# Logstash if statement for program

**URL:** <https://discuss.elastic.co/t/logstash-if-statement-for-program/234020>\
**Category:** Logstash\
**Created:** [May 23, 2020, 10:22pm UTC](https://discuss.elastic.co/t/logstash-if-statement-for-program/234020 "2020-05-23T22:22:20Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![Rasoul\_Ahmadi](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rasoul_ahmadi/32/68520_2.png) [@Rasoul\_Ahmadi](https://discuss.elastic.co/u/Rasoul_Ahmadi)\
**Post date:** [May 23, 2020, 10:22pm UTC](https://discuss.elastic.co/t/logstash-if-statement-for-program/234020/1 "2020-05-23T22:22:21Z")

</div>

hi  
i know its elementary but i am stuck at an if statement

with if statement I get grok failure  
and without it every thing is fine  
I'm using logstash 7.7

````
indent preformatted text by 4 spaces
```
input {stdin{}}
filter {
    if [program] == "sshd" {
        grok {
            patterns_dir => "${LL_PATTERN_DIR:/etc/logstash/patterns.d}"
            match => { "message" => "%{SSH_AUTHFAIL_WRONGCREDS}" }
            add_field => { "ssh_authresult" => "fail" "ssh_failreason" => 
"wrong_credentials" }
            add_tag => ["_grok_sshd_success", "matched"]
        }
        grok {
            patterns_dir => "${LL_PATTERN_DIR:/etc/logstash/patterns.d}"
            match => { "message" => "%{SSH_AUTHFAIL_WRONGUSER}" }
            add_field => { "ssh_authresult" => "fail" "ssh_failreason" => 
"unknown_user" }
            add_tag => ["_grok_sshd_success", "matched"]
        }
        grok {
            patterns_dir => "${LL_PATTERN_DIR:/etc/logstash/patterns.d}"
            match => { "message" => "%{SSH_AUTH_SUCCESS}" }
            add_field => { "ssh_authresult" => "success" }
            add_tag => ["_grok_sshd_success", "matched"]
        }
        grok {
            patterns_dir => "${LL_PATTERN_DIR:/etc/logstash/patterns.d}"
            match => { "message" => "%{SSH_DISCONNECT}" }
            add_tag => ["_grok_sshd_success", "matched", "ssh_disconnect"]
        }
        mutate {
            remove_tag => ["matched", "_grokparsefailure"]
        }
        geoip {
            source => "ssh_client_ip"
        }
    }
}
output{stdout{codec => rubydebug}}
```

````

log sample

````
```
2020-05-24T01:11:11+04:30 ldap sshd[29859]: Accepted publickey for cadmin from 192.168.2.32 port 44192 ssh2: RSA SHA256:ORw82lHe311CAgeD08StZzO31tlRZJcddddddaGx6Kg
```
````

---

<div class="post-metadata">

**Author:** ![YuWatanabe](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yuwatanabe/32/13259_2.png) [@YuWatanabe](https://discuss.elastic.co/u/YuWatanabe)\
**Post date:** [May 24, 2020, 12:16am UTC](https://discuss.elastic.co/t/logstash-if-statement-for-program/234020/2 "2020-05-24T00:16:43Z")

</div>

Could you please provide your custom grok pattern for below variables ?

```auto
SSH_AUTHFAIL_WRONGCREDS
SSH_AUTHFAIL_WRONGUSER
SSH_AUTH_SUCCESS
SSH_DISCONNECT

```

I would like to use it for testing what you are facing.

---

<div class="post-metadata">

**Author:** ![Rasoul\_Ahmadi](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rasoul_ahmadi/32/68520_2.png) [@Rasoul\_Ahmadi](https://discuss.elastic.co/u/Rasoul_Ahmadi)\
**Post date:** [May 24, 2020, 8:12am UTC](https://discuss.elastic.co/t/logstash-if-statement-for-program/234020/3 "2020-05-24T08:12:57Z")

</div>

thanks for the response  
i suspect some requirement doesn't meet or something

its from this source and I have modified groks to my need

> **[thomaspatzke/logstash-linux](https://github.com/thomaspatzke/logstash-linux)**
>
> Logstash Configuration for Linux Logs (Authentication, Apache, Mail) - thomaspatzke/logstash-linux

```
indent preformatted text by 4 spaces
SSH_AUTHFAIL_WRONGUSER Failed %{WORD:ssh_authmethod} for invalid user %{USERNAME:ssh_user} from %{IP:ssh_client_ip} port %{NUMBER:ssh_client_port} (?<ssh_protocol>\w+\d+)
SSH_AUTHFAIL_WRONGCREDS Failed %{WORD:ssh_authmethod} for %{USERNAME:ssh_user} from %{IP:ssh_client_ip} port %{NUMBER:ssh_client_port} (?<ssh_protocol>\w+\d+)
SSH_AUTH_SUCCESS Accepted %{WORD:ssh_authmethod} for %{USERNAME:ssh_user} from %{IP:ssh_client_ip} port %{NUMBER:ssh_client_port} (?<ssh_protocol>\w+\d+)(?:: %{WORD:ssh_pubkey_type} %{GREEDYDATA:ssh_pubkey_fingerprint})?
SSH_DISCONNECT Received disconnect from %{IP:ssh_client_ip} port %{INT:ssh_client_port}.*?:\s+%{GREEDYDATA:ssh_disconnect_reason}
```

---

<div class="post-metadata">

**Author:** ![YuWatanabe](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yuwatanabe/32/13259_2.png) [@YuWatanabe](https://discuss.elastic.co/u/YuWatanabe)\
**Post date:** [May 24, 2020, 11:22pm UTC](https://discuss.elastic.co/t/logstash-if-statement-for-program/234020/4 "2020-05-24T23:22:56Z")

</div>

Thanks for the reply. I have tested on logstash 7.7.0 .

`logstash_1 | [2020-05-24T23:19:20,436][INFO][logstash.runner] Starting Logstash {"logstash.version"=>"7.7.0"} `

Hmm.

From the log line you have provided , it looks filter behaves totally normal to me.

```auto
logstash_1 | /usr/share/logstash/vendor/bundle/jruby/2.5.0/gems/awesome_print-1.7.0/lib/awesome_print/formatters/base_formatter.rb:31: warning: constant ::Fixnum is deprecated
logstash_1 | {
logstash_1 | "message" => "2020-05-24T01:11:11+04:30 ldap sshd[29859]: Accepted publickey for cadmin from 192.168.2.32 port 44192 ssh2: RSA SHA256:ORw82lHe311CAgeD08StZzO31tlRZJcddddddaGx6Kg",
logstash_1 | "ssh_protocol" => "ssh2",
logstash_1 | "ssh_pubkey_fingerprint" => "SHA256:ORw82lHe311CAgeD08StZzO31tlRZJcddddddaGx6Kg",
logstash_1 | "ssh_pubkey_type" => "RSA",
logstash_1 | "@timestamp" => 2020-05-24T23:19:45.942Z,
logstash_1 | "geoip" => {},
logstash_1 | "ssh_client_port" => "44192",
logstash_1 | "tags" => [
logstash_1 | [0] "_grok_sshd_success",
logstash_1 | [1] "_geoip_lookup_failure"
logstash_1 | ],
logstash_1 | "ssh_authresult" => "success",
logstash_1 | "program" => "sshd",
logstash_1 | "ssh_user" => "cadmin",
logstash_1 | "@version" => "1",
logstash_1 | "host" => "logstash",
logstash_1 | "path" => "/mnt/logs/sshd.log",
logstash_1 | "ssh_authmethod" => "publickey",
logstash_1 | "ssh_client_ip" => "192.168.2.32"
logstash_1 | }
logstash_1 | [2020-05-24T23:19:46,834][INFO][logstash.runner] Logstash shut down.

```

It matches 3rd grok filter.

```auto
        grok {
            patterns_dir => "${LL_PATTERN_DIR:/etc/logstash/patterns.d}"
            match => { "message" => "%{SSH_AUTH_SUCCESS}" }
            add_field => { "ssh_authresult" => "success" }
            add_tag => ["_grok_sshd_success", "matched"]
        }

```

`geo_ip` fails because **192.168.2.32** is not a global ip .

Could you provide the ruby debug output you are facing ?

Below is the configuration I have used for testing .

```auto
input {                                                                                                                                                                                       
  file {                                                                                                                                                                                      
    path => [                                                                                                                                                                                 
      "/mnt/logs/sshd.log"                                                                                                                                                                    
    ]                                                                                                                                                                                         
    mode => "read"                                                                                                                                                                            
    start_position => "beginning"                                                                                                                                                             
    exit_after_read => "true"                                                                                                                                                                 
    file_completed_action => "log"                                                                                                                                                            
    file_completed_log_path => "/dev/null"                                                                                                                                                    
    sincedb_path => "/dev/null"
  }
}
filter {
    # For testing
    mutate { add_field => { "program" => "sshd"} }

    if [program] == "sshd" {
        grok {
            patterns_dir => "${LL_PATTERN_DIR:/etc/logstash/patterns.d}"
            match => { "message" => "%{SSH_AUTHFAIL_WRONGCREDS}" }
            add_field => { "ssh_authresult" => "fail" "ssh_failreason" => "wrong_credentials" }
            add_tag => ["_grok_sshd_success", "matched"]
        }
        grok {
            patterns_dir => "${LL_PATTERN_DIR:/etc/logstash/patterns.d}"
            match => { "message" => "%{SSH_AUTHFAIL_WRONGUSER}" }
            add_field => { "ssh_authresult" => "fail" "ssh_failreason" => "unknown_user" }
            add_tag => ["_grok_sshd_success", "matched"]
        }
        grok {
            patterns_dir => "${LL_PATTERN_DIR:/etc/logstash/patterns.d}"
            match => { "message" => "%{SSH_AUTH_SUCCESS}" }
            add_field => { "ssh_authresult" => "success" }
            add_tag => ["_grok_sshd_success", "matched"]
        }
        grok {
            patterns_dir => "${LL_PATTERN_DIR:/etc/logstash/patterns.d}"
            match => { "message" => "%{SSH_DISCONNECT}" }
            add_tag => ["_grok_sshd_success", "matched", "ssh_disconnect"]
        }
        mutate {
            remove_tag => ["matched", "_grokparsefailure"]
        }
        geoip {
            source => "ssh_client_ip"
        }
    }
}

output {
  stdout { }
}

```

---

<div class="post-metadata">

**Author:** ![Rasoul\_Ahmadi](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rasoul_ahmadi/32/68520_2.png) [@Rasoul\_Ahmadi](https://discuss.elastic.co/u/Rasoul_Ahmadi)\
**Post date:** [May 27, 2020, 12:52pm UTC](https://discuss.elastic.co/t/logstash-if-statement-for-program/234020/6 "2020-05-27T12:52:20Z")

</div>

i have found out if i do `import filter and output` in the same file and run it with `logstash -f` it does everything right but when it runs from `systemctl` it wond work

---

<div class="post-metadata">

**Author:** ![YuWatanabe](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yuwatanabe/32/13259_2.png) [@YuWatanabe](https://discuss.elastic.co/u/YuWatanabe)\
**Post date:** [May 27, 2020, 10:59pm UTC](https://discuss.elastic.co/t/logstash-if-statement-for-program/234020/7 "2020-05-27T22:59:56Z")

</div>

I am glad that _if statement_ has worked out.

For your information , if you have installed logstash from package manager and using systemd ,  
mostly you have to place logstash configuration file under [/etc/logstash/conf.d](https://www.elastic.co/guide/en/logstash/7.7/dir-layout.html#deb-layout) .

---

<div class="post-metadata">

**Author:** ![Rasoul\_Ahmadi](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rasoul_ahmadi/32/68520_2.png) [@Rasoul\_Ahmadi](https://discuss.elastic.co/u/Rasoul_Ahmadi)\
**Post date:** [May 28, 2020, 5:56am UTC](https://discuss.elastic.co/t/logstash-if-statement-for-program/234020/8 "2020-05-28T05:56:19Z")

</div>

thanks alot  
the if statement works fine there is something seriusly worng and i cant tshoot it alone  
i will appreciate if you could check this post out

> [@Logstash elasticsearch output problem](https://discuss.elastic.co/t/logstash-elasticsearch-output-problem/234577/6):
>
> what could be wrong with this particular config? i have multiple configs just like this and everything is working except this one input { file { path =\> ["${LL\_LOG\_IMPORT\_NGINX:/var/log/remote/ingress-nginx/nginx-access.log}"] type =\> "nginx" sincedb\_path =\> "${LL\_SINCEDB\_IMPORT\_NGINX:/var/lib/logstash/plugins/inputs/file/nginx-import.sincedb}" } } filter { if [type] == "nginx" { grok { match =\> { "message" =\> "%{TIMESTAMP\_IS…

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 25, 2020, 5:56am UTC](https://discuss.elastic.co/t/logstash-if-statement-for-program/234020/9 "2020-06-25T05:56:23Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
