# Ignore a specific or drop a field when using another Grok Pattern

**URL:** <https://discuss.elastic.co/t/ignore-a-specific-or-drop-a-field-when-using-another-grok-pattern/270522>\
**Category:** Logstash\
**Created:** [April 19, 2021, 1:55am UTC](https://discuss.elastic.co/t/ignore-a-specific-or-drop-a-field-when-using-another-grok-pattern/270522 "2021-04-19T01:55:26Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Wilks](https://avatars.discourse-cdn.com/v4/letter/w/f475e1/32.png) [@Wilks](https://discuss.elastic.co/u/Wilks)\
**Post date:** [April 19, 2021, 1:55am UTC](https://discuss.elastic.co/t/ignore-a-specific-or-drop-a-field-when-using-another-grok-pattern/270522/1 "2021-04-19T01:55:26Z")

</div>

HI,  
I have a filter that works except for when the log doesn't contains different data for a field that I am using an extra grok pattern on. I am extracting the username from DN (Distinguished Name) from the main log and it works. The problem is one of the longs comes in wonky and it assigns Session ID to the DN. So for example the below works with my filter.

message":"03-MAR-21 00:48:52|172.24.112.78|5|CN=amacctotsspulse,OU=Test Users,OU=Test,OU=Business Units,DC=Test,DC=corp,DC=Test,DC=ca|1aIek2sJlgoYgP+4oP+Sul32AG0=|Test App

```auto
filter
{
grok {
         match => { "message" => ["%{GREEDYDATA:timestamp}\|(%{IPV4:src.ip})?\|%{WORD:event.id}\|(%{GREEDYDATA:dn})?\|(%{NOTSPACE:session_id})?\|(%{GREEDYDATA:application_name})?"] }

         }
         
grok
       {
        match => { "dn" => ["(\w+\=%{NOTSPACE:user.name}\,)?"] }
       remove_field => ["message","host"]
       }

date {
        match => ["timestamp", "dd-MMM-yy HH:mm:ss"]
        target => "@timestamp"
      }

```

The issue occurs when the below log appears.  
message="03-MAR-21 22:08:23||10|session ID=vqZpWuFj95CepNVGgYfUu5acKng=|vqZpWuFj95CepNVGgYfUu5acKng=|"

I Need to somehow make it so that if the DN grok pattern in the extra grok pattern drops or doesn't try and match when it sees |session ID=" because right now it assigns session ID to the DN field. as per below

"dn": "session ID=vqZpWuFj95CepNVGgYfUu5acKng=",

is there some way to say that if match =\> { "dn" =\> ["(\w+=%{NOTSPACE:user.name},)?"] } contains "session ID'" drop just the DN for this or ignore this but continue to keep a valid DN? I don't want to drop the entire message, just the DN field

---

<div class="post-metadata">

**Author:** ![Wilks](https://avatars.discourse-cdn.com/v4/letter/w/f475e1/32.png) [@Wilks](https://discuss.elastic.co/u/Wilks)\
**Post date:** [April 19, 2021, 2:07am UTC](https://discuss.elastic.co/t/ignore-a-specific-or-drop-a-field-when-using-another-grok-pattern/270522/2 "2021-04-19T02:07:53Z")

</div>

so basically I want to remove this but only when "session ID=" shows up, keep it for valid DN  
 ![Screenshot 2021-04-18 220700](https://us1.discourse-cdn.com/elastic/original/3X/0/3/03d27cf6a98abfce82bd3d683df191aeeb1f37a0.png)

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [April 19, 2021, 3:32pm UTC](https://discuss.elastic.co/t/ignore-a-specific-or-drop-a-field-when-using-another-grok-pattern/270522/3 "2021-04-19T15:32:59Z")

</div>

How about

```
if [dn] =~ /^session ID=/ { mutate { remove_field => ["dn"] } }
```

---

<div class="post-metadata">

**Author:** ![Wilks](https://avatars.discourse-cdn.com/v4/letter/w/f475e1/32.png) [@Wilks](https://discuss.elastic.co/u/Wilks)\
**Post date:** [April 20, 2021, 1:35pm UTC](https://discuss.elastic.co/t/ignore-a-specific-or-drop-a-field-when-using-another-grok-pattern/270522/4 "2021-04-20T13:35:14Z")

</div>

Works!! Thanks

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 18, 2021, 1:36pm UTC](https://discuss.elastic.co/t/ignore-a-specific-or-drop-a-field-when-using-another-grok-pattern/270522/5 "2021-05-18T13:36:00Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
