# How to filter Errors only from logs? using logstash

**URL:** <https://discuss.elastic.co/t/how-to-filter-errors-only-from-logs-using-logstash/141563>\
**Category:** Logstash\
**Created:** [July 25, 2018, 12:26pm UTC](https://discuss.elastic.co/t/how-to-filter-errors-only-from-logs-using-logstash/141563 "2018-07-25T12:26:06Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![naga\_kunchala](https://avatars.discourse-cdn.com/v4/letter/n/d9b06d/32.png) [@naga\_kunchala](https://discuss.elastic.co/u/naga_kunchala)\
**Post date:** [July 25, 2018, 12:26pm UTC](https://discuss.elastic.co/t/how-to-filter-errors-only-from-logs-using-logstash/141563/1 "2018-07-25T12:26:06Z")

</div>

Hi, I am using logstash in our project, How to filter debug and info log from logs ? and saved separate file?

i am using below configuration:

input {  
file {  
path =\> "/home/kunchala/TESTING/mywork/trap\_testing/consul.log"  
start\_position =\> "beginning"  
}  
}  
filter {

```
    grok{
  match => { "message" => "%{SYSLOGTIMESTAMP:syslog_timestamp} %{SYSLOGHOST:syslog_hostname} %{LOGLEVEL:LEVEL} %{GREEDYDATA:whateverElseYoureFiltering}" }
    }

```

}  
output {  
if [level] == "DEBUG" {  
file{  
path =\> "/home/kunchala/TESTING/mywork/trap\_testing/DEBUG.log"  
}  
}  
else if [level] == "INFO" {  
file{  
path =\> "/home/kunchala/TESTING/mywork/trap\_testing/INFO.log"  
}  
}

```
 else {
     file{
        path => "/home/kunchala/TESTING/mywork/trap_testing/MO.log"
       }
      }
 stdout { codec => rubydebug }
}
```

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [July 25, 2018, 12:32pm UTC](https://discuss.elastic.co/t/how-to-filter-errors-only-from-logs-using-logstash/141563/2 "2018-07-25T12:32:47Z")

</div>

And what is the problem you have with the result of that?

---

<div class="post-metadata">

**Author:** ![naga\_kunchala](https://avatars.discourse-cdn.com/v4/letter/n/d9b06d/32.png) [@naga\_kunchala](https://discuss.elastic.co/u/naga_kunchala)\
**Post date:** [July 25, 2018, 12:37pm UTC](https://discuss.elastic.co/t/how-to-filter-errors-only-from-logs-using-logstash/141563/3 "2018-07-25T12:37:32Z")

</div>

my concern is all **debug** information i want to save in DEBUG.log and all **info** log information need to be save in INFO.log file. but that one is not happening. all the debug , info ,etc logging information stored in MO.log file . could you please help me on this anything i did wrong

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [July 25, 2018, 12:41pm UTC](https://discuss.elastic.co/t/how-to-filter-errors-only-from-logs-using-logstash/141563/4 "2018-07-25T12:41:06Z")

</div>

Please provide an example log line.

---

<div class="post-metadata">

**Author:** ![naga\_kunchala](https://avatars.discourse-cdn.com/v4/letter/n/d9b06d/32.png) [@naga\_kunchala](https://discuss.elastic.co/u/naga_kunchala)\
**Post date:** [July 25, 2018, 12:50pm UTC](https://discuss.elastic.co/t/how-to-filter-errors-only-from-logs-using-logstash/141563/5 "2018-07-25T12:50:40Z")

</div>

{"message":"2018-07-25\_16:57:48.39018 consul 2018/07/25 11:57:48 [DEBUG] agent: Service 'consul' in sync\n","@version":"1","crs":"consul","mms":" 2018/07/25 11:57:48 [DEBUG] agent: Service 'consul' in sync\n","host":"205.26.198.10","ts":"2018-07-25\_16:57:48.39018","@timestamp":"2018-07-25T16:57:48.389Z"}

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [July 25, 2018, 12:58pm UTC](https://discuss.elastic.co/t/how-to-filter-errors-only-from-logs-using-logstash/141563/6 "2018-07-25T12:58:11Z")

</div>

> [@naga\_kunchala](#):
>
> 2018-07-25\_16:57:48.39018 consul 2018/07/25 11:57:48 [DEBUG] agent: Service 'consul' in sync\n

Is that what a line of the log file looks like? If so, it is not even close to matching your grok filter. It has a timestamp that I would not expect to match %{SYSLOGTIMESTAMP} followed by a hostname and a second timestamp.

Build your grok filter one field at a time and make sure the first part matches before adding additional fields.

And for that format [dissect](https://www.elastic.co/guide/en/logstash/current/plugins-filters-dissect.html) is probably better than grok.

---

<div class="post-metadata">

**Author:** ![naga\_kunchala](https://avatars.discourse-cdn.com/v4/letter/n/d9b06d/32.png) [@naga\_kunchala](https://discuss.elastic.co/u/naga_kunchala)\
**Post date:** [July 25, 2018, 1:00pm UTC](https://discuss.elastic.co/t/how-to-filter-errors-only-from-logs-using-logstash/141563/7 "2018-07-25T13:00:26Z")

</div>

i am new to logstash, can you please send me the filter for that.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 22, 2018, 1:00pm UTC](https://discuss.elastic.co/t/how-to-filter-errors-only-from-logs-using-logstash/141563/8 "2018-08-22T13:00:26Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
