# How to filter only error from log file

**URL:** <https://discuss.elastic.co/t/how-to-filter-only-error-from-log-file/88591>\
**Category:** Logstash\
**Created:** [June 7, 2017, 2:05pm UTC](https://discuss.elastic.co/t/how-to-filter-only-error-from-log-file/88591 "2017-06-07T14:05:38Z")\
**Posts on this page:** 11\
**Page:** 1

<div class="post-metadata">

**Author:** ![baha1](https://avatars.discourse-cdn.com/v4/letter/b/b77776/32.png) [@baha1](https://discuss.elastic.co/u/baha1)\
**Post date:** [June 7, 2017, 2:05pm UTC](https://discuss.elastic.co/t/how-to-filter-only-error-from-log-file/88591/1 "2017-06-07T14:05:39Z")

</div>

Hi community,  
i have a log file contains INFO,WARN and ERROR like :

`17:37:17,103 ERROR [org.apache.catalina.core.ContainerBase.[jboss.web].[default-host].....rest of text.`

what is the convenient grok to filter only All errors.  
Thanks for any help.

---

<div class="post-metadata">

**Author:** ![Jaxon\_Kochel](https://avatars.discourse-cdn.com/v4/letter/j/da6949/32.png) [@Jaxon\_Kochel](https://discuss.elastic.co/u/Jaxon_Kochel)\
**Post date:** [June 7, 2017, 7:32pm UTC](https://discuss.elastic.co/t/how-to-filter-only-error-from-log-file/88591/2 "2017-06-07T19:32:55Z")

</div>

you would use whatever grok statement that would match your entire log, I tested with a basic one just for simplicity

```
grok{
	  match => { "message" => "%{TIME:timestamp} %{LOGLEVEL:LEVEL} %{GREEDYDATA:whateverElseYoureFiltering}" }
	}

```

so then if you only want errors you would then add an if statement that checks if "ERROR" is in LEVEL

```
if	"ERROR" in [LEVEL]
{
}

```

Then do whatever else you needed with it

So I tested it with only printing if the word ERROR was in the message like so.

using htis code to test:

```
input {
	stdin{}
}

filter {

	grok{
	  match => { "message" => "%{TIME:timestamp} %{LOGLEVEL:LEVEL} %{GREEDYDATA:whateverElseYoureFiltering}" }
	}
	
}

output {
if	"ERROR" in [LEVEL]
{
	 stdout { codec => rubydebug }
}
}
```

---

<div class="post-metadata">

**Author:** ![baha1](https://avatars.discourse-cdn.com/v4/letter/b/b77776/32.png) [@baha1](https://discuss.elastic.co/u/baha1)\
**Post date:** [June 8, 2017, 10:06am UTC](https://discuss.elastic.co/t/how-to-filter-only-error-from-log-file/88591/3 "2017-06-08T10:06:51Z")

</div>

Thank you so much @Jaxon_Kochel,i tested this code but the filter doesn't work.take a look around it.

```
input {
    beats {
       port => "5043"
    }
}
filter{
grok{
	  match => { "message" => "%{TIME:timestamp} %{LOGLEVEL:LEVEL} %{GREEDYDATA:errormsg}" }
	}
}
output {
if	"ERROR" in [LEVEL]
{
	 stdout { codec => rubydebug }
}
}
```

---

<div class="post-metadata">

**Author:** ![EthanStark](https://avatars.discourse-cdn.com/v4/letter/e/d6d6ee/32.png) [@EthanStark](https://discuss.elastic.co/u/EthanStark)\
**Post date:** [June 8, 2017, 10:23am UTC](https://discuss.elastic.co/t/how-to-filter-only-error-from-log-file/88591/4 "2017-06-08T10:23:22Z")

</div>

@echo off  
sed -n "/ERROR/p" "cds.log" \> "cds1.txt"  
sed -e "/HRWPC\_RFC\_EP\_READ\_PHOTO\_URI threw an Exception of type AbapException/d" "cds1.txt" \> "cds2.txt"  
sed -e "/ bad SQL grammar [DROP/d" "cds2.txt" \> "cds3.txt"

@echo off  
set intIN=-1  
set intOUT=0  
set /a intIN+=1  
set /a intOUT+=1  
sed -n "/ERROR/p" "cds.log" \> "cds%intOUT%.txt"  
set /a intIN+=1  
set /a intOUT+=1  
sed -e "/HRWPC\_RFC\_EP\_READ\_PHOTO\_URI threw an Exception of type AbapException/d" "cds%intIN%.txt" \> "cds%intOUT%.txt"  
set /a intIN+=1  
set /a intOUT+=1  
sed -e "/ bad SQL grammar [DROP/d" "cds%intIN%.txt" \> "cds%intOUT%.txt"

Ethan Stark  
[Apps4Rent](http://cloudappsportal.com/)

---

<div class="post-metadata">

**Author:** ![Jaxon\_Kochel](https://avatars.discourse-cdn.com/v4/letter/j/da6949/32.png) [@Jaxon\_Kochel](https://discuss.elastic.co/u/Jaxon_Kochel)\
**Post date:** [June 8, 2017, 1:49pm UTC](https://discuss.elastic.co/t/how-to-filter-only-error-from-log-file/88591/5 "2017-06-08T13:49:00Z")

</div>

Not sure, works fine for me. if oyu remove the if error part and just do the stdout part does it print anything at all? if not, you're beats is not working correctly.

---

<div class="post-metadata">

**Author:** ![baha1](https://avatars.discourse-cdn.com/v4/letter/b/b77776/32.png) [@baha1](https://discuss.elastic.co/u/baha1)\
**Post date:** [June 8, 2017, 1:59pm UTC](https://discuss.elastic.co/t/how-to-filter-only-error-from-log-file/88591/6 "2017-06-08T13:59:12Z")

</div>

Yeh you are right,when i tested with grokdebug it works fine.but when i navigate to [http://localhost:9200/logstash-2017.06.08/\_search.i](http://localhost:9200/logstash-2017.06.08/_search.i) don't find the result wanted by the [filter.so](http://filter.so),where i can see the result of my filter.

---

<div class="post-metadata">

**Author:** ![Jaxon\_Kochel](https://avatars.discourse-cdn.com/v4/letter/j/da6949/32.png) [@Jaxon\_Kochel](https://discuss.elastic.co/u/Jaxon_Kochel)\
**Post date:** [June 8, 2017, 3:16pm UTC](https://discuss.elastic.co/t/how-to-filter-only-error-from-log-file/88591/7 "2017-06-08T15:16:52Z")

</div>

You'll need to use Kibana or another tool to see your results that are stored inside of elasticsearch. In kibana you can even specify what you want to see. so you could query your elasticsearch storage for LEVEL:ERROR in kibana and it would only show you logs with the value "ERROR" for LOGLEVEL.

---

<div class="post-metadata">

**Author:** ![baha1](https://avatars.discourse-cdn.com/v4/letter/b/b77776/32.png) [@baha1](https://discuss.elastic.co/u/baha1)\
**Post date:** [June 8, 2017, 3:24pm UTC](https://discuss.elastic.co/t/how-to-filter-only-error-from-log-file/88591/8 "2017-06-08T15:24:41Z")

</div>

Yeh,but i need rest Api to consume it inside java application.if you have an idea to do it.

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [June 9, 2017, 7:48am UTC](https://discuss.elastic.co/t/how-to-filter-only-error-from-log-file/88591/9 "2017-06-09T07:48:27Z")

</div>

> Yeh,but i need rest Api to consume it inside java application.if you have an idea to do it.

Questions about how to make ES queries from Java is better asked in the Elasticsearch category. When you do that please be more specific.

---

<div class="post-metadata">

**Author:** ![baha1](https://avatars.discourse-cdn.com/v4/letter/b/b77776/32.png) [@baha1](https://discuss.elastic.co/u/baha1)\
**Post date:** [June 9, 2017, 11:54am UTC](https://discuss.elastic.co/t/how-to-filter-only-error-from-log-file/88591/10 "2017-06-09T11:54:27Z")

</div>

Thank you Sir,for helping me out.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 7, 2017, 11:54am UTC](https://discuss.elastic.co/t/how-to-filter-only-error-from-log-file/88591/11 "2017-07-07T11:54:29Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
