# Grokk Patterning output to respective indexes based on \[agent.type\] (or any conditionals) not working

**URL:** <https://discuss.elastic.co/t/grokk-patterning-output-to-respective-indexes-based-on-agent-type-or-any-conditionals-not-working/259602>\
**Category:** Beats\
**Tags:** filebeat, winlogbeat\
**Created:** [December 24, 2020, 6:27pm UTC](https://discuss.elastic.co/t/grokk-patterning-output-to-respective-indexes-based-on-agent-type-or-any-conditionals-not-working/259602 "2020-12-24T18:27:23Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Rohan-boogeyman](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rohan-boogeyman/32/81377_2.png) [@Rohan-boogeyman](https://discuss.elastic.co/u/Rohan-boogeyman)\
**Post date:** [December 24, 2020, 6:27pm UTC](https://discuss.elastic.co/t/grokk-patterning-output-to-respective-indexes-based-on-agent-type-or-any-conditionals-not-working/259602/1 "2020-12-24T18:27:23Z")

</div>

Hello,

Sorry but i've got a question as I have searched alot for an answer but could not find anything.  
My winlogbeat and filebeat are all sent to logstash on 5044. I want logstash to filter using Grokk and output them to dedicated indexes. I am using the following config for logstash but it appears the condition if [agent][type] == "filebeat" is not working. Please tell me what have I got wrong, thanks!

Logstash Config

> input {  
> beats {  
> port =\> 5044  
> }  
> }

> filter {  
> if [agent][type] == "filebeat"{  
> if "404" in [message] {  
> grok {  
> match =\> {"message" =\> "%{TIMESTAMP\_ISO8601:Grokkstamp} %{WORD:Grokkiis} %{WORD:Grokksite} %{IP:GrokkclientIP} %{WORD:Grokkhttp} %{GREEDYDATA:Grokkurl} %{NUMBER:Grokkport} %{NOTSPACE:Grokkusername} %{IPORHOST:Grokkclienthost} %{NOTSPACE:Grokkuseragent} %{NOTSPACE:Grokkreferer} %{DATA:Grokkhosturl} %{NUMBER:Grokkresponse} %{NUMBER:Grokksubresponse} %{NUMBER:Grokkscstatus} %{NUMBER:Grokkint}"}  
> }  
> }  
> else if "403" in [message] {  
> grok {  
> match =\> {"message" =\> "%{TIMESTAMP\_ISO8601:Grokkstamp} %{WORD:Grokkiis} %{WORD:Grokksite} %{IP:GrokkclientIP} %{WORD:Grokkhttp} %{GREEDYDATA:Grokkurl} %{NUMBER:Grokkport} %{NOTSPACE:Grokkusername} %{IPORHOST:Grokkclienthost} %{NOTSPACE:Grokkuseragent} %{NOTSPACE:Grokkreferer} %{DATA:Grokkhosturl} %{NUMBER:Grokkresponse} %{NUMBER:Grokksubresponse} %{NUMBER:Grokkscstatus} %{NUMBER:Grokkint}"}  
> }  
> }  
> else if "400" in [message] {  
> grok {  
> match =\> {"message" =\> "%{TIMESTAMP\_ISO8601:Grokkstamp} %{WORD:Grokkiis} %{WORD:Grokksite} %{IP:GrokkclientIP} %{WORD:Grokkhttp} %{GREEDYDATA:Grokkurl} %{NUMBER:Grokkport} %{NOTSPACE:Grokkusername} %{IPORHOST:Grokkclienthost} %{NOTSPACE:Grokkuseragent} %{NOTSPACE:Grokkreferer} %{DATA:Grokkhosturl} %{NUMBER:Grokkresponse} %{NUMBER:Grokksubresponse} %{NUMBER:Grokkscstatus} %{NUMBER:Grokkint}"}  
> }  
> }  
> else if "500" in [message] {  
> grok {  
> match =\> {"message" =\> "%{TIMESTAMP\_ISO8601:Grokkstamp} %{WORD:Grokkiis} %{WORD:Grokksite} %{IP:GrokkclientIP} %{WORD:Grokkhttp} %{GREEDYDATA:Grokkurl} %{NUMBER:Grokkport} %{NOTSPACE:Grokkusername} %{IPORHOST:Grokkclienthost} %{NOTSPACE:Grokkuseragent} %{NOTSPACE:Grokkreferer} %{DATA:Grokkhosturl} %{NUMBER:Grokkresponse} %{NUMBER:Grokksubresponse} %{NUMBER:Grokkscstatus} %{NUMBER:Grokkint}"}  
> }  
> }  
> else {  
> }   
> }
> 
> else if [agent][type] == "winlogbeat"{  
> if "Service: THP" in [message] {  
> grok {  
> match =\> {"message" =\> "%{GREEDYDATA:message1} %{WORD:error}"}  
> }  
> }  
> else {  
> }  
> }  
> }

> output  
> {  
> if [agent][type] == "filebeat"{  
> if "dd00-sap-iislogs" in [tags]{  
> elasticsearch  
> {  
> hosts =\> "${xxxx}"  
> user =\> "${xxxx}"  
> password =\> "${xxxx}"  
> index =\> "n1o0-rbptet-sre-windows-filebeat-%{+YYYY.MM}"  
> manage\_template =\> false  
> ssl =\> true  
> ssl\_certificate\_verification =\> false  
> cacert =\> "/xxx\_xxx/xxx/xxx-xxx.crt"  
> ilm\_rollover\_alias =\> "xxx-xxx-xxx-windows-filebeat"  
> ilm\_pattern =\> "000001"  
> ilm\_policy =\> "xxx-xxx-xxx-xxx"  
> }  
> }  
> }  
> else if [agent][type] == "winlogbeat"]{  
> elasticsearch  
> {  
> hosts =\> "${xxxx}"  
> user =\> "${xxxx}"  
> password =\> "${xxxx}"  
> index =\> "xxx-xxx-xxx-windows-winlogbeat-%{+YYYY.MM}"  
> manage\_template =\> false  
> ssl =\> true  
> ssl\_certificate\_verification =\> false  
> cacert =\> "/xxx\_xxx/xxx/xxx-xxx.crt"  
> ilm\_rollover\_alias =\> "xxx-xxx-xxx-windows-winlogbeat"  
> ilm\_pattern =\> "000001"  
> ilm\_policy =\> "xxx-xxx-xxx-xxx"  
> }  
> }  
> }

---

<div class="post-metadata">

**Author:** ![A\_B](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/a_b/32/17104_2.png) [@A\_B](https://discuss.elastic.co/u/A_B)\
**Post date:** [January 4, 2021, 8:40am UTC](https://discuss.elastic.co/t/grokk-patterning-output-to-respective-indexes-based-on-agent-type-or-any-conditionals-not-working/259602/2 "2021-01-04T08:40:32Z")

</div>

Hi @Rohan-boogeyman,

would it be possible for you to format your config using _Preformated text_ instead of _Block quote_. It would be much easier to read 🙂

Which version of Filebeat are you using? Can't see anything immediately wrong with the `if [agent][type] == "filebeat"` bit.

What is the result now? Is `else if [agent][type] == "winlogbeat"` working as expected?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 1, 2021, 10:41am UTC](https://discuss.elastic.co/t/grokk-patterning-output-to-respective-indexes-based-on-agent-type-or-any-conditionals-not-working/259602/3 "2021-02-01T10:41:00Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
