# Grok with conditional patterns and adding a tag

**URL:** <https://discuss.elastic.co/t/grok-with-conditional-patterns-and-adding-a-tag/43844>\
**Category:** Logstash\
**Created:** [March 9, 2016, 1:23am UTC](https://discuss.elastic.co/t/grok-with-conditional-patterns-and-adding-a-tag/43844 "2016-03-09T01:23:47Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![pzero](https://avatars.discourse-cdn.com/v4/letter/p/ebca7d/32.png) [@pzero](https://discuss.elastic.co/u/pzero)\
**Post date:** [March 9, 2016, 1:23am UTC](https://discuss.elastic.co/t/grok-with-conditional-patterns-and-adding-a-tag/43844/1 "2016-03-09T01:23:47Z")

</div>

Hello,

I'm trying to filter logs from auth.log on a linux server. I want to tag with "ssh\_successful\_login", "ssh\_failed\_login", "ssh\_brute\_force".

Mar 3 16:56:22 test sshd[8510]: Failed password for user1 from 192.168.2.3 port 34852 ssh2  
Mar 3 16:56:25 test sshd[8510]: Accepted password for user1 from 192.168.2.3 port 34852 ssh2  
Mar 3 16:57:46 test sshd[5328]: Failed password for invalid user user2 from 192.168.2.3 port 45512 ssh2

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [March 9, 2016, 6:50am UTC](https://discuss.elastic.co/t/grok-with-conditional-patterns-and-adding-a-tag/43844/2 "2016-03-09T06:50:56Z")

</div>

You could e.g. use multiple grok filters.

```auto
filter {
  if "grokked" not in [tags] {
    grok {
      match => ["message", "... Failed password ... "]
      add_tag = ["ssh_failed_login", "grokked"]
    }
  }
  if "grokked" not in [tags] {
    grok {
      match => ["message", "... Accepted password ... "]
      add_tag = ["ssh_successful_login", "grokked"]
    }
  }
}

```

---

<div class="post-metadata">

**Author:** ![pzero](https://avatars.discourse-cdn.com/v4/letter/p/ebca7d/32.png) [@pzero](https://discuss.elastic.co/u/pzero)\
**Post date:** [March 9, 2016, 11:47pm UTC](https://discuss.elastic.co/t/grok-with-conditional-patterns-and-adding-a-tag/43844/3 "2016-03-09T23:47:45Z")

</div>

Hey,  
Thanks for your help. The logic was enough to help me get where I wanted. Below is what I ended up with.

# Filtering Linux Auth.log

filter {  
if [type] == 'auth' {  
grok { match =\> { 'message' =\> '%{SYSLOGTIMESTAMP:timestamp} %{HOSTNAME} %{WORD:program}%{GREEDYDATA:msgsplit}' }  
}  
# SSH successful login  
if "grokked" not in [tags] and "sshd" == [program] {  
grok { match =\> ["msgsplit", "[%{BASE10NUM}]: Accepted password for %{USERNAME:user} from %{IP:src\_ip} port %{BASE10NUM}\s+ssh%{BASE10NUM}" ]  
add\_tag =\> ["ssh\_successful\_login", "grokked"]  
tag\_on\_failure =\> []  
}  
}  
# SSH failed login  
if "grokked" not in [tags] and "sshd" == [program] {  
grok { match =\> ["msgsplit", "[%{BASE10NUM}]: Failed password for %{USERNAME:user} from %{IP:src\_ip} port %{BASE10NUM}\s+ssh%{BASE10NUM}" ]  
add\_tag =\> ["ssh\_failed\_login", "grokked"]  
tag\_on\_failure =\> []  
}  
}  
# SSH Brute force attemp  
if "grokked" not in [tags] and "sshd" == [program] {  
grok { match =\> ["msgsplit", "[%{BASE10NUM}]: Failed password for invalid user %{USERNAME:user} from %{IP:src\_ip} port %{BASE10NUM}\s+ssh%{BASE10NUM}" ]  
add\_tag =\> ["ssh\_brute\_force", "grokked"]  
tag\_on\_failure =\> []  
}  
}  
# Remove excess data  
if "grokked" in [tags] and "sshd" == [program]{  
mutate {  
remove\_field =\> ["message", "fields", "input\_type", "offset", "source", "program", "msgsplit"]  
remove\_tag =\> ["beats\_input\_codec\_plain\_applied"]  
}  
}  
} #End if[type] == "auth"  
} # End Filter

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 5:07am UTC](https://discuss.elastic.co/t/grok-with-conditional-patterns-and-adding-a-tag/43844/4 "2017-07-06T05:07:39Z")

</div>


