# Logstash grep and grok

**URL:** <https://discuss.elastic.co/t/logstash-grep-and-grok/252441>\
**Category:** Logstash\
**Created:** [October 18, 2020, 6:07am UTC](https://discuss.elastic.co/t/logstash-grep-and-grok/252441 "2020-10-18T06:07:58Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![tarunmendon](https://avatars.discourse-cdn.com/v4/letter/t/58956e/32.png) [@tarunmendon](https://discuss.elastic.co/u/tarunmendon)\
**Post date:** [October 18, 2020, 6:07am UTC](https://discuss.elastic.co/t/logstash-grep-and-grok/252441/1 "2020-10-18T06:07:59Z")

</div>

I am new to Elasticstack. I am trying to implement a logstash pipeline in which the a file would be processed and it would filter(grep) and output if the line of file contains following keyword -

1. java.lang.Exception - Any line of file containing Exception should be filtered and be available on Kibana
2. XYZ process completed.  
I tried following but it seems to outputting all the contents that do not match the Exception too.

```auto
input {
  beats {
    port => 5044
    tags => "exception"
  }
}
filter{
  if "exception" in [tags]{
    grok {
    match => { message => "Exception"
    }
  }
}
output {
  elasticsearch {
    hosts => ["http://localhost:9200"]
    index => "%{[@metadata][beat]}-%{[@metadata][version]}" 
  }
}

```

Please help and advise.

---

<div class="post-metadata">

**Author:** ![grumo35](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/grumo35/32/59451_2.png) [@grumo35](https://discuss.elastic.co/u/grumo35)\
**Post date:** [October 18, 2020, 9:42am UTC](https://discuss.elastic.co/t/logstash-grep-and-grok/252441/2 "2020-10-18T09:42:44Z")

</div>

Add the following condition in the output maybe ?

```auto
output {
 if "exception" in [tags] {
  elasticsearch {
    hosts => ["http://localhost:9200"]
    index => "%{[@metadata][beat]}-%{[@metadata][version]}" 
  }
}
}

```

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [October 18, 2020, 2:14pm UTC](https://discuss.elastic.co/t/logstash-grep-and-grok/252441/3 "2020-10-18T14:14:36Z")

</div>

You could try

```auto
filter{
}
output {
  if "Exception" in [message] or "XYZ process completed" in [message] {
    elasticsearch {
      hosts => ["http://localhost:9200"]
      index => "%{[@metadata][beat]}-%{[@metadata][version]}" 
    }
  }
}

```

---

<div class="post-metadata">

**Author:** ![tarunmendon](https://avatars.discourse-cdn.com/v4/letter/t/58956e/32.png) [@tarunmendon](https://discuss.elastic.co/u/tarunmendon)\
**Post date:** [October 18, 2020, 3:16pm UTC](https://discuss.elastic.co/t/logstash-grep-and-grok/252441/4 "2020-10-18T15:16:24Z")

</div>

Hello @Badger/@grumo35,  
Thanks for the reply. I added following in the pipeline.yml -

```auto
input {
  beats {
    port => 5044
    id=> "filebeat_plugin"
    tags => "exception"
  }
}
filter{
 }
output {
if "Exception" in [message] or "XYZ process completed" in [message]{
  elasticsearch {
    hosts => ["http://localhost:9200"]
    index => "%{[@metadata][beat]}-%{[@metadata][version]}" 
  }
  }
}

```

I added following in the log :  
java.lang.NumberFormatException  
XYZ process completed  
java.lang.OtherException

Kibana output didnot process the "XYZ process completed". PFA attachment. Any idea about it?

 ![Kibana_Filebeat](https://us1.discourse-cdn.com/elastic/original/3X/2/5/2565509057bef38023baa2fc2c33256ff1f7b33f.png)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 15, 2020, 3:16pm UTC](https://discuss.elastic.co/t/logstash-grep-and-grok/252441/5 "2020-11-15T15:16:35Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
