# Logstash debugger tool shows matched for filter but new fields don't appear on Kibana

**URL:** https://discuss.elastic.co/t/logstash-debugger-tool-shows-matched-for-filter-but-new-fields-dont-appear-on-kibana/110426
**Category:** Logstash
**Created:** [December 5, 2017, 9:56pm UTC](https://discuss.elastic.co/t/logstash-debugger-tool-shows-matched-for-filter-but-new-fields-dont-appear-on-kibana/110426 "2017-12-05T21:56:19Z")
**Posts on this page:** 4
**Page:** 1

<div class="post-metadata">

### Author: ![Yuri\_Sibirski](https://avatars.discourse-cdn.com/v4/letter/y/4491bb/32.png) [@Yuri\_Sibirski](https://discuss.elastic.co/u/Yuri_Sibirski)
#### Post date: [December 5, 2017, 9:56pm UTC](https://discuss.elastic.co/t/logstash-debugger-tool-shows-matched-for-filter-but-new-fields-dont-appear-on-kibana/110426/1 "2017-12-05T21:56:20Z")

</div>

I am having an issue with my logstash and grok filters. When i use logstash debugger tool and pasting log entry and filter to test the parser it checks out OK and gives me an expected output with extra fields that i am looking for. However, when i add this new filter to logstash it starts OK without complaining about configuration but then i don't see my new fields in Kibana that i am looking for. Could you please help me to find out that's wrong? Here is my config files:

**1) 10-filters.conf file under /etc/logstash/conf.d/**

```
  filter {
      if [type] == "syslog" {
        grok {
          match => { "message" => "%{SYSLOGTIMESTAMP:syslog_timestamp} %{SYSLOGHOST:syslog_hostname} %{DATA:syslog_program}(?:\[%{POSINT:syslog_pid}\])?: %{GREEDYDATA:syslog_message}" }
          add_field => ["received_at", "%{@timestamp}"]
          add_field => ["received_from", "%{host}"]
        }
        syslog_pri { }
        date {
          match => ["syslog_timestamp", "MMM d HH:mm:ss", "MMM dd HH:mm:ss"]
        }
      }

  if [type] == "uwsgi_api" {
    grok {
      match => { "message" => "^%{SYSLOGTIMESTAMP:date} \[pid: %{INT:pid}\]: %{LOGLEVEL:loglevel}:%{GREEDYDATA:filepath}:Call( by user %{QUOTEDSTRING:username})? (raised %{WORD:abort}|completed without aborting)" }
      add_field => { "type" => "user_info" }
    }
    grok {
      patterns_dir => ["/etc/logstash/patterns"]
      match => { "message" => "\[.*\] %{IP:ipaddress} \(\) {.*} \[%{DATESTAMP_FLASK:timestamp}\] %{WORD:method} %{URIPATHPARAM:fullpath} => generated %{INT:bytes} bytes in %{INT:ms} msecs \(HTTP/1.1 %{INT:return_code}" }
      add_field => { "type" => "flask_info" }
    }
  }
}  

```

1. on the client side i am able to see that it has the right document\_type=type assigned to each of the entry that is being sent to ELK server.  
**/usr/share/filebeat/bin/filebeat -c /etc/filbeat/filebeat.yam -e -d "\*:**

I am really confused why it doesn't work. I also have my patterns file that i am using for the second grok filter:

```
MONTHDAY_FLASK (?:(?:[0][1-9])|(?:[12][0-9])|(?:3[01])|[1-9])
DATESTAMP_FLASK %{DAY} %{MONTH} %{MONTHDAY_FLASK} %{HOUR}:%{MINUTE}:%{SECOND} %{YEAR}
```

---

<div class="post-metadata">

### Author: ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)
#### Post date: [December 8, 2017, 6:21am UTC](https://discuss.elastic.co/t/logstash-debugger-tool-shows-matched-for-filter-but-new-fields-dont-appear-on-kibana/110426/2 "2017-12-08T06:21:23Z")

</div>

What do the events Logstash produce look like? Use a `stdout { codec => rubydebug }` output.

---

<div class="post-metadata">

### Author: ![Yuri\_Sibirski](https://avatars.discourse-cdn.com/v4/letter/y/4491bb/32.png) [@Yuri\_Sibirski](https://discuss.elastic.co/u/Yuri_Sibirski)
#### Post date: [December 21, 2017, 2:33pm UTC](https://discuss.elastic.co/t/logstash-debugger-tool-shows-matched-for-filter-but-new-fields-dont-appear-on-kibana/110426/3 "2017-12-21T14:33:07Z")

</div>

Magnus thank you for your response i figured it out. The problem was in the 2nd and the 3rd filters itself. They were overriding **type** attribute that was set to **uwsgi\_api** that's why it was never applied. I just delete line **add\_filed (type....)** and it worked. However i am seeing a diff issue now: logstash is trying to publish events to closed indexes and becomes stale after some time since events can't be published. I think i will open a new topic for it. Thank you again for response.

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [January 18, 2018, 2:33pm UTC](https://discuss.elastic.co/t/logstash-debugger-tool-shows-matched-for-filter-but-new-fields-dont-appear-on-kibana/110426/4 "2018-01-18T14:33:23Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
