# Grok tag\_on\_failure

**URL:** <https://discuss.elastic.co/t/grok-tag-on-failure/134310>\
**Category:** Logstash\
**Created:** [June 3, 2018, 9:49am UTC](https://discuss.elastic.co/t/grok-tag-on-failure/134310 "2018-06-03T09:49:57Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![nin77](https://avatars.discourse-cdn.com/v4/letter/n/a8b319/32.png) [@nin77](https://discuss.elastic.co/u/nin77)\
**Post date:** [June 3, 2018, 9:49am UTC](https://discuss.elastic.co/t/grok-tag-on-failure/134310/1 "2018-06-03T09:49:58Z")

</div>

Hey, I am using:

grok {  
match =\> ["ip\_filter" , " %{IPV4:clientip}"]  
tag\_on\_failure =\> ["\_todelete"]  
}

So every line with a non valid IP should be tagged \_todelete, but on Kibana I see every line tagged with it. Any ideas why?

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [June 3, 2018, 7:16pm UTC](https://discuss.elastic.co/t/grok-tag-on-failure/134310/2 "2018-06-03T19:16:52Z")

</div>

Please show an example message (copy/paste the event text from Kibana's JSON tab) and the rest of your Logstash configuration.

---

<div class="post-metadata">

**Author:** ![nin77](https://avatars.discourse-cdn.com/v4/letter/n/a8b319/32.png) [@nin77](https://discuss.elastic.co/u/nin77)\
**Post date:** [June 3, 2018, 8:46pm UTC](https://discuss.elastic.co/t/grok-tag-on-failure/134310/3 "2018-06-03T20:46:34Z")

</div>

Thank you for your replay! Here is the Json output:

{  
"\_index": "log\_analyzer",  
"\_type": "doc",  
"\_id": "y57OxmMByI6RAjAO1JOX",  
"\_version": 1,  
"\_score": 1.2111092,  
"\_source": {  
"bytes": 209,  
"ident": "-",  
"message": "192.168.1.71 - - [08/May/2018:12:56:08 +0200] "GET /favicon.ico HTTP/1.1" 404 209 "-" "Mozilla/5.0 (Windows NT 6.1; Win64; x64; rv:59.0) Gecko/20100101 Firefox/59.0"",  
"type": "apache\_access",  
"major": "59",  
"request": "/favicon.ico",  
"name": "Firefox",  
"auth": "-",  
"@timestamp": "2018-05-08T10:56:08.000Z",  
"os": "Windows 7",  
"clientip": "192.168.1.71",  
"referrer": ""-"",  
"port": 59370,  
"response": 404,  
"agent": ""Mozilla/5.0 (Windows NT 6.1; Win64; x64; rv:59.0) Gecko/20100101 Firefox/59.0"",  
"httpversion": "1.1",  
"os\_name": "Windows 7",  
"build": "",  
"host": "probackup\_nginx\_1.probackup\_elk",  
"tags": [  
"\_todelete"  
],  
"minor": "0",  
"device": "Other",  
"@version": "1",  
"verb": "GET"  
},  
"fields": {  
"@timestamp": [  
"2018-05-08T10:56:08.000Z"  
]  
},  
"highlight": {  
"tags": [  
"@kibana-highlighted-field@\_todelete@/kibana-highlighted-field@"  
]  
}  
}

My Config looks like that:

filter {

grok {  
match =\> ["message" =\> " %{IPV4:clientip}"]  
tag\_on\_failure =\> ["\_todelete"]  
}

// if "\_todelete" in [tags] {  
// drop {}  
// }

// grok {  
// remove\_tag =\> ["\_todelete"]  
// }

if [type] in ["apache" , "apache\_access" , "apache-access"] {  
grok {  
match =\> [  
"message" , "%{COMBINEDAPACHELOG}+%{GREEDYDATA:extra\_fields}",  
"message" , "%{COMMONAPACHELOG}+%{GREEDYDATA:extra\_fields}"  
]  
overwrite =\> ["message"]  
}  
mutate {  
convert =\> ["response", "integer"]  
convert =\> ["bytes", "integer"]  
convert =\> ["responsetime", "float"]  
remove\_field =\> "os\_name"  
}  
date {  
match =\> ["timestamp" , "dd/MMM/YYYY:HH:mm:ss Z"]  
remove\_field =\> ["timestamp"]  
}  
useragent {  
source =\> "agent"  
}  
}

I wanted to use one of the two commented solutions as my next step but because every line is tagged it deletes all  
(I added // instead of hastag so it doesnt kill the format)

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [June 4, 2018, 6:25am UTC](https://discuss.elastic.co/t/grok-tag-on-failure/134310/4 "2018-06-04T06:25:28Z")

</div>

Your grok expression is looking for a space followed by an IP address but your IP address comes at the very beginning of the string. So, use `^%{IPV4:clientip}` instead.

---

<div class="post-metadata">

**Author:** ![nin77](https://avatars.discourse-cdn.com/v4/letter/n/a8b319/32.png) [@nin77](https://discuss.elastic.co/u/nin77)\
**Post date:** [June 4, 2018, 8:28am UTC](https://discuss.elastic.co/t/grok-tag-on-failure/134310/5 "2018-06-04T08:28:58Z")

</div>

That worked. Thanks a lot!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 2, 2018, 8:28am UTC](https://discuss.elastic.co/t/grok-tag-on-failure/134310/6 "2018-07-02T08:28:58Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
