# How to filter the logs which has the numeric value greater than specific number in particular field?

**URL:** <https://discuss.elastic.co/t/how-to-filter-the-logs-which-has-the-numeric-value-greater-than-specific-number-in-particular-field/1360>\
**Category:** Logstash\
**Created:** [May 27, 2015, 7:16am UTC](https://discuss.elastic.co/t/how-to-filter-the-logs-which-has-the-numeric-value-greater-than-specific-number-in-particular-field/1360 "2015-05-27T07:16:20Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![selvam](https://avatars.discourse-cdn.com/v4/letter/s/65b543/32.png) [@selvam](https://discuss.elastic.co/u/selvam)\
**Post date:** [May 27, 2015, 7:16am UTC](https://discuss.elastic.co/t/how-to-filter-the-logs-which-has-the-numeric-value-greater-than-specific-number-in-particular-field/1360/1 "2015-05-27T07:16:20Z")

</div>

I am running tomcat service in client. I would like to monitor tomcat access logs and filter the logs which has response time greater than specific number.

e.g : I have the tomcat access log.

192.168.1.10 - - [26/May/2015:21:56:51 -0700] "POST /url HTTP/1.1" 200 50

In the example, it has the response time 50 in the 10th field. i would like to check condition at 10th filed. if the value exceeds the limit(specific number), i need to filter that logs.

Let me, what is the filter(grok or range) will be useful for that and also let me know the syntax.

Thanks in advance.

---

<div class="post-metadata">

**Author:** ![rafaltrojniak](https://avatars.discourse-cdn.com/v4/letter/r/ecc23a/32.png) [@rafaltrojniak](https://discuss.elastic.co/u/rafaltrojniak)\
**Post date:** [May 27, 2015, 6:20pm UTC](https://discuss.elastic.co/t/how-to-filter-the-logs-which-has-the-numeric-value-greater-than-specific-number-in-particular-field/1360/2 "2015-05-27T18:20:21Z")

</div>

Hello,

That was quite easy, and grok filters for tomcat/apache logs are easy to find on google.

Here is full example of what you did, with mathing events with time above 10. I had used 'mutate' and 'add\_tag' to show that.

The rules:

> <https://github.com/rafaltrojniak/logstash_rules/blob/selvam/rules/selvam.conf>

  
The documentation and examples :  

> <https://github.com/rafaltrojniak/logstash_rules/blob/selvam/doc.md>

---

<div class="post-metadata">

**Author:** ![selvam](https://avatars.discourse-cdn.com/v4/letter/s/65b543/32.png) [@selvam](https://discuss.elastic.co/u/selvam)\
**Post date:** [May 28, 2015, 9:11am UTC](https://discuss.elastic.co/t/how-to-filter-the-logs-which-has-the-numeric-value-greater-than-specific-number-in-particular-field/1360/3 "2015-05-28T09:11:25Z")

</div>

Hello,  
It matches all logs which means it sends all the logs to elasticsearch server and adds tag "matched\_above\_10" if the response\_time greater than 10.

Instead of that, it will send response\_time greater than 10 logs only to elasticsearch server(i.e It would drop other logs) and will add tag "matched\_above\_10".

---

<div class="post-metadata">

**Author:** ![selvam](https://avatars.discourse-cdn.com/v4/letter/s/65b543/32.png) [@selvam](https://discuss.elastic.co/u/selvam)\
**Post date:** [May 28, 2015, 11:31am UTC](https://discuss.elastic.co/t/how-to-filter-the-logs-which-has-the-numeric-value-greater-than-specific-number-in-particular-field/1360/4 "2015-05-28T11:31:25Z")

</div>

I used simple regex to grab greater than 50 response value logs and removed "\_grokparsefailure" tags. Now i got the expected results.

filter {  
if [type] == "tomcat\_response" {  
grok {  
match =\> { "message" =\> "%{IP} - - [%{HTTPDATE}] "%{DATA}" %{NUMBER} ([6-9]\d|\d{3,})" }  
add\_tag =\> "slowresponse"  
}  
if "\_grokparsefailure" in [tags] {  
drop { }  
}  
}  
}

Thanks for your assist.

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [May 28, 2015, 6:13pm UTC](https://discuss.elastic.co/t/how-to-filter-the-logs-which-has-the-numeric-value-greater-than-specific-number-in-particular-field/1360/5 "2015-05-28T18:13:47Z")

</div>

> I used simple regex to grab greater than 50 response value logs and removed "\_grokparsefailure" tags. Now i got the expected results.

Yes, but that's not a very nice way of doing it. Given a proper grok expression that extracts the fields in the log (which you should have anyway) you can just do this:

```
filter {
  if [type] == "tomcat_response" and [response_time] > 50 {
    mutate {
      add_tag => "slowresponse"
    }
  } else {
    drop { }
  }
}

```

---

<div class="post-metadata">

**Author:** ![selvam](https://avatars.discourse-cdn.com/v4/letter/s/65b543/32.png) [@selvam](https://discuss.elastic.co/u/selvam)\
**Post date:** [May 29, 2015, 4:39am UTC](https://discuss.elastic.co/t/how-to-filter-the-logs-which-has-the-numeric-value-greater-than-specific-number-in-particular-field/1360/6 "2015-05-29T04:39:44Z")

</div>

I had idea to try else condition today. But you got it. The new syntax makes sense.  
It is perfect.

Thanks.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 5:39am UTC](https://discuss.elastic.co/t/how-to-filter-the-logs-which-has-the-numeric-value-greater-than-specific-number-in-particular-field/1360/7 "2017-07-06T05:39:06Z")

</div>


