# Logstash 1.5.0 alternative for filter grep

**URL:** <https://discuss.elastic.co/t/logstash-1-5-0-alternative-for-filter-grep/2677>\
**Category:** Logstash\
**Created:** [June 15, 2015, 8:52am UTC](https://discuss.elastic.co/t/logstash-1-5-0-alternative-for-filter-grep/2677 "2015-06-15T08:52:37Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![shartmann](https://avatars.discourse-cdn.com/v4/letter/s/3ab097/32.png) [@shartmann](https://discuss.elastic.co/u/shartmann)\
**Post date:** [June 15, 2015, 8:52am UTC](https://discuss.elastic.co/t/logstash-1-5-0-alternative-for-filter-grep/2677/1 "2015-06-15T08:52:37Z")

</div>

Hello,  
we used logstash 1.4.2 and will update to 1.5.0. In logstash 1.4.2 we used grep as filter. For logstash 1.5.0 filter grep is never available, I think. Is there any alternative for grep or how can we change our configuration?

Here our config-file:

input {  
file {  
path =\> "/var/log/glassfish/server.log"  
type =\> "exceptions"  
discover\_interval =\> 10  
}  
...  
}  
if [type] == "exceptions" {  
grok {  
break\_on\_match =\> false  
type =\> "exceptions"  
match =\> [  
"message", "(?m)[#|%{TIMESTAMP\_ISO8601:timestamp}|%{LOGLEVEL}|%{DATA:server\_version}|%{JAVACLASS:javaclass}|\_ThreadID=%{INT:threadId};\_ThreadName=%{USERNAME:threadName};|%{DATA:startException:}Exception:%{DATA:exceptionmessage}#]"  
}  
#########################

# alternative for this part, everything else work

```
grep {
      type => "exceptions"
      match => ["tags", "_grokparsefailure"] negate => true
}

```

#########################  
}  
...  
}  
output {  
if [type] == "exceptions" {  
elasticsearch {  
type =\> "exceptions"  
cluster =\> "cluster1234"  
index =\> "exceptions"  
}  
}  
...  
}

Thanks,  
Stefan

---

<div class="post-metadata">

**Author:** ![yuphing](https://avatars.discourse-cdn.com/v4/letter/y/7ea924/32.png) [@yuphing](https://discuss.elastic.co/u/yuphing)\
**Post date:** [June 18, 2015, 9:37am UTC](https://discuss.elastic.co/t/logstash-1-5-0-alternative-for-filter-grep/2677/2 "2015-06-18T09:37:11Z")

</div>

Maybe something like:

```
filter{
...
        if ([type] == "exceptions" and "_grokparsefailure" in [tags]) {
           mutate { negate => true }
        }
...
```

---

<div class="post-metadata">

**Author:** ![shartmann](https://avatars.discourse-cdn.com/v4/letter/s/3ab097/32.png) [@shartmann](https://discuss.elastic.co/u/shartmann)\
**Post date:** [June 19, 2015, 9:23am UTC](https://discuss.elastic.co/t/logstash-1-5-0-alternative-for-filter-grep/2677/3 "2015-06-19T09:23:33Z")

</div>

Hi yuphing,

thanks for your reply, this works.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 5:37am UTC](https://discuss.elastic.co/t/logstash-1-5-0-alternative-for-filter-grep/2677/4 "2017-07-06T05:37:05Z")

</div>


