# Logstash if-condition doesn't match

**URL:** <https://discuss.elastic.co/t/logstash-if-condition-doesnt-match/106892>\
**Category:** Logstash\
**Created:** [November 8, 2017, 3:14pm UTC](https://discuss.elastic.co/t/logstash-if-condition-doesnt-match/106892 "2017-11-08T15:14:07Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![Mugen](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mugen/32/16454_2.png) [@Mugen](https://discuss.elastic.co/u/Mugen)\
**Post date:** [November 8, 2017, 3:14pm UTC](https://discuss.elastic.co/t/logstash-if-condition-doesnt-match/106892/1 "2017-11-08T15:14:07Z")

</div>

I've setup a filter in my logstash configuration and it doesn't match everytime the field has the correct value.  
I am using Logstash 5.6.3 ,Elasticsearch 5.6.3 and Kibana 5.6.3

**Filter:**

> filter {  
> if [program] == "RT\_FLOW" {
> 
> grok {  
> patterns\_dir =\> ["/etc/logstash/patterns"]  
> match =\> { "message" =\> "%{RT\_FLOW}"}  
> tag\_on\_failure =\> [\_grokparsefailure]  
> }
> 
> mutate {  
> add\_tag =\> ["Junos\_parsed"]  
> }  
> }  
> }

**Message A (Doesn't get matched):**

> {  
> "\_index": "logstash-2017.11.08",  
> "\_type": "syslog",  
> "\_id": "AV-aYxJyCrJhlYCvXZZp",  
> "\_version": 1,  
> "\_score": null,  
> "\_source": {  
> "@timestamp": "2017-11-08T14:40:34.000Z",  
> "@version": "1",  
> "host": "194.94.58.1",  
> "program": "RT\_FLOW",  
> "message": "RT\_FLOW\_SESSION\_CLOSE: session closed idle Timeout: XXX.XXX.XXX.XXX/49153-\>XXX.XXX.XXX.XXX/53 junos-dns-udp XXX.XXX.XXX.XXX/49153-\>XXX.XXX.XXX.XXX/53 None None 17 jh-allow-all XXX XXX 14663 2(114) 2(262) 4 UNKNOWN UNKNOWN N/A(N/A) fe-0/0/1.0 UNKNOWN",  
> "type": "syslog",  
> "logsource": "XXX"  
> },  
> "fields": {  
> "@timestamp": [  
> 1510152034000  
> ]  
> },  
> "sort": [  
> 1510152034000  
> ]  
> }

**Message B (Gets parsed):**

> {  
> "\_index": "firewall-2017.11",  
> "\_type": "accounting\_log",  
> "\_id": "AV-cIFbtZ4vZR059cUPw",  
> "\_version": 1,  
> "\_score": null,  
> "\_source": {  
> "src-ip": "XXX.XXX.XXX.XXX",  
> "dst-ip": "XXX.XXX.XXX.XXX",  
> "src-port": "1403",  
> "dst-port": "17600",  
> "program": "RT\_FLOW",  
> "type": "syslog",  
> "to-zone": "junos-host",  
> "policy-name": "ssh-host",  
> "@version": "1",  
> "host": "XXX.XXX.XXX.XXX",  
> "elapsed-time": "4",  
> "event": "RT\_FLOW\_SESSION\_CLOSE",  
> "close-reason": "session closed response received",  
> "nat-src-port": "1403",  
> "received": "0",  
> "message": "RT\_FLOW\_SESSION\_CLOSE: session closed response received: XXX.XXX.XXX.XXX/1403-\>XXX.XXX.XXX.XXX/17600 icmp XXX.XXX.XXX.XXX/1403-\>XXX.XXX.XXX.XXX/17600 None None 1 ssh-host untrust junos-host 5808 1(84) 0(0) 4 UNKNOWN UNKNOWN N/A(N/A) fe-0/0/0.0 UNKNOWN",  
> "logsource": "XXXX",  
> "src-nat-rule-name": "None",  
> "sent": "84",  
> "tags": [  
> "Junos\_parsed"  
> ],  
> "nat-src-ip": "XXX.XXX.XXX.XXX",  
> "@timestamp": "2017-11-08T14:54:51.000Z",  
> "dst-nat-rule-name": "None",  
> "port": 39364,  
> "service": "icmp",  
> "nat-dst-ip": "XXX.XXX.XXX.XXX",  
> "protocol-id": "1",  
> "nat-dst-port": "17600",  
> "from-zone": "untrust",  
> "session-id": "5808"  
> },  
> "fields": {  
> "@timestamp": [  
> 1510152891000  
> ]  
> },  
> "sort": [  
> 1510152891000  
> ]  
> }

On another note: My Documents seem to be hanging behind about 10 min .  
The "missing" 10 minutes get filled as the time progresses

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/8/e/8e1497625b1e2edcb3cffe56b5e0678d6cc54aba.png)

**Monitoring of my Logstash :**

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/d/e/ded237b74286d3d4f1a0fab26f405a34e0681c5b.png)

Thanks in advance 🙂

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 6, 2017, 3:14pm UTC](https://discuss.elastic.co/t/logstash-if-condition-doesnt-match/106892/2 "2017-12-06T15:14:10Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
