# How can I make my Grok filter match a file extension or blank (if no extension)?

**URL:** <https://discuss.elastic.co/t/how-can-i-make-my-grok-filter-match-a-file-extension-or-blank-if-no-extension/286011>\
**Category:** Logstash\
**Created:** [October 6, 2021, 10:37am UTC](https://discuss.elastic.co/t/how-can-i-make-my-grok-filter-match-a-file-extension-or-blank-if-no-extension/286011 "2021-10-06T10:37:30Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![nsouth](https://avatars.discourse-cdn.com/v4/letter/n/ecccb3/32.png) [@nsouth](https://discuss.elastic.co/u/nsouth)\
**Post date:** [October 6, 2021, 10:37am UTC](https://discuss.elastic.co/t/how-can-i-make-my-grok-filter-match-a-file-extension-or-blank-if-no-extension/286011/1 "2021-10-06T10:37:30Z")

</div>

I have the following grok filter which extracts the `file_extension` from a field. It works except fine for files which have no extension, which generate a `_grokparsefailure` tag. For files with no extension, I would like the `file_extension` value set to an empty string. How can I accomplish this? Thank you!

```auto
        grok {
            match => { "file_path" => "(?<file_extension>\.[^.]+$)"}
            keep_empty_captures => true
        }

```

---

<div class="post-metadata">

**Author:** ![aaron-nimocks](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/aaron-nimocks/32/73965_2.png) [@aaron-nimocks](https://discuss.elastic.co/u/aaron-nimocks)\
**Post date:** [October 6, 2021, 11:49am UTC](https://discuss.elastic.co/t/how-can-i-make-my-grok-filter-match-a-file-extension-or-blank-if-no-extension/286011/2 "2021-10-06T11:49:10Z")

</div>

First thought is to only grok if it contains a period and if not then add the field with empty string.

```auto
if "." in [file_path] {
 grok {
  match => { "file_path" => "(?<file_extension>\.[^.]+$)"}
  keep_empty_captures => true
 }
} else {
 mutate { add_field => { "file_extension" => "" } }
}

```

---

<div class="post-metadata">

**Author:** ![nsouth](https://avatars.discourse-cdn.com/v4/letter/n/ecccb3/32.png) [@nsouth](https://discuss.elastic.co/u/nsouth)\
**Post date:** [October 6, 2021, 1:30pm UTC](https://discuss.elastic.co/t/how-can-i-make-my-grok-filter-match-a-file-extension-or-blank-if-no-extension/286011/3 "2021-10-06T13:30:01Z")

</div>

That works! I actually chose to check the regex instead of just checking for a period in the string.

```auto
if ([file_path] =~ /\.[^.]+$/ ) {

```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 3, 2021, 1:30pm UTC](https://discuss.elastic.co/t/how-can-i-make-my-grok-filter-match-a-file-extension-or-blank-if-no-extension/286011/4 "2021-11-03T13:30:45Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
