# Logstash syslog message, doesn't choose right if statement

**URL:** <https://discuss.elastic.co/t/logstash-syslog-message-doesnt-choose-right-if-statement/327181>\
**Category:** Logstash\
**Created:** [March 7, 2023, 1:56pm UTC](https://discuss.elastic.co/t/logstash-syslog-message-doesnt-choose-right-if-statement/327181 "2023-03-07T13:56:11Z")\
**Posts on this page:** 1\
**Showing post:** 2

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [March 7, 2023, 5:57pm UTC](https://discuss.elastic.co/t/logstash-syslog-message-doesnt-choose-right-if-statement/327181/2 "2023-03-07T17:57:05Z")

</div>

> [@splitmessage88](#):
>
> `[message] !~ '/^[A-Za-z0-9._%+-]+@[A-Za-z0-9.-]+\.[A-Za-z]{2,}\s/' {`

Your messages start with \<, so they are never going to match that pattern. Thus they will always match the first if.

I would suggest using dissect for the fixed prefix, then use grok for the rest of the line. See [here](https://discuss.elastic.co/t/metatrader-how-parse-such-logs/248406/2) for an example.

Note that if you do not set the overwrite option and your output field matches an existing field (e.g. [message]) then you will end up with that field [being an array](https://github.com/logstash-plugins/logstash-filter-grok/issues/180).

Note also that there are [standard grok patterns](https://github.com/logstash-plugins/logstash-patterns-core/blob/f01f3f34cfab13a28b0822bdba33db41823cb1d8/patterns/legacy/grok-patterns#L3) that can be used to pick out an email address, and that recognizing an email address is a ridiculously complex problem if you need to support [international addresses](https://en.wikipedia.org/wiki/International_email).

---

_[View the full topic](https://discuss.elastic.co/t/logstash-syslog-message-doesnt-choose-right-if-statement/327181)._
