# How to calculate first pass logic and reren for testcase using logstash grok

**URL:** <https://discuss.elastic.co/t/how-to-calculate-first-pass-logic-and-reren-for-testcase-using-logstash-grok/313089>\
**Category:** Logstash\
**Created:** [August 28, 2022, 10:43am UTC](https://discuss.elastic.co/t/how-to-calculate-first-pass-logic-and-reren-for-testcase-using-logstash-grok/313089 "2022-08-28T10:43:35Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![aish794726](https://avatars.discourse-cdn.com/v4/letter/a/a6a055/32.png) [@aish794726](https://discuss.elastic.co/u/aish794726)\
**Post date:** [August 28, 2022, 10:43am UTC](https://discuss.elastic.co/t/how-to-calculate-first-pass-logic-and-reren-for-testcase-using-logstash-grok/313089/1 "2022-08-28T10:43:35Z")

</div>

am working on grok, have very few knowledge about it, we are preparing regression dashboard there we need first pass and reren so that system should understand, these script got pass infirst these are fail n might required rerun, here is my logic..but ELK is new to me we want this syntax using grok,logstash here is the formula

First pass logic --\> total TC-first run passed TC/total TC \* 100

Rerun--\> rerun =(prevRun\* prevPass + passPerc)/(prevRun + 1)

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [August 28, 2022, 2:43pm UTC](https://discuss.elastic.co/t/how-to-calculate-first-pass-logic-and-reren-for-testcase-using-logstash-grok/313089/2 "2022-08-28T14:43:58Z")

</div>

Grok is used to parse string data into fields. It is not clear to me how grok is related to what you are describing.it would be useful if you could elaborate more and privide an exame of what the data looks like and what you are looking to achieve with this.

---

<div class="post-metadata">

**Author:** ![aish794726](https://avatars.discourse-cdn.com/v4/letter/a/a6a055/32.png) [@aish794726](https://discuss.elastic.co/u/aish794726)\
**Post date:** [August 29, 2022, 4:42am UTC](https://discuss.elastic.co/t/how-to-calculate-first-pass-logic-and-reren-for-testcase-using-logstash-grok/313089/3 "2022-08-29T04:42:30Z")

</div>

hi team this is taken as input

input {  
file {  
path =\> "/root/logs/logs/0001\_ipos\_nightly\_evr\_td\_031321\_182638.log"  
start\_position =\> "beginning"  
sincedb\_path =\> "/dev/null"  
type =\> "log"  
}  
file {

```
     path => "/root/logs/0001_ipos_nightly_evr_td_031321_182638.result"
     #path => "/root/logs/*.result"
     codec => multiline {
     pattern => "^#"
                negate => true
                what => "next"
            }
     start_position => "beginning"
     sincedb_path => "/dev/null"
     type => "result"

```

}  
}

filter {  
if [type] == "log" {  
grok {  
match =\> { "message" =\> "\\s%{DATA:timestamp}\s_LOG\s_\\s_CHECK\s%{DATA:Chck\_num}\s_:\s\*...\s\*%{WORD:status}\s\*...\s\*%{GREEDYDATA:checkpoint}" }  
add\_field =\> { "index" =\> "TESTCASE" }  
add\_field =\> { "taskid" =\> "TESTCASE\_LOG" }  
}  
if "\_grokparsefailure" in [tags] {  
grok{  
match =\> { "message" =\> "Start Time:\s\*%{GREEDYDATA:script\_start\_time}" }  
match =\> { "message" =\> "Script\s_Name:\s_%{GREEDYDATA:script\_path}"}  
match =\> { "message" =\> "Machine Name \s\*:\s\*%{GREEDYDATA:server\_name}"}  
match =\> { "message" =\> "DEVICE\d+=%{GREEDYDATA:devices}\s_DEVICE\d+=%{GREEDYDATA:devices}\s_DEVICE\d+=%{GREEDYDATA:devices}"}  
add\_field =\> { "index" =\> "TESTSCRIPT" }  
add\_field =\> { "taskid" =\> "TESTSCRIPT\_LOG" }  
remove\_tag =\> ["\_grokparsefailure"]  
}  
}  
aggregate {  
task\_id =\> "%{taskid}"

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [August 29, 2022, 11:11am UTC](https://discuss.elastic.co/t/how-to-calculate-first-pass-logic-and-reren-for-testcase-using-logstash-grok/313089/4 "2022-08-29T11:11:25Z")

</div>

What does the data in the file look like? What is the output you are looking to achieve?

---

<div class="post-metadata">

**Author:** ![aish794726](https://avatars.discourse-cdn.com/v4/letter/a/a6a055/32.png) [@aish794726](https://discuss.elastic.co/u/aish794726)\
**Post date:** [August 31, 2022, 11:23am UTC](https://discuss.elastic.co/t/how-to-calculate-first-pass-logic-and-reren-for-testcase-using-logstash-grok/313089/5 "2022-08-31T11:23:50Z")

</div>

Hi Christian,  
please find my inputi files

{"errors":"0","log":{"file":{"path":"/root/logs/0015\_ha\_l3vpn\_ldp\_ospf\_backbone\_part1\_031321\_200626.result.xml"}},"index":["TESTCASE","TESTSCRIPT"],"fail":"0","skip":"0","time":"2491","tests":"1","type":"resultx"}  
{"dut\_type":"EVR\_VMWARE","log":{"file":{"path":"/root/logs/0015\_ha\_l3vpn\_ldp\_ospf\_backbone\_part1\_031321\_200626.result.xml"}},"index":["TESTCASE","TESTSCRIPT"],"type":"resultx"}  
{"Time":"13MAR2021 18h33m48s","testcasenum":"8","log":{"file":{"path":"/root/logs/0001\_ipos\_nightly\_evr\_td\_031321\_182638.result"}},"index":"TESTSCRIPT","testcase":"Verify OSPF Nbrs and Routes in mcast context","STATUS":"PASS","type":"result"}  
{"Time":"13MAR2021 18h34m32s","testcasenum":"18","log":{"file":{"path":"/root/logs/0001\_ipos\_nightly\_evr\_td\_031321\_182638.result"}},"index":"TESTSCRIPT","testcase":"Verify ICR State","STATUS":"PASS","type":"result"}  
{"Time":"13MAR2021 18h34m42s","testcasenum":"22","log":{"file":{"path":"/root/logs/0001\_ipos\_nightly\_evr\_td\_031321\_182638.result"}},"index":"TESTSCRIPT","testcase":"Verify RSVP Sanity","STATUS":"PASS","type":"result"}  
{"Time":"13MAR2021 18h34m52s","testcasenum":"25","log":{"file":{"path":"/root/logs/0001\_ipos\_nightly\_evr\_td\_031321\_182638.result"}},"index":"TESTSCRIPT","testcase":"Verify ip route summary in all contexts","STATUS":"PASS","type":"result"}  
{"Time":"13MAR2021 18h35m23s","testcasenum":"38","log":{"file":{"path":"/root/logs/0001\_ipos\_nightly\_evr\_td\_031321\_182638.result"}},"index":"TESTSCRIPT","testcase":"BGP Diverse Path Verification","STATUS":"PASS","type":"result"}  
{"Time":"13MAR2021 18h35m27s","testcasenum":"40","log":{"file":{"path":"/root/logs/0001\_ipos\_nightly\_evr\_td\_031321\_182638.result"}},"index":"TESTSCRIPT","testcase":"BGP Multi Path Verification","STATUS":"PASS","type":"result"}  
{"Time":"13MAR2021 18h35m38s","testcasenum":"41","log":{"file":{"path":"/root/logs/0001\_ipos\_nightly\_evr\_td\_031321\_182638.result"}},"index":"TESTSCRIPT","testcase":"TC38 Ping test","STATUS":"PASS","type":"result"}  
{"script\_path":"/project/iposarts/iposr6k/IPOS-TP/ipostest/ARTS/tests/IPOS/EVR-TD/nightly/ipos\_nightly\_lsv\_evr\_td/ipos\_nightly\_evr\_td/ipos\_nightly\_evr\_td","log":{"file":{"path":"/root/logs/logs/0001\_ipos\_nightly\_evr\_td\_031321\_182638.log"}},"index":"TESTSCRIPT","type":"log"}  
{"dut\_type":"EVR\_VMWARE","log":{"file":{"path":"/root/logs/0004\_FT17658\_ldp\_hardening\_031321\_183241.result.xml"}},"index":["TESTCASE","TESTSCRIPT"],"type":"resultx"}

These all are input from my testscipt, so some of them will pass in first run some might need rerun, how do I write program form that, if you could help here please

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 28, 2022, 11:24am UTC](https://discuss.elastic.co/t/how-to-calculate-first-pass-logic-and-reren-for-testcase-using-logstash-grok/313089/6 "2022-09-28T11:24:21Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
