# Dissect file pattern that is not always available

**URL:** <https://discuss.elastic.co/t/dissect-file-pattern-that-is-not-always-available/310387>\
**Category:** Logstash\
**Created:** [July 22, 2022, 11:11am UTC](https://discuss.elastic.co/t/dissect-file-pattern-that-is-not-always-available/310387 "2022-07-22T11:11:14Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![mikhatanu](https://avatars.discourse-cdn.com/v4/letter/m/ba8739/32.png) [@mikhatanu](https://discuss.elastic.co/u/mikhatanu)\
**Post date:** [July 22, 2022, 11:11am UTC](https://discuss.elastic.co/t/dissect-file-pattern-that-is-not-always-available/310387/1 "2022-07-22T11:11:14Z")

</div>

Hello, i have a txt that looks like this:

```auto
ltm classification application app_name { application-id 7974 category Entertainment description "this app is popular. (tcp/http/ssl)" predefined yes risk 3 }
ltm classification application app1234_name { application-id 1234 category Entertainment description "this app is not popular. (udp)" predefined yes }

```

This log sometimes doesnt have the risk part as shown above. Can i still use dissect on this? This is my current config:

```auto
input {
  file {
      path => ["/some/data/path/appid_list_20220707.txt"]
      start_position => beginning
  }
}
filter{
  dissect{
    mapping=> {
      "message" => 'ltm %{ltm} application %{[application][name]} { application-id %{[application][id]} category %{[application][category]} description "%{[application][description]}" predefined %{[application][predefined]} risk %{[application][risk]} }'
    }		
  }
}
output {
  stdout { }	
}

```

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [July 22, 2022, 12:26pm UTC](https://discuss.elastic.co/t/dissect-file-pattern-that-is-not-always-available/310387/2 "2022-07-22T12:26:35Z")

</div>

It will fail on every message that does not have the _risk_ in it and you will need another dissect.

You could a conditional to test if you have _risk_ in the message and send it to the correct dissect.

```auto
if "risk" in [message] {
    dissect { dissect for messages with risk }
} else {
    dissect { dissect for messages without risk }
}
    

```

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [July 22, 2022, 4:46pm UTC](https://discuss.elastic.co/t/dissect-file-pattern-that-is-not-always-available/310387/3 "2022-07-22T16:46:58Z")

</div>

You may want to use a combination of dissect and grok. For example,

```
grok { match => { "message" => "%{GREEDYDATA:[@metadata][prefix]}" predefined %{WORD:[application][predefined]}( risk %{[application][risk]})?"
dissect { mapping => { "[@metadata][prefix]" => " ... " } }

```

---

<div class="post-metadata">

**Author:** ![mikhatanu](https://avatars.discourse-cdn.com/v4/letter/m/ba8739/32.png) [@mikhatanu](https://discuss.elastic.co/u/mikhatanu)\
**Post date:** [July 25, 2022, 2:42am UTC](https://discuss.elastic.co/t/dissect-file-pattern-that-is-not-always-available/310387/4 "2022-07-25T02:42:12Z")

</div>

this can fail if the log description contains the word risk and the log doesn't have risk in the back of it

---

<div class="post-metadata">

**Author:** ![mikhatanu](https://avatars.discourse-cdn.com/v4/letter/m/ba8739/32.png) [@mikhatanu](https://discuss.elastic.co/u/mikhatanu)\
**Post date:** [July 25, 2022, 3:12am UTC](https://discuss.elastic.co/t/dissect-file-pattern-that-is-not-always-available/310387/6 "2022-07-25T03:12:58Z")

</div>

Is there something like a try and catch, where i can try the first dissect. If the first fails, i can use the second dissect

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [July 25, 2022, 3:20am UTC](https://discuss.elastic.co/t/dissect-file-pattern-that-is-not-always-available/310387/7 "2022-07-25T03:20:41Z")

</div>

No, you can use a pattern match to test whether a field matches a pattern and only apply the dissect if it matches. The pattern for the =~ and the dissect will look different, but have to match.

---

<div class="post-metadata">

**Author:** ![mikhatanu](https://avatars.discourse-cdn.com/v4/letter/m/ba8739/32.png) [@mikhatanu](https://discuss.elastic.co/u/mikhatanu)\
**Post date:** [July 25, 2022, 5:51am UTC](https://discuss.elastic.co/t/dissect-file-pattern-that-is-not-always-available/310387/8 "2022-07-25T05:51:00Z")

</div>

I decided to changed my filter to mutate (remove curly brackets) + kv (to creat field automatically)

```auto
filter{
  mutate{
    gsub => ["message","[{}]",""]
  }
  kv{
    value_split => " "
  }
}

```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 22, 2022, 5:51am UTC](https://discuss.elastic.co/t/dissect-file-pattern-that-is-not-always-available/310387/9 "2022-08-22T05:51:15Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
