# \[Ingest pipeline\] tag and trace match

**URL:** <https://discuss.elastic.co/t/ingest-pipeline-tag-and-trace-match/298745>\
**Category:** Elasticsearch\
**Tags:** ingest-pipeline\
**Created:** [March 3, 2022, 12:59pm UTC](https://discuss.elastic.co/t/ingest-pipeline-tag-and-trace-match/298745 "2022-03-03T12:59:22Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![marrc.rousseau](https://avatars.discourse-cdn.com/v4/letter/m/2acd7d/32.png) [@marrc.rousseau](https://discuss.elastic.co/u/marrc.rousseau)\
**Post date:** [March 3, 2022, 12:59pm UTC](https://discuss.elastic.co/t/ingest-pipeline-tag-and-trace-match/298745/1 "2022-03-03T12:59:22Z")

</div>

Hi,

I try to migrate my logstash filters to ingest pipeline but I'm stuck on an issue:  
I'm parsing VMware ESX logs with a grok pattern and I would like to add a field if grok pattern match

In logstash I've something like

```auto
   grok {
        match => [
                 "message" , "%{DATA:event.security} %{DATA:event.provider} \[%{DATA:event.module}\] %{GREEDYDATA:event.reason}",
                 "message" , "%{GREEDYDATA:event.reason}"
                ]
        add_field => { "host.os.type" => "ESX"}
   }

```

I don't see how to do that with ingest pipeline.

My first try was to do a pipeline with

- grok processor :  
pattern=%{DATA:event.security} %{DATA:event.provider} [%{DATA:event.module}] %{GREEDYDATA:event.reason}  
pattern=%{GREEDYDATA:event.reason}  
tag=grok1
- set processor:  
if ctx.tag == grok1  
set host.os.type = ESX

But when I look in kibana for "tags" field it's empty, so "set processor" doesn't work

- is my logic good ? if not how to do this ? is that possible to run a processor only if previous one succeed ?
- is that normal that tag field is not filled by my grok processor ?

Other thing : when I use "trace match" option in grok processor and "\_simultate" I'm able to see \_ingest metadata to debug. These \_ingest metadata are only visible in "simulate" mode ? I'm not able to see \_ingest metadata in kibana/discover when I look at documents

Thanks for your help

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 31, 2022, 1:00pm UTC](https://discuss.elastic.co/t/ingest-pipeline-tag-and-trace-match/298745/2 "2022-03-31T13:00:04Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
