# Logstash if statement not working correctly

**URL:** <https://discuss.elastic.co/t/logstash-if-statement-not-working-correctly/37919>\
**Category:** Logstash\
**Created:** [December 24, 2015, 8:07am UTC](https://discuss.elastic.co/t/logstash-if-statement-not-working-correctly/37919 "2015-12-24T08:07:28Z")\
**Posts on this page:** 1\
**Showing post:** 1

<div class="post-metadata">

**Author:** ![davinders](https://avatars.discourse-cdn.com/v4/letter/d/e274bd/32.png) [@davinders](https://discuss.elastic.co/u/davinders)\
**Post date:** [December 24, 2015, 8:07am UTC](https://discuss.elastic.co/t/logstash-if-statement-not-working-correctly/37919/1 "2015-12-24T08:07:28Z")

</div>

I am trying to restrict content/data to go to elastic search if grok not able to parse data in input.log but seems if " **\_grokparsefailure" not in** [tags] not working. I am parsing some input log and matching some pattern using grok. If grok does not find a match, this match is still going to output and I can see unmatched (\_grokparsefailure) text in tags in elastic search indexed docs. So i don't want any data to be passed to elastic search if grok pattern fails. Hope my question is clear.

**My logstash.conf file.**  
input {  
file {  
path =\> "/opt/elasticSearch/logstash-1.4.2/input.log"  
codec =\> multiline {  
pattern =\> "^["  
negate =\> true  
what =\> previous  
}  
start\_position =\> "end"  
}  
}

filter {  
grok {  
match =\> [  
"message", "^[%{GREEDYDATA}] %{GREEDYDATA} Searching hotels for country %{GREEDYDATA:country}, city %{GREEDYDATA:city}, checkin %{GREEDYDATA:checkin}, checkout %{GREEDYDATA:checkout}, roomstay %{GREEDYDATA:roomstay}, No. of hotels returned is %{NUMBER:hotelcount} ."  
]  
}  
}

output {

```
    if "_grokparsefailure" not in [tags]{
            elasticsearch {
                    cluster => "elasticsearchdev"
            }
    }

```

}

---

_[View the full topic](https://discuss.elastic.co/t/logstash-if-statement-not-working-correctly/37919)._
