# Logstash If statement and grok not working

**URL:** <https://discuss.elastic.co/t/logstash-if-statement-and-grok-not-working/271717>\
**Category:** Logstash\
**Created:** [April 29, 2021, 8:51pm UTC](https://discuss.elastic.co/t/logstash-if-statement-and-grok-not-working/271717 "2021-04-29T20:51:49Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![ankitdevnalkar](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ankitdevnalkar/32/46158_2.png) [@ankitdevnalkar](https://discuss.elastic.co/u/ankitdevnalkar)\
**Post date:** [April 29, 2021, 8:51pm UTC](https://discuss.elastic.co/t/logstash-if-statement-and-grok-not-working/271717/1 "2021-04-29T20:51:49Z")

</div>

I am using following if statement, not sure what is wrong here, it is giving me `_mutate_error`.  
Does the `/` cause this error?

```
if [operationName] == "MICROSOFT.RESOURCES/SUBSCRIPTIONS/RESOURCEGROUPS/DELETE"
        {
            mutate {
                add_field => { "Signal" => "A resource group deletion operation has %{[resultSignature]} by the user %{[identity][claims]http://schemas.xmlsoap.org/ws/2005/05/identity/claims/emailaddress]}"}
		add_field => { "Priority" => "HIGH"}
                add_field => { "category" => "Resource"}
            }
        }

```

Also, getting `_grokparsefailure`in tag, grok filter is as follows :

```
if "RESOURCEGROUPS" in [resourceId]
{
                grok
                {
                match => {"[resourceId]" => ".*resourceGroups/%{USERNAME:resourceGroupName}.*"}
                }
                
}

```

Can anyone help ?

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [April 29, 2021, 9:25pm UTC](https://discuss.elastic.co/t/logstash-if-statement-and-grok-not-working/271717/2 "2021-04-29T21:25:59Z")

</div>

```
%{[identity][claims]http://schemas.xmlsoap.org/ws/2005/05/identity/claims/emailaddress]}

```

That is not a valid field reference.

What does the [resourceId] field look like?

grok patterns are not anchored, so the .\* at the start and end are not needed.

---

<div class="post-metadata">

**Author:** ![ankitdevnalkar](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ankitdevnalkar/32/46158_2.png) [@ankitdevnalkar](https://discuss.elastic.co/u/ankitdevnalkar)\
**Post date:** [April 30, 2021, 4:10am UTC](https://discuss.elastic.co/t/logstash-if-statement-and-grok-not-working/271717/3 "2021-04-30T04:10:52Z")

</div>

@Badger thanks for getting back.

`resourceId` data is as follows:  
/SUBSCRIPTIONS/AC015FE2-22FA-4D11-8E84-275FE7123A28/RESOURCEGROUPS/TEST

---

<div class="post-metadata">

**Author:** ![ankitdevnalkar](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ankitdevnalkar/32/46158_2.png) [@ankitdevnalkar](https://discuss.elastic.co/u/ankitdevnalkar)\
**Post date:** [April 30, 2021, 4:52am UTC](https://discuss.elastic.co/t/logstash-if-statement-and-grok-not-working/271717/4 "2021-04-30T04:52:30Z")

</div>

I got it !  
I was searching for `resourceGroups` in grok but it is in caps `RESOURCEGROUPS` I changed grok pattern to `.*RESOURCEGROUPS/%{USERNAME:resourceGroupName}.*` and now it is working.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 28, 2021, 4:53am UTC](https://discuss.elastic.co/t/logstash-if-statement-and-grok-not-working/271717/5 "2021-05-28T04:53:14Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
