# How to extract specific entries matching a pattern to a different file

**URL:** <https://discuss.elastic.co/t/how-to-extract-specific-entries-matching-a-pattern-to-a-different-file/24864>\
**Category:** Logstash\
**Created:** [July 3, 2015, 11:24am UTC](https://discuss.elastic.co/t/how-to-extract-specific-entries-matching-a-pattern-to-a-different-file/24864 "2015-07-03T11:24:34Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![cruizpollino](https://avatars.discourse-cdn.com/v4/letter/c/6a8cbe/32.png) [@cruizpollino](https://discuss.elastic.co/u/cruizpollino)\
**Post date:** [July 3, 2015, 11:24am UTC](https://discuss.elastic.co/t/how-to-extract-specific-entries-matching-a-pattern-to-a-different-file/24864/1 "2015-07-03T11:24:34Z")

</div>

Good morning everyone,

I'm starting with logstash and elasticsearch so maybe this is a silly question, if its sorry for make lost your time guys.

We've set a central server as the syslogd server and rest of servers are forwarding system messages to it.

These log files are later forwarded from this syslog central server to our Logstash, elasticsearch, kibana installation

Indexes are properly created and information is properly forwarded

now we need to move one step further and check the lines on the messages files in order to generate a file with only those lines that match some perl pattern expressions like "nfs\_statfs:\s+statfs\s+error  
" or "Inquiry\s+failed\s+on\s+FCP\s+device\s+with\s+device\s+id\s+0x\w{6}"

this is our current configuration file:

# cat logstash-syslogfullv3.conf

input {  
file {  
path =\> "/var/log/hpoodganglia0\*/\*"  
type =\> "syslog"  
}  
}

filter {  
if [type] == "syslog" {  
grok {  
match =\> { "message" =\> "%{SYSLOGTIMESTAMP:syslog\_timestamp} %{SYSLOGHOST:syslog\_hostname} %{DATA:syslog\_program}(?:[%{POSINT:syslog\_pid}])?: %{GREEDYDATA:syslog\_message}" }  
add\_field =\> ["environment", "DEV"]  
add\_field =\> ["system", "HPC\_pRed\_Cluster"]  
}  
syslog\_pri { }  
date {  
match =\> ["syslog\_timestamp", "MMM d HH:mm:ss", "MMM dd HH:mm:ss"]  
}  
}  
}

output {  
elasticsearch {  
host =\> "rbalhpc06"  
cluster =\> "robinhood"  
}  
}

Thanks in advance for your help and patience

kind Regards

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [July 3, 2015, 11:45am UTC](https://discuss.elastic.co/t/how-to-extract-specific-entries-matching-a-pattern-to-a-different-file/24864/2 "2015-07-03T11:45:48Z")

</div>

Add an extra output, wrapped in a conditional:

```
output {
  if [message] =~ /Inquiry\s+failed\s+on\s+FCP\s+device\s+with\s+device\s+id\s+0x\w{6}/ {
    file {
      path => "/path/to/log"
    }
  }
}
```

---

<div class="post-metadata">

**Author:** ![cruizpollino](https://avatars.discourse-cdn.com/v4/letter/c/6a8cbe/32.png) [@cruizpollino](https://discuss.elastic.co/u/cruizpollino)\
**Post date:** [July 3, 2015, 2:18pm UTC](https://discuss.elastic.co/t/how-to-extract-specific-entries-matching-a-pattern-to-a-different-file/24864/3 "2015-07-03T14:18:56Z")

</div>

good afternoon Markus,

that make the trick, thx a lot for fast help

the file is now be created on syslog server on the proper way, is there a way to make that this file is processed as well and index created on elasticsearch in order to be able to check on kibana the number of entries created in this file?

regards

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [July 3, 2015, 2:25pm UTC](https://discuss.elastic.co/t/how-to-extract-specific-entries-matching-a-pattern-to-a-different-file/24864/4 "2015-07-03T14:25:45Z")

</div>

With the configuration you originally posted you're _already_ sending _all_ messages to Elasticsearch, but then you _additionally_ wanted some messages written to a separate file and that's the question I answered.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 5:35am UTC](https://discuss.elastic.co/t/how-to-extract-specific-entries-matching-a-pattern-to-a-different-file/24864/5 "2017-07-06T05:35:35Z")

</div>


