# Issues with Logstash filter ignoring logical elements

**URL:** <https://discuss.elastic.co/t/issues-with-logstash-filter-ignoring-logical-elements/90159>\
**Category:** Logstash\
**Created:** [June 20, 2017, 8:41pm UTC](https://discuss.elastic.co/t/issues-with-logstash-filter-ignoring-logical-elements/90159 "2017-06-20T20:41:57Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![Problematiq](https://avatars.discourse-cdn.com/v4/letter/p/b38774/32.png) [@Problematiq](https://discuss.elastic.co/u/Problematiq)\
**Post date:** [June 20, 2017, 8:41pm UTC](https://discuss.elastic.co/t/issues-with-logstash-filter-ignoring-logical-elements/90159/1 "2017-06-20T20:41:57Z")

</div>

Here is a snip-it of my filter.

> filter {  
> if "ASA" in [tags] {  
> grok {  
> patterns\_dir =\> ["/etc/logstash/patterns"]  
> match =\> [  
> "message", "%{CISCOFW106023}",  
> "message", "%{CISCOFW313005}",  
> "message", "%{CISCOFW733100}"  
> ]  
> add\_field =\> ["received\_at", "%{@timestamp}"]  
> add\_field =\> ["received\_from", "%{host}"]  
> tag\_on\_failure =\> [Unknown\_event]  
> }  
> if [src\_ip] != "%{RFC1918}" {  
> geoip {  
> source =\> "src\_ip"  
> target =\> "geoip"  
> add\_tag =\> ["Cisco-src-geoip"]  
> add\_field =\> ["[geoip][location]", "%{[geoip][longitude]}" ]  
> add\_field =\> ["[geoip][location]", "%{[geoip][latitude]}" ]  
> }  
> mutate {  
> convert =\> ["[geoip][location]", "float"]  
> }  
> }  
> if [dst\_ip] != "%{RFC1918}" {  
> geoip {  
> source =\> "dst\_ip"  
> target =\> "geoip"  
> add\_tag =\> ["Cisco-dst-geoip"]  
> add\_field =\> ["[geoip][location]", "%{[geoip][longitude]}" ]  
> add\_field =\> ["[geoip][location]", "%{[geoip][latitude]}" ]  
> }  
> mutate {  
> convert =\> ["[geoip][location]", "float"]  
> }  
> }  
> if "\_geoip\_lookup\_failure" in [tags] {  
> mutate {  
> remove\_tag =\> ["\_geoip\_lookup\_failure"]  
> }  
> }  
> }  
> For some reason the second geoip does not work correctly. when the first fails to trigger, the second fails to trigger. When the first one triggers, the second one triggers. I've been trying to wrap my brain around why it is not working. I know I could force it to close out the first geoip by doing an elseif and some sort of null command, but I would rather fix it the right way.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 18, 2017, 8:42pm UTC](https://discuss.elastic.co/t/issues-with-logstash-filter-ignoring-logical-elements/90159/2 "2017-07-18T20:42:00Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
