# Logstash if statement not working probably

**URL:** <https://discuss.elastic.co/t/logstash-if-statement-not-working-probably/37920>\
**Category:** Logstash\
**Created:** [December 24, 2015, 8:12am UTC](https://discuss.elastic.co/t/logstash-if-statement-not-working-probably/37920 "2015-12-24T08:12:43Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![davinders](https://avatars.discourse-cdn.com/v4/letter/d/e274bd/32.png) [@davinders](https://discuss.elastic.co/u/davinders)\
**Post date:** [December 24, 2015, 8:12am UTC](https://discuss.elastic.co/t/logstash-if-statement-not-working-probably/37920/1 "2015-12-24T08:12:43Z")

</div>

Continuing the discussion from [Grok filter if condition issue](https://discuss.elastic.co/t/grok-filter-if-condition-issue/28619/2):

> [@Grok filter if condition issue](https://discuss.elastic.co/t/grok-filter-if-condition-issue/28619/2):
>
> This isn't a grok question, it's a general filter question. This is probably what you're looking for:
> 
> ```
> filter {
> ...
> if "method" in [tags] {
> mutate {
> add_tag => ["newtag", "manualtag"]
> }
> }
> }
> 
> ```

Continuing the discussion from [Grok filter if condition issue](https://discuss.elastic.co/t/grok-filter-if-condition-issue/28619/2):

> [@Grok filter if condition issue](https://discuss.elastic.co/t/grok-filter-if-condition-issue/28619/2):
>
> This isn't a grok question, it's a general filter question. This is probably what you're looking for:
> 
> ```
> filter {
> ...
> if "method" in [tags] {
> mutate {
> add_tag => ["newtag", "manualtag"]
> }
> }
> }
> 
> ```

I am trying to restrict content/data to go to Elasticsearch if grok not able to parse data in input.log but seems if " **\_grokparsefailure" not in** [tags] not working. I am parsing some input log and matching some pattern using grok. If grok does not find a match, this match is still going to output and I can see unmatched (\_grokparsefailure) text in tags in Elasticsearch indexed docs. So i don't want any data to be passed to Elasticsearch if grok pattern fails. Hope my question is clear.

**My logstash.conf file.**  
input {  
file {  
path =\> "/opt/elasticSearch/logstash-1.4.2/input.log"  
codec =\> multiline {  
pattern =\> "^["  
negate =\> true  
what =\> previous  
}  
start\_position =\> "end"  
}  
}

filter {  
grok {  
match =\> [  
"message", "^[%{GREEDYDATA}] %{GREEDYDATA} Searching hotels for country %{GREEDYDATA:country}, city %{GREEDYDATA:city}, checkin %{GREEDYDATA:checkin}, checkout %{GREEDYDATA:checkout}, roomstay %{GREEDYDATA:roomstay}, No. of hotels returned is %{NUMBER:hotelcount} ."  
]  
}  
}

output {

```
    if "_grokparsefailure" not in [tags]{
            elasticsearch {
                    cluster => "elasticsearchdev"
            }
    }

```

}

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [December 24, 2015, 11:06pm UTC](https://discuss.elastic.co/t/logstash-if-statement-not-working-probably/37920/2 "2015-12-24T23:06:00Z")

</div>

I'll close this one as you also have [Logstash if statement not working correctly](https://discuss.elastic.co/t/logstash-if-statement-not-working-correctly/37919/1) 🙂

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [December 25, 2015, 1:06am UTC](https://discuss.elastic.co/t/logstash-if-statement-not-working-probably/37920/3 "2015-12-25T01:06:05Z")

</div>

This topic was automatically closed 2 hours after the last reply. New replies are no longer allowed.
