# Logstash not matching substring of custom field

**URL:** <https://discuss.elastic.co/t/logstash-not-matching-substring-of-custom-field/52389>\
**Category:** Logstash\
**Created:** [June 9, 2016, 11:26pm UTC](https://discuss.elastic.co/t/logstash-not-matching-substring-of-custom-field/52389 "2016-06-09T23:26:48Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Josh\_Reichardt](https://avatars.discourse-cdn.com/v4/letter/j/f08c70/32.png) [@Josh\_Reichardt](https://discuss.elastic.co/u/Josh_Reichardt)\
**Post date:** [June 9, 2016, 11:26pm UTC](https://discuss.elastic.co/t/logstash-not-matching-substring-of-custom-field/52389/1 "2016-06-09T23:26:48Z")

</div>

I have the following Logstash setup.

Logs are piped to Logstash from Logspout via the [logspout-logstash](https://github.com/looplab/logspout-logstash) adapter, which adds a few fields to log messages, namely the `docker.image` field.

I am able to ingest the logs but am having trouble parsing them. I would like to make some filters based on the Docker image field, below I'm trying to parse and match just the `nginx` piece out of the full Docker image, which is similar to `organization/nginx:tag`.

There is something wrong with my config though because the tag doesn't look like it is being created and the message field doesn't look like it is being parsed either.

Here's what I have in my config so far:

```
input {

    # Logspout UDP input
    udp {
        port => 5000
        type => logspout
        codec => json
    }
}

filter {

  # Nginx access logs
  if [docker.image] =~ /nginx/ {
    grok {
      match => ["message", "%{IPORHOST:clientip} - - \[%{HTTPDATE:timestamp}\] %{QS:request} %{INT:status} %{INT:body_bytes_sent} %{QS:http_referer} %{QS:agent}" ]
      add_tag => ["nginx"]
    }
  }
}

```

I have a feeling the field is part of the problem but I'm not sure. Is there something happening behind the scenes that I'm missing? Is there a way to step through a filter to see if a log is hitting my filter?

---

<div class="post-metadata">

**Author:** ![Josh\_Reichardt](https://avatars.discourse-cdn.com/v4/letter/j/f08c70/32.png) [@Josh\_Reichardt](https://discuss.elastic.co/u/Josh_Reichardt)\
**Post date:** [June 10, 2016, 4:21pm UTC](https://discuss.elastic.co/t/logstash-not-matching-substring-of-custom-field/52389/2 "2016-06-10T16:21:53Z")

</div>

I figured out what I was doing wrong. I needed to use `[docker][image]`.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 4:53am UTC](https://discuss.elastic.co/t/logstash-not-matching-substring-of-custom-field/52389/3 "2017-07-06T04:53:34Z")

</div>


