# How can I check loglevel with use of If else condition in logstash filter?

**URL:** <https://discuss.elastic.co/t/how-can-i-check-loglevel-with-use-of-if-else-condition-in-logstash-filter/250844>\
**Category:** Logstash\
**Created:** [October 2, 2020, 8:53pm UTC](https://discuss.elastic.co/t/how-can-i-check-loglevel-with-use-of-if-else-condition-in-logstash-filter/250844 "2020-10-02T20:53:13Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Bhavin\_Varsur](https://avatars.discourse-cdn.com/v4/letter/b/ecccb3/32.png) [@Bhavin\_Varsur](https://discuss.elastic.co/u/Bhavin_Varsur)\
**Post date:** [October 2, 2020, 8:53pm UTC](https://discuss.elastic.co/t/how-can-i-check-loglevel-with-use-of-if-else-condition-in-logstash-filter/250844/1 "2020-10-02T20:53:13Z")

</div>

filter{  
# 1. for LogLevel.Error logs  
grok{  
match=\> ["message","%{DATESTAMP:timestamp} %{LOGLEVEL:level} %{USERNAME:logger}  
%{USER:user} %{URI:url} %{USER:method} %{IPV4:clientIp} %{GREEDYDATA:message}"]  
}  
# 2. for other Level logs except Error  
grok{  
match=\> ["message","%{DATESTAMP:timestamp} %{LOGLEVEL:level} %{USERNAME:logger}  
%{USER:user} %{GREEDYDATA:message}"]  
}  
}

Here are two grok patterns i want to use both.  
but whether loglevel is Error and Fatal I need to use number 1 grok pattern.  
and the others levels like Warn Debug Trace Info I need the number 2 grok pattern.  
How can I do that?

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [October 2, 2020, 9:24pm UTC](https://discuss.elastic.co/t/how-can-i-check-loglevel-with-use-of-if-else-condition-in-logstash-filter/250844/2 "2020-10-02T21:24:44Z")

</div>

Two options I can think of

One is parse out the level before parsing the rest of the line

```
grok { match=> ["message","^%{DATESTAMP:timestamp} %{LOGLEVEL:level} %{GREEDYDATA:restOfLine}"] }
if [level] in ["Error", "Fatal"] {
    grok { match=> ["restOfLine", "^%{USERNAME:logger} %{USER:user} %{GREEDYDATA:message}"] }
} else {
    grok { match=> ["restOfLine", "^%{USERNAME:logger} %{USER:user} %{URI:url} %{USER:method} %{IPV4:clientIp} %{GREEDYDATA:message}"] }
}

```

The other is to try both patterns, the more specific one first, and see which one works:

```
grok {
    match=> {
        "message" => [
            "%{DATESTAMP:timestamp} %{LOGLEVEL:level} %{USERNAME:logger} %{USER:user} %{URI:url} %{USER:method} %{IPV4:clientIp} % GREEDYDATA:message}",
            "%{DATESTAMP:timestamp} %{LOGLEVEL:level} %{USERNAME:logger} %{USER:user} %{GREEDYDATA:message}"
        ]
    }
}
```

---

<div class="post-metadata">

**Author:** ![Bhavin\_Varsur](https://avatars.discourse-cdn.com/v4/letter/b/ecccb3/32.png) [@Bhavin\_Varsur](https://discuss.elastic.co/u/Bhavin_Varsur)\
**Post date:** [October 3, 2020, 7:34am UTC](https://discuss.elastic.co/t/how-can-i-check-loglevel-with-use-of-if-else-condition-in-logstash-filter/250844/3 "2020-10-03T07:34:08Z")

</div>

the first one you suggested it works  
Thanks you !

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 31, 2020, 7:34am UTC](https://discuss.elastic.co/t/how-can-i-check-loglevel-with-use-of-if-else-condition-in-logstash-filter/250844/4 "2020-10-31T07:34:21Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
