# Logstash syslog message, doesn't choose right if statement

**URL:** <https://discuss.elastic.co/t/logstash-syslog-message-doesnt-choose-right-if-statement/327181>\
**Category:** Logstash\
**Created:** [March 7, 2023, 1:56pm UTC](https://discuss.elastic.co/t/logstash-syslog-message-doesnt-choose-right-if-statement/327181 "2023-03-07T13:56:11Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![splitmessage88](https://avatars.discourse-cdn.com/v4/letter/s/a87d85/32.png) [@splitmessage88](https://discuss.elastic.co/u/splitmessage88)\
**Post date:** [March 7, 2023, 1:56pm UTC](https://discuss.elastic.co/t/logstash-syslog-message-doesnt-choose-right-if-statement/327181/1 "2023-03-07T13:56:11Z")

</div>

Hi,

I'm trying to create a logstash pipeline for cisco FMC audit log.

I have create 3 if statements and would like for logstash to parse the syslog message according to the if statement.

Here is two example syslog messages

syslog message one  
`<189>Mar 7 13:09:01 ADIGCFMC01 sfdccsm: [FMC_AUDIT_LOG] ADIGCFMC01.test.net: test.user@test.net@10.10.10.25, Devices > Device Management > NGFW Interfaces, Page View`

syslog message two

`<189>Mar 7 10:14:25 ADIGCFMC01 sfdccsm: [FMC_AUDIT_LOG] ADIGCFMC01.test.net: csm_processes@Default User IP, Login, Login Success`

Here is my logstash pipeline

```auto
input {
          udp {
            port => 1514
            type => "syslog"
          }
        }

        filter {
          if "FMC_AUDIT_LOG" in [message] and [message] !~ '/^[A-Za-z0-9._%+-]+@[A-Za-z0-9.-]+\.[A-Za-z]{2,}\s/' {
            grok {
              match => { "message" => '<%{INT:Facility}>%{SYSLOGTIMESTAMP:timestamp}%{SPACE}%{HOSTNAME:hostname}%{SPACE}%{USERNAME:TEST}:%{SPACE}\[%{USER:ciscoauth}\]%{SPACE}%{GREEDYDATA:message}'
              }
            add_tag => ["one_value"]
            } 
          } else if [message] =~ '/^[A-Za-z0-9._%+-]+@[A-Za-z0-9.-]+\.[A-Za-z]{2,}\s/' {
            grok {
              match => {
                "message" => '<%{INT:Facility}>%{SYSLOGTIMESTAMP:timestamp}%{SPACE}%{HOSTNAME:hostname}%{SPACE}%{USERNAME:process}:%{SPACE}\[%{USER:ciscoauth}\]%{SPACE}%{HOSTNAME:hostname123}:%{SPACE}%{DATA:username}%{DATA:username}%{EMAILADDRESS:email}@%{IPV4:ipv4},%{SPACE}%{GREEDYDATA:message}'
              }
              add_tag => ["two_value"]
            }
          } else {
            drop {}
          }

          date {
            match => ["timestamp", "MMM d HH:mm:ss", "MMM dd HH:mm:ss"]
          }

```

The syslog message always chooses to run with the first if-statement and ignore the second one.

Request:  
I would like logstash to use the first if statement if the syslog message contains FMC\_AUDIT\_LOG and an email address and the second if statement if the syslog message contains FMC\_AUDIT\_LOG but not the email address.

Question:

1. How can I change the if statement so it chooses the right if statement to use?
2. Can this be done another way that is much easier than using if statements and grok?

Thanks.

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [March 7, 2023, 5:57pm UTC](https://discuss.elastic.co/t/logstash-syslog-message-doesnt-choose-right-if-statement/327181/2 "2023-03-07T17:57:05Z")

</div>

> [@splitmessage88](#):
>
> `[message] !~ '/^[A-Za-z0-9._%+-]+@[A-Za-z0-9.-]+\.[A-Za-z]{2,}\s/' {`

Your messages start with \<, so they are never going to match that pattern. Thus they will always match the first if.

I would suggest using dissect for the fixed prefix, then use grok for the rest of the line. See [here](https://discuss.elastic.co/t/metatrader-how-parse-such-logs/248406/2) for an example.

Note that if you do not set the overwrite option and your output field matches an existing field (e.g. [message]) then you will end up with that field [being an array](https://github.com/logstash-plugins/logstash-filter-grok/issues/180).

Note also that there are [standard grok patterns](https://github.com/logstash-plugins/logstash-patterns-core/blob/f01f3f34cfab13a28b0822bdba33db41823cb1d8/patterns/legacy/grok-patterns#L3) that can be used to pick out an email address, and that recognizing an email address is a ridiculously complex problem if you need to support [international addresses](https://en.wikipedia.org/wiki/International_email).

---

<div class="post-metadata">

**Author:** ![splitmessage88](https://avatars.discourse-cdn.com/v4/letter/s/a87d85/32.png) [@splitmessage88](https://discuss.elastic.co/u/splitmessage88)\
**Post date:** [March 8, 2023, 2:36pm UTC](https://discuss.elastic.co/t/logstash-syslog-message-doesnt-choose-right-if-statement/327181/3 "2023-03-08T14:36:26Z")

</div>

Hi @Badger

Thank you for the input.

I used your information and now the syslog message is parsing correctly.

The if statement is working and I had some issue with the last part of the message but solved it with the below code.

I split the last part of the message and created new fields with it.

```auto
mutate {
            split => { "data" => ", "}

            add_field => { "[event][type]" => "%{[data][1]}" }
            add_field => { "[event][dataset]" => "%{[data][2]}" }
          }

```

Thanks!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 5, 2023, 2:36pm UTC](https://discuss.elastic.co/t/logstash-syslog-message-doesnt-choose-right-if-statement/327181/4 "2023-04-05T14:36:53Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
