# Logstash conditionals

**URL:** <https://discuss.elastic.co/t/logstash-conditionals/96139>\
**Category:** Logstash\
**Created:** [August 7, 2017, 4:51pm UTC](https://discuss.elastic.co/t/logstash-conditionals/96139 "2017-08-07T16:51:30Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![zozo6015](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/zozo6015/32/12117_2.png) [@zozo6015](https://discuss.elastic.co/u/zozo6015)\
**Post date:** [August 7, 2017, 4:51pm UTC](https://discuss.elastic.co/t/logstash-conditionals/96139/1 "2017-08-07T16:51:30Z")

</div>

Hello,

I am trying to parse auth.log into the elasticsearch and since different actions have different formats I cannot parse the whole log as one. I was thinking to check if there are certain words in the message part of the log and if there are to parse only those type of messages into multiple different fields. Is that possible? I would appreciate some examples.

Regards,

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [August 8, 2017, 5:32am UTC](https://discuss.elastic.co/t/logstash-conditionals/96139/2 "2017-08-08T05:32:01Z")

</div>

```nohighlight
if [message] =~ /pattern matching something in your message/ {
  grok {
    ...
  }
}

```

Note that a grok filter can list multiple expressions that are tried one by one in order. That might be more efficient and easier on the eyes than the example above, depending on what your logs look like and how you want to parse them.

---

<div class="post-metadata">

**Author:** ![zozo6015](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/zozo6015/32/12117_2.png) [@zozo6015](https://discuss.elastic.co/u/zozo6015)\
**Post date:** [August 8, 2017, 8:22am UTC](https://discuss.elastic.co/t/logstash-conditionals/96139/3 "2017-08-08T08:22:48Z")

</div>

Thanks for the information, for some logs which has the same number of fields I am using dissect. Is there. possible to list multiple expressions with dissect just like you have suggested for grok?

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [August 8, 2017, 8:52am UTC](https://discuss.elastic.co/t/logstash-conditionals/96139/4 "2017-08-08T08:52:44Z")

</div>

I don't think so, but I've never used dissect.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 5, 2017, 8:53am UTC](https://discuss.elastic.co/t/logstash-conditionals/96139/5 "2017-09-05T08:53:00Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
