# How to make logstash filter multiple grok pattern

**URL:** <https://discuss.elastic.co/t/how-to-make-logstash-filter-multiple-grok-pattern/309810>\
**Category:** Logstash\
**Tags:** docker\
**Created:** [July 17, 2022, 8:32am UTC](https://discuss.elastic.co/t/how-to-make-logstash-filter-multiple-grok-pattern/309810 "2022-07-17T08:32:01Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![lzold\_z](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/lzold_z/32/108411_2.png) [@lzold\_z](https://discuss.elastic.co/u/lzold_z)\
**Post date:** [July 17, 2022, 8:32am UTC](https://discuss.elastic.co/t/how-to-make-logstash-filter-multiple-grok-pattern/309810/1 "2022-07-17T08:32:01Z")

</div>

Hello, im new to the logstash and i want to know how to make logstash filter multiple grok pattern for example from httpd error logs and access logs, im already have those pattern but logstash seem didnt catch the logs, here is the sample logstash configuration i have

```auto
input {
   beats {
    port => 5044
 }
}

filter {
  if "httpd_accesslog" in [fields][type] {
     mutate {
       remove_field => ["log","ecs","input","tags","fields","agent" ,"os"]
       update => {
        "event" => "%{[event][original]}"
        "host" => "%{[host][hostname]}"
        "fields" => "%{[fields][type]}"
        }
    }
    grok {
      break_on_match => false
      match => { "message" => "%{IPORHOST:clientip} %{HTTPDUSER:ident} %{USER:auth} \[%{HTTPDATE:timestamp}\] \"(?:%{WORD:verb} %{NOTSPACE:request}(?: HTTP/%{NUMBER:httpversion})?|%{DATA:rawrequest})\" %{NUMBER:response} (?:%{NUMBER:bytes}|-)" }
    }
  }
   else if "httpd_errorlog" in [fields][type] {
     mutate {
       remove_field => ["log","ecs","input","tags","fields","agent" ,"os"]
       update => {
        "event" => "%{[event][original]}"
        "host" => "%{[host][hostname]}"
        "fields" => "%{[fields][type]}"
        }
    }
    grok {
      break_on_match => false
      match => { "message" => "%{HTTPD20_ERRORLOG}|%{HTTPD24_ERRORLOG}" }
    }
  }
}

output {

    if "httpd_accesslog" in [fields] {
        solr_http {
            solr_url => "http://ip address:8983/solr/access-logs"
        }
    }
    else if "httpd_errorlog" in [fields] {
        solr_http {
            solr_url => "http://ip address:8983/solr/error-logs"
        }
    }
}

```

and here is my filebeat.yml file

```auto
filebeat.inputs:

- type: log
  enabled: true
  paths:
    - /var/log/httpd/access_log
  fields:
    type: httpd_accesslog

- type: log
  enabled: true
  paths:
    - /var/log/httpd/error_log
  fields:
    type: httpd_errorlog
  multiline.type: pattern
  multiline.pattern: '^\['
  multiline.negate: true
  multiline.match: after
  multiline.max.lines: 30

# ------------------------------ Logstash Output -------------------------------
output.logstash:
  # The Logstash hosts
  hosts: ["ipaddress:5044"]

```

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [July 18, 2022, 2:56am UTC](https://discuss.elastic.co/t/how-to-make-logstash-filter-multiple-grok-pattern/309810/2 "2022-07-18T02:56:46Z")

</div>

In the filter section you have `if "httpd_accesslog" in [fields][type] {`, which is testing whether that string occurs with that field (a substring match). That will probably work, but I would suggest an equality test, which I think is clearer

```
if [fields][type] == "httpd_accesslog"

```

In the output section you have `if "httpd_accesslog" in [fields] {`, which I do not think will ever work because [fields] is an object, not a string. Use the same test I suggested for the filter section.

---

<div class="post-metadata">

**Author:** ![lzold\_z](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/lzold_z/32/108411_2.png) [@lzold\_z](https://discuss.elastic.co/u/lzold_z)\
**Post date:** [July 19, 2022, 9:17am UTC](https://discuss.elastic.co/t/how-to-make-logstash-filter-multiple-grok-pattern/309810/4 "2022-07-19T09:17:56Z")

</div>

Thank you so much @Badger it's works

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 16, 2022, 9:18am UTC](https://discuss.elastic.co/t/how-to-make-logstash-filter-multiple-grok-pattern/309810/5 "2022-08-16T09:18:22Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
