# How to create grok filter on response field

**URL:** <https://discuss.elastic.co/t/how-to-create-grok-filter-on-response-field/152667>\
**Category:** Elasticsearch\
**Created:** [October 16, 2018, 1:28pm UTC](https://discuss.elastic.co/t/how-to-create-grok-filter-on-response-field/152667 "2018-10-16T13:28:58Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![eyaldavid](https://avatars.discourse-cdn.com/v4/letter/e/e274bd/32.png) [@eyaldavid](https://discuss.elastic.co/u/eyaldavid)\
**Post date:** [October 16, 2018, 1:28pm UTC](https://discuss.elastic.co/t/how-to-create-grok-filter-on-response-field/152667/1 "2018-10-16T13:28:58Z")

</div>

Hi Guys

im having trouble to add filter on respons\_code

in kibana im doing it easily : response\_code:[400 TO 600]

how to translate it to grok and filter in filter.conf ?

Thanks

---

<div class="post-metadata">

**Author:** ![jakelandis](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jakelandis/32/36163_2.png) [@jakelandis](https://discuss.elastic.co/u/jakelandis)\
**Post date:** [October 16, 2018, 10:07pm UTC](https://discuss.elastic.co/t/how-to-create-grok-filter-on-response-field/152667/2 "2018-10-16T22:07:50Z")

</div>

I am not sure I understand the question.

Is this for Logstash grok ?

What is an example string you want to parse ?  
What are the parts you want as the result of the parsing ?

---

<div class="post-metadata">

**Author:** ![eyaldavid](https://avatars.discourse-cdn.com/v4/letter/e/e274bd/32.png) [@eyaldavid](https://discuss.elastic.co/u/eyaldavid)\
**Post date:** [October 17, 2018, 6:05am UTC](https://discuss.elastic.co/t/how-to-create-grok-filter-on-response-field/152667/3 "2018-10-17T06:05:06Z")

</div>

Hi

Thanks for the fast response

yes it for logstash grok

im trying to do something like this

json{  
if ["\_source"]["response\_code"] is not between "400..600"  
drop { }  
}

i have messages that im collecting and I want to see only the messages that are relevant for me

which means only those who holds in response code the range between 400 TO 600 if it is not in the range i don't want them to be seen at all in kibana

any idea the piece of code i wrote doesn't wok ... 🙂

Thanks

---

<div class="post-metadata">

**Author:** ![jakelandis](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jakelandis/32/36163_2.png) [@jakelandis](https://discuss.elastic.co/u/jakelandis)\
**Post date:** [October 17, 2018, 1:49pm UTC](https://discuss.elastic.co/t/how-to-create-grok-filter-on-response-field/152667/4 "2018-10-17T13:49:06Z")

</div>

I think this is the conditional you want (in the filter section):

```auto
if [response_code] >= 400 and [response_code] <= 600 {
	drop {}
	}
}

```

Usually with Logstash you are not working against the `_source` root (unless you are using the elasticsearch input). Also, the conditional should be outside the filter, in your example the json{} block should before or after the conditional, not around it.

hope this helps.

---

<div class="post-metadata">

**Author:** ![eyaldavid](https://avatars.discourse-cdn.com/v4/letter/e/e274bd/32.png) [@eyaldavid](https://discuss.elastic.co/u/eyaldavid)\
**Post date:** [October 17, 2018, 2:02pm UTC](https://discuss.elastic.co/t/how-to-create-grok-filter-on-response-field/152667/5 "2018-10-17T14:02:12Z")

</div>

Hi  
thank you this what i needed ...

if [response\_code] =~ "^[1-3]" {  
drop { }  
}

thank you very much

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 14, 2018, 2:13pm UTC](https://discuss.elastic.co/t/how-to-create-grok-filter-on-response-field/152667/6 "2018-11-14T14:13:24Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
