# How does Logstash determine that a field matches a string regularly？

**URL:** <https://discuss.elastic.co/t/how-does-logstash-determine-that-a-field-matches-a-string-regularly/310586>\
**Category:** Logstash\
**Created:** [July 26, 2022, 2:45am UTC](https://discuss.elastic.co/t/how-does-logstash-determine-that-a-field-matches-a-string-regularly/310586 "2022-07-26T02:45:55Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![wentao\_Xiong](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/wentao_xiong/32/108340_2.png) [@wentao\_Xiong](https://discuss.elastic.co/u/wentao_Xiong)\
**Post date:** [July 26, 2022, 2:45am UTC](https://discuss.elastic.co/t/how-does-logstash-determine-that-a-field-matches-a-string-regularly/310586/1 "2022-07-26T02:45:55Z")

</div>

I am a newcomer to ELK, and now I encounter a problem as shown in the title: How does Logstash determine that a field matches a string regularly?  
**such as whether the [path] field contains the "err" string? (the path field means the filename such as "/var/log/game\_err.log")**  
Is this how it is configured in logstash.conf?

Sincerely hope to get an answer, thank you!

---

<div class="post-metadata">

**Author:** ![sudhagar\_ramesh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sudhagar_ramesh/32/105673_2.png) [@sudhagar\_ramesh](https://discuss.elastic.co/u/sudhagar_ramesh)\
**Post date:** [July 26, 2022, 2:59am UTC](https://discuss.elastic.co/t/how-does-logstash-determine-that-a-field-matches-a-string-regularly/310586/2 "2022-07-26T02:59:59Z")

</div>

Hello @wentao_Xiong

You are trying to get the file path if that is the case then use filebeat. To get the substring from the filename "err" then use grok pattern.

```auto
input
{
<Your-filebeats-configuration>
}

filter
{
grok
{
match => 
{
"message" => '/%{GREEDYDATA:path}/%{GREEDYDATA:filename}'
}
}

}
output
{
if [filename] == "game_err"
{
stdout{codec => jsondebug}
}
}

```

---

<div class="post-metadata">

**Author:** ![wentao\_Xiong](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/wentao_xiong/32/108340_2.png) [@wentao\_Xiong](https://discuss.elastic.co/u/wentao_Xiong)\
**Post date:** [July 26, 2022, 4:24am UTC](https://discuss.elastic.co/t/how-does-logstash-determine-that-a-field-matches-a-string-regularly/310586/4 "2022-07-26T04:24:27Z")

</div>

Hello~ @sudhagar_ramesh  
Thanks a lot for your answer! I would like to elaborate on my situation:

The data I collect has the format of "/var/log/game\_err.log" or "/xx/xx/xx\_errxx.log" in the field [path] value, I need to judge whether the field [path] **contains** Some string "err"?

My logstash.conf is

```auto
input {
  beats {
    port => 5044
  }
}

filter {
  if [path] in "err" {
    mutate {
      add_field => {
        "log_type" => "err"
      }
    }
  }
  if [path] in "oss" {
    mutate {
      add_field => {
        "log_type" => "oss"
      }
    }
  }
}

output {
  if [log_type] == "err" {
    elasticsearch {
      hosts => ["http:// ****** :9200"]
      index => "log-err-%{+YYYY.MM.dd}"
      user => " ****"
      password => " ****"
    }
  }else if [log_type] == "oss" {
    redis {
      host => " ******"
      password => " ****"
      port => 6379
      data_type => list
      db => 0
      key => "log-oss"
    }
  }
}

```

Why if [path] in "err" doesn't work?

Thanks again and looking forward to your reply!

---

<div class="post-metadata">

**Author:** ![wentao\_Xiong](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/wentao_xiong/32/108340_2.png) [@wentao\_Xiong](https://discuss.elastic.co/u/wentao_Xiong)\
**Post date:** [July 26, 2022, 9:16am UTC](https://discuss.elastic.co/t/how-does-logstash-determine-that-a-field-matches-a-string-regularly/310586/5 "2022-07-26T09:16:30Z")

</div>

I solved this problem，thanks ！

```auto
input {
  beats {
    port => 5044
  }
}

filter {
  if [log][file][path] =~ /err/ {
    mutate {
      add_field => {
        "log_type" => "err"
      }
    }
  }
  if [log][file][path] =~ /oss/ {
    mutate {
      add_field => {
        "log_type" => "oss"
      }
    }
  }
}

output {
  if [log_type] == "err" {
    elasticsearch {
      hosts => ["http://xxxxx:9200"]
      index => "log-err-%{+YYYY.MM.dd}"
      user => "xxxxxxxxx"
      password => "xxxx"
    }
  }else if [log_type] == "oss" {
    redis {
      host => "xxxxxxxx"
      password => "xxxx"
      port => 6379
      data_type => list
      db => 0
      key => "log-oss"
    }
  }

  stdout { codec => rubydebug }
}

```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 23, 2022, 9:16am UTC](https://discuss.elastic.co/t/how-does-logstash-determine-that-a-field-matches-a-string-regularly/310586/6 "2022-08-23T09:16:53Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
