# Logstash grok is failing to parse greedydata inside conditional statement

**URL:** <https://discuss.elastic.co/t/logstash-grok-is-failing-to-parse-greedydata-inside-conditional-statement/130570>\
**Category:** Logstash\
**Created:** [May 4, 2018, 6:46am UTC](https://discuss.elastic.co/t/logstash-grok-is-failing-to-parse-greedydata-inside-conditional-statement/130570 "2018-05-04T06:46:11Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Sriram\_Kannan](https://avatars.discourse-cdn.com/v4/letter/s/94ad74/32.png) [@Sriram\_Kannan](https://discuss.elastic.co/u/Sriram_Kannan)\
**Post date:** [May 4, 2018, 6:46am UTC](https://discuss.elastic.co/t/logstash-grok-is-failing-to-parse-greedydata-inside-conditional-statement/130570/1 "2018-05-04T06:46:11Z")

</div>

## I am having a logs pattern as below

## 2018-05-04 06:30:00.010 [http-nio-6080-exec-6] INFO .Controller - Processing request 16329d7d247 from 10.209.15.10: /uri/64511/5800/ 2018-05-04 06:30:00.007 [http-nio-6080-exec-7] INFO .Controller - Finished processing request 16329d7d247: status 200, body [1010], took 0ms

## and i waned to grok the date differently depending on keyword in log as -Processing/ -Finished. Below is my grok filter.

```
grok {
  match => { "message" => "%{TIMESTAMP_ISO8601:timestamp} %{SYSLOG5424SD} %{LOGLEVEL:loglevel} %{JAVACLASS} - %{WORD:processing} %{GREEDYDATA:log_message}" }
}
if [processing] == "Processing" 
{
   grok {
      match => ["log_message","request (?<requestID>[0-9a-z]) from %{IP:clientIP}/: %{URIPATHPARAM: uri}"]
   }
}
else
{
   grok{
      match => ["log_message", "processing request (?<requestID>[0-9a-z])\: status %{WORD:response}, body \[%{WORD:response_size}\]"]
   }
}	

```

* * *

When running logstash with this config I am able to see the indexes getting created for the 1st grok(outside the if statement) but the indexes inside the if statement are not getting created.

Can someone please help whether i am doing anything wrong.

Thanks  
Sriram

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [May 4, 2018, 7:00am UTC](https://discuss.elastic.co/t/logstash-grok-is-failing-to-parse-greedydata-inside-conditional-statement/130570/2 "2018-05-04T07:00:46Z")

</div>

> [@Sriram\_Kannan](#):
>
> from %{IP:clientIP}/:

Should the forward slash be there?

> [@Sriram\_Kannan](#):
>
> (?\<requestID\>[0-9a-z]):

Should there be a backslash before the colon here?

---

<div class="post-metadata">

**Author:** ![Sriram\_Kannan](https://avatars.discourse-cdn.com/v4/letter/s/94ad74/32.png) [@Sriram\_Kannan](https://discuss.elastic.co/u/Sriram_Kannan)\
**Post date:** [May 4, 2018, 7:40am UTC](https://discuss.elastic.co/t/logstash-grok-is-failing-to-parse-greedydata-inside-conditional-statement/130570/3 "2018-05-04T07:40:16Z")

</div>

Hi Christian,

Thanks for pointing out I tried altering to %{IP:clientIP}: and for (?[0-9a-z]):

still no success, the grokking inside the if loop didnt happen

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [May 4, 2018, 7:44pm UTC](https://discuss.elastic.co/t/logstash-grok-is-failing-to-parse-greedydata-inside-conditional-statement/130570/4 "2018-05-04T19:44:56Z")

</div>

Please show an example event produced by Logstash. Use a `stdout { codec => rubydebug }` output.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 1, 2018, 7:44pm UTC](https://discuss.elastic.co/t/logstash-grok-is-failing-to-parse-greedydata-inside-conditional-statement/130570/5 "2018-06-01T19:44:59Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
