# Filter problems

**URL:** <https://discuss.elastic.co/t/filter-problems/34827>\
**Category:** Logstash\
**Created:** [November 17, 2015, 4:53pm UTC](https://discuss.elastic.co/t/filter-problems/34827 "2015-11-17T16:53:52Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![Jackal9301](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jackal9301/32/5748_2.png) [@Jackal9301](https://discuss.elastic.co/u/Jackal9301)\
**Post date:** [November 17, 2015, 4:53pm UTC](https://discuss.elastic.co/t/filter-problems/34827/1 "2015-11-17T16:53:52Z")

</div>

Hey guys I'm trying to match a string in a filter. But the output isn't giving me what i'm expecting.

The input is:  
\<36\>Nov 02 15:48:57 LCE: [not-matched] 0.0.0.0:0 -\> 10.1.116.173:0 ::

```
filter{
grok{
	match => {"message" => "<%{BASE10NUM:LCE_log_num}>%{SYSLOGTIMESTAMP:LCE_time} %{PROG:header_type}: \[matched] %{IP:Source_IP}:%{BASE10NUM:Source_Port} -> %{IP:Destination_IP}:%{BASE10NUM:Destination_Port} ::%{GREEDYDATA:Message_Data}" }
	add_field => { "sort_num" => "%{LCE_log_num}" }
    }
if "_grokparsefailure" in [tags] {
    grok {
	remove_tag => ["_grokparsefailure"]
	add_tag => ["unmatched"]
	break_on_match => true
    }
  }	
}
ouput {	
if "unmatched" in [tags] {
	file {
  	path => "C:\ELK\running\logstash-2.0.0\test\JackTest\unmatched.txt"
    }
elasticsearch {
}

```

What I want is for every log that fails to match to be output to a file and not elastic. What is happening for me is i'm getting the grokparsefailure and its not matching my if statement stripping that and adding unmatched.

Any help is greatly appreciated

Thanks

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [November 17, 2015, 6:29pm UTC](https://discuss.elastic.co/t/filter-problems/34827/2 "2015-11-17T18:29:08Z")

</div>

That's because your second grok filter doesn't have any expressions to match so it doesn't count as successful, and because of that `remove_tag` and `add_tag` won't do anything. But you're overcomplicating things. Just set `tag_on_failure` for the first grok and drop the second one.

---

<div class="post-metadata">

**Author:** ![Jackal9301](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jackal9301/32/5748_2.png) [@Jackal9301](https://discuss.elastic.co/u/Jackal9301)\
**Post date:** [November 17, 2015, 6:30pm UTC](https://discuss.elastic.co/t/filter-problems/34827/3 "2015-11-17T18:30:40Z")

</div>

Thanks I was looking for something like that I must have looked over it. You the man

---

<div class="post-metadata">

**Author:** ![Jackal9301](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jackal9301/32/5748_2.png) [@Jackal9301](https://discuss.elastic.co/u/Jackal9301)\
**Post date:** [November 17, 2015, 6:33pm UTC](https://discuss.elastic.co/t/filter-problems/34827/4 "2015-11-17T18:33:42Z")

</div>

How can I have these events not go into elasticsearch though and just into a file?

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [November 17, 2015, 6:38pm UTC](https://discuss.elastic.co/t/filter-problems/34827/5 "2015-11-17T18:38:23Z")

</div>

Just wrap the outputs in a conditional, similar to what you had in the filter section of your first message in this thread.

---

<div class="post-metadata">

**Author:** ![Jackal9301](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jackal9301/32/5748_2.png) [@Jackal9301](https://discuss.elastic.co/u/Jackal9301)\
**Post date:** [November 17, 2015, 6:45pm UTC](https://discuss.elastic.co/t/filter-problems/34827/6 "2015-11-17T18:45:11Z")

</div>

I just tried this and It didn't fix it for me. Do you mind writing out how it should look? (the output is still writing to elastic)

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [November 17, 2015, 6:59pm UTC](https://discuss.elastic.co/t/filter-problems/34827/7 "2015-11-17T18:59:13Z")

</div>

```
output {
  if "unmatched" in [tags] {
    file {
      ...
    }
  } else {
    elasticsearch {
      ...
    }
  }
}
```

---

<div class="post-metadata">

**Author:** ![Jackal9301](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jackal9301/32/5748_2.png) [@Jackal9301](https://discuss.elastic.co/u/Jackal9301)\
**Post date:** [November 17, 2015, 7:01pm UTC](https://discuss.elastic.co/t/filter-problems/34827/8 "2015-11-17T19:01:53Z")

</div>

That is exactly what I had. I just changed it and wrote:

```
    if "multiline" in [tags] or "_xmlparsefailure" in [tags] or "_grokparsefailure" in [tags] or "unmatched" not in [tags] {
       file{
    }
}
```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 5:22am UTC](https://discuss.elastic.co/t/filter-problems/34827/9 "2017-07-06T05:22:31Z")

</div>


