# Logstash problem

**URL:** <https://discuss.elastic.co/t/logstash-problem/177636>\
**Category:** Logstash\
**Created:** [April 19, 2019, 2:52pm UTC](https://discuss.elastic.co/t/logstash-problem/177636 "2019-04-19T14:52:35Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![bkrishna](https://avatars.discourse-cdn.com/v4/letter/b/5daacb/32.png) [@bkrishna](https://discuss.elastic.co/u/bkrishna)\
**Post date:** [April 19, 2019, 2:52pm UTC](https://discuss.elastic.co/t/logstash-problem/177636/1 "2019-04-19T14:52:35Z")

</div>

input {  
tcp {  
port =\> 5004  
codec =\> multiline {  
pattern =\> "^index::"  
negate =\> true  
what =\> "previous"  
}  
}  
}  
filter {  
if "index::" in [message] {  
grok {  
match =\> { "message" =\> "%{}" }  
}  
}  
else if "index::" in [message] {  
grok {  
match =\> { "message" =\> "%{}" }  
}  
}  
else {  
drop { }  
}  
}

output {  
stdout { codec =\> rubydebug }  
kafka {  
bootstrap\_servers =\> ["[AUSILKFKWA01.us.er.com:9092](http://AUSILKFKWA01.us.er.com:9092),[AUSILKFKQB01.us.er.com:9092](http://AUSILKFKQB01.us.er.com:9092)"]  
topic\_id =\> "try1"  
compression\_type =\> "snappy"  
value\_serializer =\> 'org.apache.kafka.common.serialization.ByteArraySerializer'  
}  
}

my log looks like this : ::::  
i am using logstash 6.5.4 version  
"message" =\> "index::goa\_route sourcetype:: rash host::ausflsexsslap23.us.dell.com 2019-04-19 07:59:46,242 INFO - \tFri Apr 19 07:59:46 CDT 2019\tID:\<281683.1555678786240.0\>\tes\_svc7\_dr\_osb\tes\_svc7\_dr\_osb\_ms09\tSiebelSessionAdapter/3\_7/ProxyServices/SiebelSessionAdapter\tSIEBEL\_WS\_REQUEST\_HEADER\_MSG\t[messageData([UniqueReqId = 2b1d4a3b-68da-40bd-a2a6-cb03250ec390]; [SessionType = Stateless]; [SessionToken = sAiS.bW4zs0kwZaO-8FBXaS.iWgufG7tp58zMfRuX6I2om-Dh5xUBPenApZck2ac9nyouWn9z7usM4ZwdcZuSbMio91F7lJOqJImUjG9mT4NRNCA-jURUreb4600qCBIjlEmwNQqiOhqLMYAW1rBN2vKBGXDbZ5v4hr-vGIMn.PiqLG5HK-SMrNjBEB5AoVSyjPIwbsBRnTgkkfMkWEDQbxe5YEaBH8IVCDGKLCMNgT8Yl3hEgtD4OOzB4mnx.ZkO.bNjk-H8oqLL4jPCvp4yfvn9zdpyoZtvQQGiok.FPHHWPYWTL9qWJ12vG5gbUDC3Scs26nRpJUOb.JlhzhnqA\_\_]; [UsernameToken =]; [PasswordText =])]\tms \t",

task : like above message i used to get different type of indexes so each index type i have to route to different kafka topic so please help the filter logic with if condition

looking quick help

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [April 20, 2019, 1:21pm UTC](https://discuss.elastic.co/t/logstash-problem/177636/2 "2019-04-20T13:21:57Z")

</div>

If you want to parse the index name from the message you could use

```
grok { match => { "message" => "^index::%{WORD:indexName}" } }

```

and then use a sprintf reference in the kafka output

```
topic => "%{indexName}"
```

---

<div class="post-metadata">

**Author:** ![bkrishna](https://avatars.discourse-cdn.com/v4/letter/b/5daacb/32.png) [@bkrishna](https://discuss.elastic.co/u/bkrishna)\
**Post date:** [April 22, 2019, 5:23am UTC](https://discuss.elastic.co/t/logstash-problem/177636/3 "2019-04-22T05:23:58Z")

</div>

if "index::soa\_prod\_server" and "ERROR" in [message] {  
kafka {  
bootstrap\_servers =\> ["AUSILKjKBK01:9092"]  
topic\_id =\> "try3"  
}  
}

can some one tell "index::soa\_prod\_server" only searching after and what ever it is there not searching can some one tell how can i search both using if condition

please suggest me logic i am using logstace version:6.5.4

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 20, 2019, 5:24am UTC](https://discuss.elastic.co/t/logstash-problem/177636/4 "2019-05-20T05:24:00Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
