# Grok filter for selecting and formatting certain logs lines

**URL:** <https://discuss.elastic.co/t/grok-filter-for-selecting-and-formatting-certain-logs-lines/131892>\
**Category:** Logstash\
**Created:** [May 15, 2018, 9:12am UTC](https://discuss.elastic.co/t/grok-filter-for-selecting-and-formatting-certain-logs-lines/131892 "2018-05-15T09:12:03Z")\
**Posts on this page:** 1\
**Showing post:** 2

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [May 15, 2018, 9:16am UTC](https://discuss.elastic.co/t/grok-filter-for-selecting-and-formatting-certain-logs-lines/131892/2 "2018-05-15T09:16:42Z")

</div>

Use a grok filter that only matches and extracts fields from this exact kind of message. If a line doesn't match it'll get tagged ẁith `_grokparsefailure`. You can then look for that tag in a conditional that wraps a drop filter (see [How to exclude bad output (lines not matching 'grok' pattern) from logstash?](https://discuss.elastic.co/t/how-to-exclude-bad-output-lines-not-matching-grok-pattern-from-logstash/40459) for an example).

---

_[View the full topic](https://discuss.elastic.co/t/grok-filter-for-selecting-and-formatting-certain-logs-lines/131892)._
