# Logstash config works but unable to see logs in Kibana

**URL:** <https://discuss.elastic.co/t/logstash-config-works-but-unable-to-see-logs-in-kibana/190374>\
**Category:** Logstash\
**Created:** [July 14, 2019, 7:44am UTC](https://discuss.elastic.co/t/logstash-config-works-but-unable-to-see-logs-in-kibana/190374 "2019-07-14T07:44:50Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Mohammad\_hossein\_Taj](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mohammad_hossein_taj/32/44550_2.png) [@Mohammad\_hossein\_Taj](https://discuss.elastic.co/u/Mohammad_hossein_Taj)\
**Post date:** [July 14, 2019, 7:44am UTC](https://discuss.elastic.co/t/logstash-config-works-but-unable-to-see-logs-in-kibana/190374/1 "2019-07-14T07:44:51Z")

</div>

Hi. I'm trying to read two types of log files that one of them has different logs that one of them is in this type:  
`2019-06-26 01:00:31,069 INFO ir.ac.ut.sdrwebservice.SDRWebService @ batchAddStdDoc, System:G, User:25117, StudentIDs:[450188215], GroupID:4501, DocType:1349, returned 1561494631012101`  
and it is parsing correctly and I can see the related logs in discover part of Kibana.  
but my problem is with the second file that just has logs in this type:  
`OQUEUE, Wed Jun 26 01:00:34 +0430 2019, 1561494631012101`  
I wrote a grok filter for it and it's tested with grok debugger but the related logs are not visible in discover part of Kibana.  
here is my grok config filter:

```auto
  if([message] =~ /QUEUE,/){
    grok {
      match => {"message" => "%{NOTSPACE:queueType}, (?<nothing>.{4})(?<part1>.{15})(?<nothing2>.{6}) %{NUMBER:part2}, %{NOTSPACE:returnedCode}"}
    }
    mutate {
      add_field => {
        "timestamp1" => "%{part1} %{part2}"
      }
      remove_field => ["part1", "part2", "nothing", "nothing2"]
    }
    date {
      match => ["timestamp1", "MMM dd HH:mm:ss YYYY"]
    }
  }
  if ([message] !~ /batchAddStdDoc/) {
    drop { }
  }
  if ([message] !~ /returned/) {
    drop { }
  }
  grok {
    match => { "message" => "%{TIMESTAMP_ISO8601:timestamp}%{SPACE}%{LOGLEVEL:loglevel} %{NOTSPACE:webService} @ %{NOTSPACE:function}, System:(?<systemName>.), User:%{NOTSPACE:userId}, StudentIDs:\[%{NUMBER:studentId}\], GroupID:%{GREEDYDATA:groupId}, DocType:%{NOTSPACE:docType}, returned %{INT:returnedCode}" }
  }
  date {
    match => ["timestamp", "YYYY-MM-dd HH:mm:ss,SSS"]
  }
}

```

thanks for your help.

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [July 14, 2019, 11:36am UTC](https://discuss.elastic.co/t/logstash-config-works-but-unable-to-see-logs-in-kibana/190374/2 "2019-07-14T11:36:34Z")

</div>

The message does not match either of the if conditions, so it will go through the

```
drop {}
```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 11, 2019, 11:36am UTC](https://discuss.elastic.co/t/logstash-config-works-but-unable-to-see-logs-in-kibana/190374/3 "2019-08-11T11:36:34Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
