# Do Grok patterns have a place in the if =~ conditional matching?

**URL:** <https://discuss.elastic.co/t/do-grok-patterns-have-a-place-in-the-if-conditional-matching/45138>\
**Category:** Logstash\
**Created:** [March 22, 2016, 5:27pm UTC](https://discuss.elastic.co/t/do-grok-patterns-have-a-place-in-the-if-conditional-matching/45138 "2016-03-22T17:27:35Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![David\_McClain](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/david_mcclain/32/8613_2.png) [@David\_McClain](https://discuss.elastic.co/u/David_McClain)\
**Post date:** [March 22, 2016, 5:27pm UTC](https://discuss.elastic.co/t/do-grok-patterns-have-a-place-in-the-if-conditional-matching/45138/1 "2016-03-22T17:27:36Z")

</div>

I have the case where..

Sometimes my log has a block of JSON.  
Sometimes that block of JSON has a field (Lets call it "IPAddress")  
Sometimes the field "IPAddress" has a valid IP, other times, I've seen it with the value "unknown" or an empty string.

I want to..

If the "IPAddress" field exists..  
If the field contains a valid IP address..

THEN, apply the geoip filter to it.

I know that there is a %{IP} defined pattern for Grok.  
What I would like to do is something similar to..

```
if [IPAddress] =~ %{IP} {
  #Do stuff
}

```

However there are few caveats I've seen.

1. It doesn't seem to work that way. In place of that, I found the base regex that comprises the %{IP} pattern, and now have done this:  
`if [IPAddress] =~ /Long horrible string of regex.. seriously like 8 lines/`  
That works. **But, its messy**.

2. What kind of performance impact does this present, if any? And would any performance be gained by replacing the long regex string with %{IP}?

So overall, I would argue that a more readable config file, using Grok patterns for situations like this, is a benefit.  
What do you guys think?

And, maybe this is just a horrible way to approach my problems. What might be some other ways to solve this?  
Thanks!

_Edit: Post had multiple items as a numbered list... all with the same number. Fixed. Also changed some words and emphasized some text for clarity_

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [March 22, 2016, 6:05pm UTC](https://discuss.elastic.co/t/do-grok-patterns-have-a-place-in-the-if-conditional-matching/45138/2 "2016-03-22T18:05:11Z")

</div>

> It doesn't seem to work that way.

Yeah, I'm pretty sure the regexps in conditionals don't support grok patterns.

> And would any performance be gained by replacing the long regex string with %{IP}?

I'd assume the IP pattern in the end expands to more or less the same expression that you're currently using, so no.

But why have such a strict regexp? Is it really likely that the IPAddress field frequently will contain strings that match a simple expression like `^\d{1,3}\.\d{1,3}\.\d{1,3}\.\d{1,3}$` yet aren't valid IPv4 addresses?

---

<div class="post-metadata">

**Author:** ![David\_McClain](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/david_mcclain/32/8613_2.png) [@David\_McClain](https://discuss.elastic.co/u/David_McClain)\
**Post date:** [March 22, 2016, 6:34pm UTC](https://discuss.elastic.co/t/do-grok-patterns-have-a-place-in-the-if-conditional-matching/45138/3 "2016-03-22T18:34:32Z")

</div>

> [@magnusbaeck](#):
>
> But why have such a strict regexp?

So.. that's definitely a valid question.  
Originally I was trying to match with a grok filter, using %{IP}. I carried that over when I ended up making it an IF statement.

My thinking is.. if I am going to end up matching a field with %{IP} at any point, I would want my if statement to be an exact replica of that match. Not leaving any gaps. I didn't have any specific examples in mind, it was just a way to not leave any ground open for unexpected errors in the future.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 5:05am UTC](https://discuss.elastic.co/t/do-grok-patterns-have-a-place-in-the-if-conditional-matching/45138/4 "2017-07-06T05:05:51Z")

</div>


