# Logstash filter problem

**URL:** <https://discuss.elastic.co/t/logstash-filter-problem/124912>\
**Category:** Logstash\
**Created:** [March 21, 2018, 6:38am UTC](https://discuss.elastic.co/t/logstash-filter-problem/124912 "2018-03-21T06:38:44Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Mango](https://avatars.discourse-cdn.com/v4/letter/m/ed655f/32.png) [@Mango](https://discuss.elastic.co/u/Mango)\
**Post date:** [March 21, 2018, 6:38am UTC](https://discuss.elastic.co/t/logstash-filter-problem/124912/1 "2018-03-21T06:38:45Z")

</div>

I have one log file with two different format, And now, I want to match them together ,and I write logstash-filter in below way.

```auto
filter{
	if [type] == "test" {
		grok {
                	match => {"message" => "%{WORD:logger}\s+%{GREEDYDATA:information}"}
                	if [logger] == "api_playlist" {
                		grok {
                			match => {"information" => "%{GREEDYDATA:test1}"}
                		}
                	}

                	else if [logger] == "grpc_playlist" {
                		grok {
                			match => {"information" => "%{GREEDYDATA:test2}"}
                		}
                	}

		}
        		
	}
}

```

AND my log file is

```auto
api_playlist 2017-12-20 09:26:37 0f957a40 null amzn1.account.AGYYSC3H4MWTZXRZHT4SQWP67AHA Discover null undefined Done 0.346
2017-12-20 09:26:56 0ff2cdbf null amzn1.account.AEOIL2NUCQRJI23M7UH3BXS2QN5Q Discover null undefined Done 0.251
grpc_playlist 2017-12-20 09:26:37 0f957a40 null amzn1.account.AGYYSC3H4MWTZXRZHT4SQWP67AHA Discover null undefined Done 0.346
2017-12-20 09:26:56 0ff2cdbf null amzn1.account.AEOIL2NUCQRJI23M7UH3BXS2QN5Q Discover null undefined Done 0.251

```

But I failed,What's my problem or Anyway else can meet my require?  
THANKS!

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [March 21, 2018, 6:58am UTC](https://discuss.elastic.co/t/logstash-filter-problem/124912/2 "2018-03-21T06:58:01Z")

</div>

You can not have conditionals within a filter. You can however [specify a list of grok patterns](https://www.elastic.co/guide/en/logstash/current/plugins-filters-grok.html#plugins-filters-grok-match) in a grok filter. When you do this the default behaviour is that it tests the expressions one by one and stops processing as soon as a match is found.

---

<div class="post-metadata">

**Author:** ![Mango](https://avatars.discourse-cdn.com/v4/letter/m/ed655f/32.png) [@Mango](https://discuss.elastic.co/u/Mango)\
**Post date:** [March 22, 2018, 3:34am UTC](https://discuss.elastic.co/t/logstash-filter-problem/124912/3 "2018-03-22T03:34:33Z")

</div>

Thank you for your reply,That's WORK!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 19, 2018, 3:34am UTC](https://discuss.elastic.co/t/logstash-filter-problem/124912/4 "2018-04-19T03:34:37Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
