# Logstash filter not wroking

**URL:** <https://discuss.elastic.co/t/logstash-filter-not-wroking/100470>\
**Category:** Logstash\
**Created:** [September 14, 2017, 7:12am UTC](https://discuss.elastic.co/t/logstash-filter-not-wroking/100470 "2017-09-14T07:12:47Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![pope843](https://avatars.discourse-cdn.com/v4/letter/p/f4b2a3/32.png) [@pope843](https://discuss.elastic.co/u/pope843)\
**Post date:** [September 14, 2017, 7:12am UTC](https://discuss.elastic.co/t/logstash-filter-not-wroking/100470/1 "2017-09-14T07:12:47Z")

</div>

Hello

I'm new with logstash and i'm having problems in filter condition, i would like to ship onlt llogs/lines with ERROR, DEBUG, INFO and WARN message.

Here's the working config only one string on if condition.

```
filter {
  if [type] == "syslog" {
    grok {
      match => { "message" => "%{SYSLOGTIMESTAMP:syslog_timestamp} %{SYSLOGHOST:syslog_hostname} %{DATA:syslog_program}(?:\[%{POSINT:syslog_pid}\])?: %{GREEDYDATA:syslog_message}" }
      add_field => ["received_at", "%{@timestamp}"]
      add_field => ["received_from", "%{host}"]
    }
    syslog_pri { }
    date {
      match => ["syslog_timestamp", "MMM d HH:mm:ss", "MMM dd HH:mm:ss"]
    }
}
 if "DEBUG" not in [message] {

```

}  
else {  
drop { }  
}  
}

not working A:

```
 if "DEBUG" not in [message] {

```

}  
else if "WARN" not in [message] {  
}  
else if "INFO" not in [message] {  
}  
else if "ERROR" not in [message] {  
}  
else {  
drop { }  
}  
}

not working B:

if "DEBUG" not in [message] or "WARN" not in [message] or "INFO" not in [message] or "ERROR" not in [message] {

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [September 14, 2017, 7:25am UTC](https://discuss.elastic.co/t/logstash-filter-not-wroking/100470/2 "2017-09-14T07:25:09Z")

</div>

In example B you need to use the `and` operator, not `or`. Otherwise you'll drop all messages except those containing DEBUG, WARN, INFO and ERROR _at the same time_.

---

<div class="post-metadata">

**Author:** ![pope843](https://avatars.discourse-cdn.com/v4/letter/p/f4b2a3/32.png) [@pope843](https://discuss.elastic.co/u/pope843)\
**Post date:** [September 14, 2017, 7:44am UTC](https://discuss.elastic.co/t/logstash-filter-not-wroking/100470/3 "2017-09-14T07:44:01Z")

</div>

hello, thanks for the prompt response, my goal is to drop all the messages without DEBUG, WARN, INFO and ERROR.

---

<div class="post-metadata">

**Author:** ![pope843](https://avatars.discourse-cdn.com/v4/letter/p/f4b2a3/32.png) [@pope843](https://discuss.elastic.co/u/pope843)\
**Post date:** [September 14, 2017, 7:47am UTC](https://discuss.elastic.co/t/logstash-filter-not-wroking/100470/4 "2017-09-14T07:47:24Z")

</div>

example message withour DEBUG, INGO, ERROR, WARN

{  
"\_index": "maprouter-2017.09.14",  
"\_type": "log",  
"\_id": "AV5\_TmTHj1PRrJFkBAHk",  
"\_version": 1,  
"\_score": 1,  
"\_source": {  
"message": "00: 01 00 03 03 00 00 00 08 -- -- -- -- -- -- -- -- | ........ ",  
"@version": "1",  
"@timestamp": "2017-09-14T07:33:14.194Z",  
"type": "log",  
"input\_type": "log",  
"count": 1,  
"beat": {  
"hostname": "ip-10-3-101-15",  
"name": "ip-10-3-101-15"  
},  
"source": "/opt/esc/logs/cmaprouter101.log",  
"offset": 1592332,  
"fields": null,  
"host": "ip-10-3-101-15",  
"tags": [  
"beats\_input\_codec\_plain\_applied"  
]  
},  
"fields": {  
"@timestamp": [  
1505374394194  
]  
}  
}

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [September 14, 2017, 8:40am UTC](https://discuss.elastic.co/t/logstash-filter-not-wroking/100470/5 "2017-09-14T08:40:16Z")

</div>

> my goal is to drop all the messages without DEBUG, WARN, INFO and ERROR.

Yes, I know.

> example message withour DEBUG, INGO, ERROR, WARN

For that example message your option B works:

```plaintext
$ cat test.config 
input { stdin { } }
output { stdout { codec => rubydebug } }
filter {
  if "DEBUG" not in [message] or "WARN" not in [message] or "INFO" not in [message] or "ERROR" not in [message] {
    drop { }
  }
}
$ echo '00: 01 00 03 03 00 00 00 08 -- -- -- -- -- -- -- -- | ........' | /opt/logstash/bin/logstash -f test.config
Settings: Default pipeline workers: 8
Pipeline main started
Pipeline main has been shutdown
stopping pipeline {:id=>"main"}

```

(Logstash isn't emitting any events, proving that the drop filter worked.)

However, for other kinds of messages you do need to follow the advice I gave earlier.

---

<div class="post-metadata">

**Author:** ![pope843](https://avatars.discourse-cdn.com/v4/letter/p/f4b2a3/32.png) [@pope843](https://discuss.elastic.co/u/pope843)\
**Post date:** [September 14, 2017, 9:08am UTC](https://discuss.elastic.co/t/logstash-filter-not-wroking/100470/6 "2017-09-14T09:08:53Z")

</div>

> [@magnusbaeck](#):
>
> echo '00: 01 00 03 03 00 00 00 08 -- -- -- -- -- -- -- -- | ........' | /opt/logstash/bin/logstash -f test.config

I've tried to use and operator, and it works on my testing. But on the actual setup i Dont see any data on my ES/Kibana :(.

$ echo '00: 01 00 03 03 00 00 00 08 -- -- -- -- -- -- -- -- | ........' | /opt/logstash/bin/logstash -f test.config  
Settings: Default pipeline workers: 1  
Logstash startup completed  
Logstash shutdown completed

$ echo ' DEBUG o.m.protocols.sctp.AssociationImpl - Rx : Ass=SAP\_cmap101 PayloadData [dataLength=8, complete=true, unordered=true, payloadProtocolId=3, streamNumber=0, data=' | /opt/logstash/bin/logstash -f test.config

Settings: Default pipeline workers: 1  
Logstash startup completed  
{  
"message" =\> " DEBUG o.m.protocols.sctp.AssociationImpl - Rx : Ass=SAP\_cmap101 PayloadData [dataLength=8, complete=true, unordered=true, payloadProtocolId=3, streamNumber=0, data=",  
"@version" =\> "1",  
"@timestamp" =\> "2017-09-14T09:05:51.249Z",  
"host" =\> "ip-10-3-2-105"  
}  
Logstash shutdown completed

---

<div class="post-metadata">

**Author:** ![pope843](https://avatars.discourse-cdn.com/v4/letter/p/f4b2a3/32.png) [@pope843](https://discuss.elastic.co/u/pope843)\
**Post date:** [September 14, 2017, 9:20am UTC](https://discuss.elastic.co/t/logstash-filter-not-wroking/100470/7 "2017-09-14T09:20:19Z")

</div>

it's now working!!!! thank you so much,

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 12, 2017, 9:20am UTC](https://discuss.elastic.co/t/logstash-filter-not-wroking/100470/8 "2017-10-12T09:20:22Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
