# Not getting any ouput

**URL:** <https://discuss.elastic.co/t/not-getting-any-ouput/34172>\
**Category:** Logstash\
**Created:** [November 9, 2015, 4:40pm UTC](https://discuss.elastic.co/t/not-getting-any-ouput/34172 "2015-11-09T16:40:04Z")\
**Posts on this page:** 13\
**Page:** 1

<div class="post-metadata">

**Author:** ![Jackal9301](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jackal9301/32/5748_2.png) [@Jackal9301](https://discuss.elastic.co/u/Jackal9301)\
**Post date:** [November 9, 2015, 4:40pm UTC](https://discuss.elastic.co/t/not-getting-any-ouput/34172/1 "2015-11-09T16:40:05Z")

</div>

I'm trying to see the output of an if statement with grok filters. Logstash says it's starting however there is no file ever created in my output. Shouldn't I be seeing something even if there arent any matches?

Test input:  
{"message":"\<36\>Nov 02 15:48:57 LCE: [matched] 1.1.1.1:0 -\> 1.1.1.1:0 :: Microsoft-Windows-WMI-Activity/Operational,11/02/2015,15:48:00 PM,Microsoft-Windows-WMI-Activity,5858,Error,N/A,None,N/A,[GVLRESCMA02.shermfin.com](http://GVLRESCMA02.shermfin.com),IP:10.36.48.32,5858,Id = {074A806D-1260-000E-6F80-4A076012D101}; ClientMachine = SERVERNAME; User = NT AUTHORITY\SYSTEM; ClientProcessId = 1964; Component = Unknown; Operation = Start IWbemServices::ExecQuery - ROOT\STANDARDCIMV2 : ASSOCIATORS OF {MSFT\_NetLbfoTeamMember.InstanceID="{DE3CFAF2-9030-431E-8CDC-007673D0C50E}"} WHERE ResultClass=MSFT\_NetLbfoTeam; ResultCode = 0x80041008; PossibleCause = Unknown ","@version":"1","@timestamp":"2015-11-02T20:48:57.843Z","type":"LCE","host":"1.1.1.1"}

```
input {
  file{
	path => "C:\ELK\running\logstash-2.0.0\test\testinputgrok36.txt"
	#type => "LCE"
	}
}
filter {
	grok{
  		match => {"message" => "<%{BASE10NUM:LCE_log_num}>%{SYSLOGTIMESTAMP:LCE_time} %{NOTSPACE}: %{NOTSPACE} %{IP:Source_IP}:%{BASE10NUM:Source_Port} -> %{IP:Destination_IP}:%{BASE10NUM:Destination_Port} ::%{GREEDYDATA:Message_Data}" }
  		add_field => { "sort_num" => "%{LCE_log_num}" }
	}
if [sort_num] == "36" {
	grok{
		match => ["Message_Data", "%{PROG:Log_Type},%{DATE_US:Event_Date},%{TIME:Event_Time} %{WORD},%{PROG:Log},%{BASE10NUM},%{WORD:Error_id},%{PROG}%{SPACE}%{PROG},%{WORD},%{PROG},%{HOSTNAME},IP:%{IP},%{BASE10NUM}%{GREEDYDATA:Win_Log}"]
		add_tag => ["suceeded grok"]
	}
}
else {
	grok{
		add_tag => "failed grok"
	}
}
}
output {
  file{
    path => "C:\ELK\running\logstash-2.0.0\test\groktest.txt"
  }
}

```

Any and all help would be extremely appreciated.

Thanks

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [November 9, 2015, 7:41pm UTC](https://discuss.elastic.co/t/not-getting-any-ouput/34172/2 "2015-11-09T19:41:11Z")

</div>

Logstash is waiting for more data to be appended to testinputgrok36.txt, which it's tailing. For testing purposes like this I suggest you use the stdin input and redirect your test file to Logstash.

---

<div class="post-metadata">

**Author:** ![Jackal9301](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jackal9301/32/5748_2.png) [@Jackal9301](https://discuss.elastic.co/u/Jackal9301)\
**Post date:** [November 9, 2015, 7:42pm UTC](https://discuss.elastic.co/t/not-getting-any-ouput/34172/3 "2015-11-09T19:42:54Z")

</div>

Thanks, What I actually ended up doing was added start\_postion =\> ["beginning"] to the input and that has allowed me to test. Thanks for the input though!!

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [November 9, 2015, 7:52pm UTC](https://discuss.elastic.co/t/not-getting-any-ouput/34172/4 "2015-11-09T19:52:50Z")

</div>

That'll still only allow you to test it once. The second time you run Logstash with the exact same file Logstash will continue to tail it. This is a _major_ source of confusion among Logstash beginners, so beware.

---

<div class="post-metadata">

**Author:** ![Jackal9301](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jackal9301/32/5748_2.png) [@Jackal9301](https://discuss.elastic.co/u/Jackal9301)\
**Post date:** [November 9, 2015, 8:32pm UTC](https://discuss.elastic.co/t/not-getting-any-ouput/34172/5 "2015-11-09T20:32:44Z")

</div>

How do i use STDIN with a file?

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [November 9, 2015, 8:35pm UTC](https://discuss.elastic.co/t/not-getting-any-ouput/34172/6 "2015-11-09T20:35:35Z")

</div>

```
command < file

```

which (on Windows) is equivalent to

```
type file | command
```

---

<div class="post-metadata">

**Author:** ![Jackal9301](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jackal9301/32/5748_2.png) [@Jackal9301](https://discuss.elastic.co/u/Jackal9301)\
**Post date:** [November 9, 2015, 8:42pm UTC](https://discuss.elastic.co/t/not-getting-any-ouput/34172/7 "2015-11-09T20:42:58Z")

</div>

I don't understand this. Can you show me the syntax relative to my above example?

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [November 9, 2015, 8:45pm UTC](https://discuss.elastic.co/t/not-getting-any-ouput/34172/8 "2015-11-09T20:45:34Z")

</div>

```
C:\path\to\logstash\executable -f C:\path\to\configfile < C:\ELK\running\logstash-2.0.0\test\testinputgrok36.txt
```

---

<div class="post-metadata">

**Author:** ![Jackal9301](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jackal9301/32/5748_2.png) [@Jackal9301](https://discuss.elastic.co/u/Jackal9301)\
**Post date:** [November 9, 2015, 9:32pm UTC](https://discuss.elastic.co/t/not-getting-any-ouput/34172/9 "2015-11-09T21:32:11Z")

</div>

Thanks again!!! Is there a way when writing a GROK filter you can just say i dont care what data is in between x and y?

for example:  
A new process has been created. \<---I want this  
Subject: Security ID: S-1-5-18 \<---I don't want this  
Account Name: XXXXX \<---I want this

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [November 10, 2015, 6:47am UTC](https://discuss.elastic.co/t/not-getting-any-ouput/34172/10 "2015-11-10T06:47:24Z")

</div>

Are those three lines part of the same multi-line message or are they three different messages?

---

<div class="post-metadata">

**Author:** ![Jackal9301](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jackal9301/32/5748_2.png) [@Jackal9301](https://discuss.elastic.co/u/Jackal9301)\
**Post date:** [November 10, 2015, 2:11pm UTC](https://discuss.elastic.co/t/not-getting-any-ouput/34172/11 "2015-11-10T14:11:29Z")

</div>

They are all in the same line

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [November 10, 2015, 2:33pm UTC](https://discuss.elastic.co/t/not-getting-any-ouput/34172/12 "2015-11-10T14:33:12Z")

</div>

The grok filter doesn't do search-and-replace (use gsub for that), but grok is usually used for extracting fields from a larger message and you can choose to simply not extract the contents of the Subject line.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 5:23am UTC](https://discuss.elastic.co/t/not-getting-any-ouput/34172/13 "2017-07-06T05:23:16Z")

</div>


