# How do I test my condition statement that is not working?

**URL:** <https://discuss.elastic.co/t/how-do-i-test-my-condition-statement-that-is-not-working/226504>\
**Category:** Logstash\
**Created:** [April 4, 2020, 9:49am UTC](https://discuss.elastic.co/t/how-do-i-test-my-condition-statement-that-is-not-working/226504 "2020-04-04T09:49:35Z")\
**Posts on this page:** 1\
**Showing post:** 2

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [April 4, 2020, 2:53pm UTC](https://discuss.elastic.co/t/how-do-i-test-my-condition-statement-that-is-not-working/226504/2 "2020-04-04T14:53:50Z")

</div>

I suggest you read [this](https://discuss.elastic.co/t/help-needed-in-grok/213827/2) for advice on how to create a grok pattern for a complex string.

You have newlines in your message, so the pattern has to match them. I would start with

```
        match => [ 'message', '^%{WORD}=%{INT:_nrings}
 %{WORD}=%{INT:_phone}
 %{WORD}=%{GREEDYDATA:_informat}
 %{WORD}=%{INT:_tries}
 %{WORD}=%{INT:_callTime}
 %{WORD}=%{GREEDYDATA:_newApp}
 %{WORD}=%{INT:_retryInterval}
 %{WORD}=%{URI:_initialScript}']

```

Extend that one line at a time. Personally I would replace the patterns like %{GREEDYDATA:\_newApp} with `(?<_newApp>[^_]+)`.

---

_[View the full topic](https://discuss.elastic.co/t/how-do-i-test-my-condition-statement-that-is-not-working/226504)._
