# Need more information on logstash

**URL:** <https://discuss.elastic.co/t/need-more-information-on-logstash/46694>\
**Category:** Logstash\
**Created:** [April 7, 2016, 2:10pm UTC](https://discuss.elastic.co/t/need-more-information-on-logstash/46694 "2016-04-07T14:10:50Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![oth1113](https://avatars.discourse-cdn.com/v4/letter/o/13edae/32.png) [@oth1113](https://discuss.elastic.co/u/oth1113)\
**Post date:** [April 7, 2016, 2:10pm UTC](https://discuss.elastic.co/t/need-more-information-on-logstash/46694/1 "2016-04-07T14:10:50Z")

</div>

I need easy explanation please 🙂 I am a beginner in logstash  
i have some questions 🙂

1- What is the tag "\_gorkparsefailure" and it used for? if I delete this tag what will happen ?

2- how to remove the tag " multiline " ?

3- how I can make a condition from a field of my grok (condition in grok ) ?

4- "endpoint" what is it ?

thank you in advance

---

<div class="post-metadata">

**Author:** ![Alex\_6](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/alex_6/32/1330_2.png) [@Alex\_6](https://discuss.elastic.co/u/Alex_6)\
**Post date:** [April 7, 2016, 3:00pm UTC](https://discuss.elastic.co/t/need-more-information-on-logstash/46694/2 "2016-04-07T15:00:28Z")

</div>

1. grokparsefailure tag gets added when you use the Grok filter and it was unable to match the input to any of the patterns you have defined. You can change it using the [tag\_on\_failure](https://www.elastic.co/guide/en/logstash/current/plugins-filters-grok.html#plugins-filters-grok-tag_on_failure) attribute, including setting it to an empty array if you don't want to add a tag on failure.

2. I don't think that's a standard tag, check your multiline filter to see if it's being set in there.

3. Not sure what you mean. You want to check to see if a field exists after you have used Grok? You can do

4 . An endpoint is just a location that something connects to. So Logstash can be an endpoint for another application if that application is sending data to Logstash. Or if Logstash is sending data to Elasticsearch then Elasticsearch is the endpoint for Logstash.

---

<div class="post-metadata">

**Author:** ![oth1113](https://avatars.discourse-cdn.com/v4/letter/o/13edae/32.png) [@oth1113](https://discuss.elastic.co/u/oth1113)\
**Post date:** [April 7, 2016, 3:13pm UTC](https://discuss.elastic.co/t/need-more-information-on-logstash/46694/3 "2016-04-07T15:13:28Z")

</div>

Thank you it's great. I understand better now.  
One last question. " Break\_on match " used for?

Thanks again.

---

<div class="post-metadata">

**Author:** ![Alex\_6](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/alex_6/32/1330_2.png) [@Alex\_6](https://discuss.elastic.co/u/Alex_6)\
**Post date:** [April 7, 2016, 3:24pm UTC](https://discuss.elastic.co/t/need-more-information-on-logstash/46694/4 "2016-04-07T15:24:39Z")

</div>

If you have multiple Grok patterns then Grok will try to match against them in the order which they appear in the config file. As soon as one is matched the filter finishes. [break\_on\_match](https://www.elastic.co/guide/en/logstash/current/plugins-filters-grok.html#plugins-filters-grok-break_on_match) is set to true by default and this is its behaviour.

However, if you set break\_on\_match to false then Grok will attempt all patterns no matter what. If the first pattern matches then it will still continue to match all the others you may have defined too. It just allows more flexibility.

As an example, say you had some user data like:

`James Bond, MI5 Spy`

You could have the following Grok filter to extract all the data you need in one go:

```
grok {
  match => {
    "message" => [
      "%{GREEDYDATA:full_name}, %{GREEDYDATA:occupation}",
      "%{WORD:first_name} %{WORD:last_name},"
    ]
  }
  break_on_match => false
}

```

That would pull out full\_name, first\_name, last\_name and occupation all in one Grok as it would do the 2nd pattern even after the first one has matched.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 5:03am UTC](https://discuss.elastic.co/t/need-more-information-on-logstash/46694/5 "2017-07-06T05:03:17Z")

</div>


