# Need help to create loglevel field

**URL:** <https://discuss.elastic.co/t/need-help-to-create-loglevel-field/287665>\
**Category:** Logstash\
**Created:** [October 26, 2021, 9:25am UTC](https://discuss.elastic.co/t/need-help-to-create-loglevel-field/287665 "2021-10-26T09:25:39Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![sushant12](https://avatars.discourse-cdn.com/v4/letter/s/c37758/32.png) [@sushant12](https://discuss.elastic.co/u/sushant12)\
**Post date:** [October 26, 2021, 9:25am UTC](https://discuss.elastic.co/t/need-help-to-create-loglevel-field/287665/1 "2021-10-26T09:25:39Z")

</div>

filter{  
if "ERROR" in [LEVEl]{  
grok{  
match =\> {·  
"message" =\> "%{TIME:timestamp} %{LOGLEVEL:LEVEL} %{GREEDYDATA:errormsg}"·  
}

```
             }
 }           
 if "DEBUG" in [LEVEl]{
       grok{·····
          match => {·
             "message" => "%{TIME:timestamp} %{LOGLEVEL:LEVEL} %{GREEDYDATA:errormsg}"·
             }
           } 
 }         
 if "CRITICAL" in [LEVEl]{
       grok{····· 
          match => {·
             "message" => "%{TIME:timestamp} %{LOGLEVEL:LEVEL} %{GREEDYDATA:errormsg}"
             }
           } 
 }

 mutate {
         remove_field => ["@version", "path", "host"]
           }
```

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [October 26, 2021, 5:33pm UTC](https://discuss.elastic.co/t/need-help-to-create-loglevel-field/287665/2 "2021-10-26T17:33:36Z")

</div>

> [@sushant12](#):
>
> if "ERROR" in [LEVEl]{

I do not understand what you are trying to do here. I see nothing that would have created the [LEVEl] field, so I would expect none of the groks to be executed. Also, all of your grok filters look the same, so why not replace that whole filter section with

```
filter { grok { match => { "message" => "%{TIME:timestamp} %{LOGLEVEL:LEVEL} %{GREEDYDATA:errormsg}" } }

```

---

<div class="post-metadata">

**Author:** ![sushant12](https://avatars.discourse-cdn.com/v4/letter/s/c37758/32.png) [@sushant12](https://discuss.elastic.co/u/sushant12)\
**Post date:** [October 27, 2021, 10:15am UTC](https://discuss.elastic.co/t/need-help-to-create-loglevel-field/287665/3 "2021-10-27T10:15:39Z")

</div>

please help me. here I am trying to extract "ERROR", "DEBUG" and "CRITICAL " logs with the help of logstash and add\_field which contain loglevel like ("ERROR", "DEBUG" and "CRITICAL") as per its type.  
Avoid to send "INFO" logs to output.  
Could you please help how can write filter for that?

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [October 27, 2021, 2:51pm UTC](https://discuss.elastic.co/t/need-help-to-create-loglevel-field/287665/4 "2021-10-27T14:51:35Z")

</div>

You could try

```
filter {
    grok { match => { "message" => "%{TIME:timestamp} %{LOGLEVEL:LEVEL} %{GREEDYDATA:errormsg}" }
    if [LEVEL] == "INFO" { drop {} }
}
```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 24, 2021, 2:51pm UTC](https://discuss.elastic.co/t/need-help-to-create-loglevel-field/287665/5 "2021-11-24T14:51:48Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
