# Logstash Multiple Grok Add Field

**URL:** <https://discuss.elastic.co/t/logstash-multiple-grok-add-field/141683>\
**Category:** Logstash\
**Created:** [July 26, 2018, 2:48am UTC](https://discuss.elastic.co/t/logstash-multiple-grok-add-field/141683 "2018-07-26T02:48:14Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![insomniac](https://avatars.discourse-cdn.com/v4/letter/i/bb73d2/32.png) [@insomniac](https://discuss.elastic.co/u/insomniac)\
**Post date:** [July 26, 2018, 2:48am UTC](https://discuss.elastic.co/t/logstash-multiple-grok-add-field/141683/1 "2018-07-26T02:48:15Z")

</div>

I'm trying to have a single message parse through a hash array of match, and then check the message type after to add a field.

```
 grok {
  match => { "message" => [
      "%{NOTSPACE:syslogversion}%{SYSLOGTIMESTAMP:timestamp} %{WORD:servicename}\[%{NUMBER:pid}\]: Invalid user %{WORD:username} from %{IP:ip}",
      "%{NOTSPACE:syslogversion}%{SYSLOGTIMESTAMP:timestamp} %{WORD:servicename}\[%{NUMBER:pid}\]: Failed keyboard-interactive/pam for invalid user %{WORD:username} from %{IP:ip} port %{NUMBER:port} %{WORD:protocol}"
      "%{NOTSPACE:syslogversion}%{SYSLOGTIMESTAMP:timestamp} %{WORD:servicename}\[%{NUMBER:pid}\]: Accepted keyboard-interactive/pam for %{WORD:username} from %{IP:ip} port %{NUMBER:port} %{WORD:protocol}",
      "%{NOTSPACE:syslogversion}%{SYSLOGTIMESTAMP:timestamp} %{WORD:servicename}\[%{NUMBER:pid}\]: Failed password for %{WORD:username} from %{IP:ip} port %{NUMBER:port} %{WORD:protocol}",
      "%{NOTSPACE:syslogversion}%{SYSLOGTIMESTAMP:timestamp} %{DATA:servicename}\[%{NUMBER:pid}\]: /index.php: Successful login for user '%{WORD:username}' from: %{IP:ip}",
      "%{NOTSPACE:syslogversion}%{SYSLOGTIMESTAMP:timestamp} %{DATA:servicename}\[%{NUMBER:pid}\]: /index.php: User logged out for user '%{WORD:username}' from: %{IP:ip}",
      "%{NOTSPACE:syslogversion}%{SYSLOGTIMESTAMP:timestamp} %{DATA:servicename}\[%{NUMBER:pid}\]: /index.php: webConfigurator authentication error for '%{WORD:username}' from %{IP:ip}"
      ]
  }
}

    if "Failed keyboard" in [message] {
      grok { add_field => { "error_type" => "Failed keyboard-interactive/pam" } }
    }

    if "Invalid User" in [message] {
      grok { add_field => { "error_type" => "Invalid User" } }
    }

    if "Accepted keyboard" in [message] {
      grok { add_field => { "error_type" => "Accepted User" } }
    }

    if "Failed password" in [message] {
      grok { add_field => { "error_type" => "Invalid Password" } }
    }

    if "Successful login" in [message] {
      grok { add_field => { "error_type" => "Successful Login" } }
    }

    if "User logged out" in [message] {
      grok { add_field => { "error_type" => "Logged Out" } }
    }

    if "webConfigurator authentication error" in [message] {
      grok { add_field => { "error_type" => "Invalid Password" } }
    }

```

However, the message does get grok'd fine, but its always has the \_grokparsefailure tag, and the additional field does not get added.

```
{"ip":"10.162.126.165","pid":"11609","username":"test","tags":["_grokparsefailure"],"servicename":"php-fpm","message":"<32>Jul 26 10:18:15 php-fpm[11609]: /index.php: webConfigurator authentication error for 'test' from 10.162.126.165","@version":"1","@timestamp":"2018-07-26T02:18:15.000Z","type":"pfsense-system","timestamp":"Jul 26 10:18:15","syslogversion":"<32>"}

```

Can anyone point me in the right direction? All the threads i've found haven't helped.

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [July 26, 2018, 7:03am UTC](https://discuss.elastic.co/t/logstash-multiple-grok-add-field/141683/2 "2018-07-26T07:03:28Z")

</div>

Don't use a grok filter to just add a field. Use a mutate filter for that. `add_field` only triggers when the filter is successful, and a grok filter without `match` doesn't count as successful.

---

<div class="post-metadata">

**Author:** ![insomniac](https://avatars.discourse-cdn.com/v4/letter/i/bb73d2/32.png) [@insomniac](https://discuss.elastic.co/u/insomniac)\
**Post date:** [July 27, 2018, 2:19am UTC](https://discuss.elastic.co/t/logstash-multiple-grok-add-field/141683/3 "2018-07-27T02:19:41Z")

</div>

Thank you Magnus. Two birds with one stone 🙂

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 24, 2018, 2:19am UTC](https://discuss.elastic.co/t/logstash-multiple-grok-add-field/141683/4 "2018-08-24T02:19:42Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
