# Logstash - Handling different kinds of logs

**URL:** <https://discuss.elastic.co/t/logstash-handling-different-kinds-of-logs/11965>\
**Category:** Elasticsearch\
**Created:** [May 15, 2013, 4:02am UTC](https://discuss.elastic.co/t/logstash-handling-different-kinds-of-logs/11965 "2013-05-15T04:02:05Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![aakashanuj](https://avatars.discourse-cdn.com/v4/letter/a/c68b51/32.png) [@aakashanuj](https://discuss.elastic.co/u/aakashanuj)\
**Post date:** [May 15, 2013, 4:02am UTC](https://discuss.elastic.co/t/logstash-handling-different-kinds-of-logs/11965/1 "2013-05-15T04:02:05Z")

</div>

I am using Logstash to parse logs which have a keyword ERR in them.

I want to ship these logs to the elastic search, whereas I do not want to  
ship the logs which do not contain the word ERR.

So for that, I am using a regex pattern to parse the logs and send them to  
the elastic search. It is working fine with the logs that have the word  
ERR. But for the logs which dont have it, I get an error and the code gives  
an Exception.

I do not want the code to hang, rather I want to skip those logs which done  
have ERR.

How do I achieve this with Logstash/Grok?

Please help.

My conf file is:

input {  
stdin {  
type =\> "stdin-type"  
}  
}  
filter {

grok {  
type =\> "stdin-type"  
patterns\_dir=\>["./patterns"]  
pattern =\> "%{PARSE\_ERROR}"  
add\_tag=\>"%{type1},%{type2},%{slave},ERR\_SYSTEM"  
}  
date  
{  
replace=\>["%{ts}","yyyy/MM/dd-HH:mm:ss.SSS"]  
custom\_timestamp=\>[%{ts}]  
}

mutate  
{  
type=\>"stdin-type"  
replace =\> ["@message", "%{message}"]

}

}  
output {  
stdout { debug =\> true debug\_format =\> "json"}  
elasticsearch  
{  
}  
}

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
For more options, visit [https://groups.google.com/groups/opt\_out](https://groups.google.com/groups/opt_out).

---

<div class="post-metadata">

**Author:** ![Clinton\_Gormley](https://avatars.discourse-cdn.com/v4/letter/c/50afbb/32.png) [@Clinton\_Gormley](https://discuss.elastic.co/u/Clinton_Gormley)\
**Post date:** [May 15, 2013, 10:23am UTC](https://discuss.elastic.co/t/logstash-handling-different-kinds-of-logs/11965/2 "2013-05-15T10:23:49Z")

</div>

You'd be better off asking this on the logstash mailing list

clint

On 15 May 2013 06:02, Aakash Anuj [aakashanuj.iitkgp@gmail.com](mailto:aakashanuj.iitkgp@gmail.com) wrote:

> I am using Logstash to parse logs which have a keyword ERR in them.
> 
> I want to ship these logs to the Elasticsearch, whereas I do not want to  
> ship the logs which do not contain the word ERR.
> 
> So for that, I am using a regex pattern to parse the logs and send them to  
> the Elasticsearch. It is working fine with the logs that have the word  
> ERR. But for the logs which dont have it, I get an error and the code gives  
> an Exception.
> 
> I do not want the code to hang, rather I want to skip those logs which  
> done have ERR.
> 
> How do I achieve this with Logstash/Grok?
> 
> Please help.
> 
> My conf file is:
> 
> input {  
> stdin {  
> type =\> "stdin-type"  
> }  
> }  
> filter {
> 
> grok {  
> type =\> "stdin-type"  
> patterns\_dir=\>["./patterns"]  
> pattern =\> "%{PARSE\_ERROR}"  
> add\_tag=\>"%{type1},%{type2},%{\*\*slave},ERR\_SYSTEM"  
> }  
> date  
> {  
> replace=\>["%{ts}","yyyy/MM/dd-\*\*HH:mm:ss.SSS"]  
> custom\_timestamp=\>[%{ts}]  
> }
> 
> mutate  
> {  
> type=\>"stdin-type"  
> replace =\> ["@message", "%{message}"]
> 
> }
> 
> }  
> output {  
> stdout { debug =\> true debug\_format =\> "json"}  
> elasticsearch  
> {  
> }  
> }
> 
> --  
> You received this message because you are subscribed to the Google Groups  
> "elasticsearch" group.  
> To unsubscribe from this group and stop receiving emails from it, send an  
> email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
> For more options, visit [https://groups.google.com/groups/opt\_out](https://groups.google.com/groups/opt_out).

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
For more options, visit [https://groups.google.com/groups/opt\_out](https://groups.google.com/groups/opt_out).

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 2:36am UTC](https://discuss.elastic.co/t/logstash-handling-different-kinds-of-logs/11965/3 "2017-07-06T02:36:36Z")

</div>


