38am UTC](https://discuss.elastic.co/t/check-for-more-than-one-text-from-the-grok-filtered-message/60286/4 "2017-07-06T04:38:54Z")

</div>


