# Grok multiple pattern and tag\_on\_failure for each pattern

**URL:** <https://discuss.elastic.co/t/grok-multiple-pattern-and-tag-on-failure-for-each-pattern/150816>\
**Category:** Logstash\
**Created:** [October 3, 2018, 5:21am UTC](https://discuss.elastic.co/t/grok-multiple-pattern-and-tag-on-failure-for-each-pattern/150816 "2018-10-03T05:21:42Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![sagark](https://avatars.discourse-cdn.com/v4/letter/s/a4c791/32.png) [@sagark](https://discuss.elastic.co/u/sagark)\
**Post date:** [October 3, 2018, 5:21am UTC](https://discuss.elastic.co/t/grok-multiple-pattern-and-tag-on-failure-for-each-pattern/150816/1 "2018-10-03T05:21:42Z")

</div>

Hello, I am trying to use multiple grok pattern under single grok, but when any of the pattern matches, it should not add tag\_on\_failure. Or can I add tag\_on\_failure for each pattern? Configuration is as below:

grok {  
match =\> { "message" =\> ["%{pattern1}", "%{pattern2}"] tag\_on\_failure =\> ["parse-failed"] }

In above case, when logline matches with pattern1 and failed with pattern2 then it add tag\_on\_failure to it and when logline doesn't match with pattern1 but match with pattern2 then it will not add tag\_on\_failure.

Please suggest

---

<div class="post-metadata">

**Author:** ![bardie](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bardie/32/36173_2.png) [@bardie](https://discuss.elastic.co/u/bardie)\
**Post date:** [October 3, 2018, 1:42pm UTC](https://discuss.elastic.co/t/grok-multiple-pattern-and-tag-on-failure-for-each-pattern/150816/2 "2018-10-03T13:42:50Z")

</div>

Use the following

```
  grok {
    break_on_match => true
    tag_on_failure => ["parse-failed"]
    match => ['message', '%{PATTERN1}']
    match => ['message', '%{PATTERN2}']
    match => ['message', '%{PATTERN3}']
}
```

---

<div class="post-metadata">

**Author:** ![sagark](https://avatars.discourse-cdn.com/v4/letter/s/a4c791/32.png) [@sagark](https://discuss.elastic.co/u/sagark)\
**Post date:** [October 4, 2018, 5:00am UTC](https://discuss.elastic.co/t/grok-multiple-pattern-and-tag-on-failure-for-each-pattern/150816/3 "2018-10-04T05:00:42Z")

</div>

Thanks for the reply and help Bardie. Can you tell me one more thing that why do we need to write "break\_on\_match =\> true" when its the default value ? So is that the case with other options as well ?

Ref: [https://www.elastic.co/guide/en/logstash/5.3/plugins-filters-grok.html#plugins-filters-grok-break\_on\_match](https://www.elastic.co/guide/en/logstash/5.3/plugins-filters-grok.html#plugins-filters-grok-break_on_match)

---

<div class="post-metadata">

**Author:** ![bardie](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bardie/32/36173_2.png) [@bardie](https://discuss.elastic.co/u/bardie)\
**Post date:** [October 4, 2018, 2:30pm UTC](https://discuss.elastic.co/t/grok-multiple-pattern-and-tag-on-failure-for-each-pattern/150816/4 "2018-10-04T14:30:13Z")

</div>

> [@sagark](#):
>
> ly and help Bardie. Can you tell me one more thing that why do we need to write "break\_on\_match =\> true" when its the default value ? So is that the case with other options as well ?

`break_on_match => true` is used when you have multiple matches and you want to prevent logstash from trying all the match statements on grok

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [October 5, 2018, 5:17pm UTC](https://discuss.elastic.co/t/grok-multiple-pattern-and-tag-on-failure-for-each-pattern/150816/5 "2018-10-05T17:17:38Z")

</div>

> Can you tell me one more thing that why do we need to write "break\_on\_match =\> true" when its the default value ?

You don't. `break_on_match` is the default behavior.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 2, 2018, 5:18pm UTC](https://discuss.elastic.co/t/grok-multiple-pattern-and-tag-on-failure-for-each-pattern/150816/6 "2018-11-02T17:18:08Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
