# Grok pattern for stashing Ansible logs

**URL:** <https://discuss.elastic.co/t/grok-pattern-for-stashing-ansible-logs/299227>\
**Category:** Logstash\
**Created:** [March 9, 2022, 1:59pm UTC](https://discuss.elastic.co/t/grok-pattern-for-stashing-ansible-logs/299227 "2022-03-09T13:59:54Z")\
**Posts on this page:** 1\
**Showing post:** 5

<div class="post-metadata">

**Author:** ![santy1](https://avatars.discourse-cdn.com/v4/letter/s/e9bcb4/32.png) [@santy1](https://discuss.elastic.co/u/santy1)\
**Post date:** [March 11, 2022, 2:10pm UTC](https://discuss.elastic.co/t/grok-pattern-for-stashing-ansible-logs/299227/5 "2022-03-11T14:10:00Z")

</div>

I stumbled upon this 6 year old post [https://discuss.elastic.co/t/keeping-global-variables-in-ls/39908](https://discuss.elastic.co/t/keeping-global-variables-in-ls/39908) which describes the exact same scenario as mine.

After following this post, I was able to get partial success using ruby filter.

My progress. so far:

1. Using ruby filter, store the value of task\_name field in a variable called @@taskname that will persist for later user.

2. Using GROK, search for events where you want to insert the above field.

3. Field inserted in all the lines that match in step 2.

What I am stuck at:

1. "\_grokparsefailure" tag gets inserted in all events, even though the patterns have matched and the task\_name field was inserted.

2. When I run Logstash again, then all 4 events get the same task\_name inserted. Actual behavior should be, 2 events get task\_name as "Formatting xfs filesystem" and the other 2 should get the. 2nd task name. If I run it again, I get one of the events getting a null value. Any ideas for the reason behind this random behaviour?

I have made sure to set the Logstash workers to '1' for thread safety.

Below is my conf

```auto
## Parse Logs
input {
  file {
    path => "/var/log/dummy.log"
    start_position => "beginning"
    sincedb_path => "/dev/null"
  }
}

filter {
  grok {
    patterns_dir => ["./patterns"]
    match => { "message" => "%{GROK_PATTERN}TASK%{SPACE}\[%{WORD:role}%{SPACE}\:%{SPACE}%{GREEDYDATA:task_name}\]" }
  }

## Store the value in @@taskname
  ruby {
       init => '@@taskname = ""'
       code => '
         if event.get("task_name")
            @@taskname = event.get("task_name")
         end'
  }

## Match events where the @@taskname should be added
  grok {
    patterns_dir => ["./patterns"]
    match => { "message" => "%{GROK_PATTERN}%{WORD:task_status}\:%{SPACE}\[%{HOSTNAME:hostname}.*" }
  }

## Insert the field
  if [task_status] =~ "changed" {
    ruby { code => 'event.set("task_name", @@taskname)' }
  }
}

output {
  elasticsearch {
    hosts => ["TESTVM-1:9200"]
    index => "dummy_logs"
  }
  stdout {}
} 

```

---

_[View the full topic](https://discuss.elastic.co/t/grok-pattern-for-stashing-ansible-logs/299227)._
