# If Else in logstash filter

**URL:** <https://discuss.elastic.co/t/if-else-in-logstash-filter/251019>\
**Category:** Logstash\
**Created:** [October 5, 2020, 3:35pm UTC](https://discuss.elastic.co/t/if-else-in-logstash-filter/251019 "2020-10-05T15:35:54Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![Rahul\_Ravichandran](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rahul_ravichandran/32/53882_2.png) [@Rahul\_Ravichandran](https://discuss.elastic.co/u/Rahul_Ravichandran)\
**Post date:** [October 5, 2020, 3:35pm UTC](https://discuss.elastic.co/t/if-else-in-logstash-filter/251019/1 "2020-10-05T15:35:54Z")

</div>

hey Guys,  
kindly help me to solve this

- There are two types of messages that i am trying to parse

- So this was my config before

```auto
input {
  file {
    path => "/home/ubuntu/*"
    start_position => "beginning"
  }
}
filter {

   grok {																									
    match => { "message" => "(?<jsonf>({.*}))"}
  }
  json {
            source => "jsonf"
  }
  mutate {
        remove_field => ["message","jsonf"]
      }
}

output {
  amazon_es {
    hosts => [" *****************************"]
    region => "us-east-1"
    index => "test-%{+YYYY.MM.dd}"
    #user => "elastic"
    #password => "changeme"
  }
}

```

- so this was working fine for the 1st message and for the second message it was throwing as\_grokparsefailure

- So the next thing i tried was by putting IF conditions

```auto
input {
	file {
		type => "testlogs"
		path => "/home/ubuntu/testlog.log"
		start_position => "beginning"
	}
}

filter {

	# strating if
	if [message] == "message" {
		
	
 
 	# filter
	grok {
			match => { "message" => "(?<jsonf>({.*}))"}
		}
    json {
            source => "jsonf"
        }
    mutate {
        remove_field => ["message","jsonf"]
      }
	
}
}

# output logs to console and to elasticsearch
output {
if [message] =~ "message" {
amazon_es {
    hosts => [" ******************************"]
    region => "us-east-1"
    index => "test-%{+YYYY.MM.dd}"

  }
    
}	
}

```

- when i use this i dint get any errors but when i tried to push the logs there was no index created
- i would request anyone to help me out with this , im totally not sure whether im using the conditions in right place .

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [October 5, 2020, 4:01pm UTC](https://discuss.elastic.co/t/if-else-in-logstash-filter/251019/2 "2020-10-05T16:01:08Z")

</div>

I would suggest that you use a json filter unconditionally, but tell it to delete the message field if it successfully parses it.

```
json { source => "message" remove_field => ["message"] }
```

---

<div class="post-metadata">

**Author:** ![Rahul\_Ravichandran](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rahul_ravichandran/32/53882_2.png) [@Rahul\_Ravichandran](https://discuss.elastic.co/u/Rahul_Ravichandran)\
**Post date:** [October 5, 2020, 4:30pm UTC](https://discuss.elastic.co/t/if-else-in-logstash-filter/251019/3 "2020-10-05T16:30:37Z")

</div>

@Badger so u mean i should put the grok in conditions and not the json right ?

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [October 5, 2020, 5:08pm UTC](https://discuss.elastic.co/t/if-else-in-logstash-filter/251019/4 "2020-10-05T17:08:22Z")

</div>

I see no reason to use a grok filter.

---

<div class="post-metadata">

**Author:** ![Rahul\_Ravichandran](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rahul_ravichandran/32/53882_2.png) [@Rahul\_Ravichandran](https://discuss.elastic.co/u/Rahul_Ravichandran)\
**Post date:** [October 6, 2020, 6:14am UTC](https://discuss.elastic.co/t/if-else-in-logstash-filter/251019/5 "2020-10-06T06:14:16Z")

</div>

i am trying to parse this message

```auto
{"Code":"BOSIIF902","Message":"Backup stopped. Error during the backup :: SOAP-ERROR: P","time":1583470627,"userId":" *****************","businessUserId":"************","cloudId":4,"domainId":"603","additionalInfo":null} [] []

```

- if i want that code, Message, USerID, BusinessID cloudID as a seperate feild i should use grok with json right ?

- so without using grok i will get the whole message in a single field.

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [October 6, 2020, 2:20pm UTC](https://discuss.elastic.co/t/if-else-in-logstash-filter/251019/6 "2020-10-06T14:20:40Z")

</div>

OK, I did not realize that there is additional text after the JSON. Try

```
filter {
    if [message] =~ /{.*}/
        grok { match => { "message" => "(?<[@metadata][json]({.*}))"} }
        json { source => "[@metadata][json]" remove_field => ["message"] }
    }
}

```

Fields under [@metadata] exist in logstash, but are not indexed into elasticsearch. The remove\_field only gets executed if the json filter successfully parses the message, so if there is a problem with the JSON you will be able to see what it is. For the plain text messages none of the filters will be applied and they will just be sent to the elasticsearch output.

---

<div class="post-metadata">

**Author:** ![Rahul\_Ravichandran](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rahul_ravichandran/32/53882_2.png) [@Rahul\_Ravichandran](https://discuss.elastic.co/u/Rahul_Ravichandran)\
**Post date:** [October 6, 2020, 2:53pm UTC](https://discuss.elastic.co/t/if-else-in-logstash-filter/251019/7 "2020-10-06T14:53:38Z")

</div>

Thanks a lot @Badger this solved my problem

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 3, 2020, 2:53pm UTC](https://discuss.elastic.co/t/if-else-in-logstash-filter/251019/8 "2020-11-03T14:53:40Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
