# Parsing a keyword from message

**URL:** <https://discuss.elastic.co/t/parsing-a-keyword-from-message/86434>\
**Category:** Logstash\
**Created:** [May 19, 2017, 1:43pm UTC](https://discuss.elastic.co/t/parsing-a-keyword-from-message/86434 "2017-05-19T13:43:35Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Bhargav\_Narine](https://avatars.discourse-cdn.com/v4/letter/b/0ea827/32.png) [@Bhargav\_Narine](https://discuss.elastic.co/u/Bhargav_Narine)\
**Post date:** [May 19, 2017, 1:43pm UTC](https://discuss.elastic.co/t/parsing-a-keyword-from-message/86434/1 "2017-05-19T13:43:35Z")

</div>

Hi,

I am new to ELK and trying to parse a specific keyword from message of the log entry and if that matches, creating a separate index in elasticsearch. My output config is like below

output {

```
if "ALARM" in [logmsg] {
  elasticsearch {
     hosts => ["localhost:9200"]
     index => "alarm"
 }
else

```

{  
elasticsearch {  
hosts =\> ["localhost:9200"]  
index =\> "%{+YYYY.MM.dd}"

}  
}  
}

I got the above logic from [Filter specific Message with logstash before sending to ElasticSearch](https://discuss.elastic.co/t/filter-specific-message-with-logstash-before-sending-to-elasticsearch/28584) but it is not working. Is there any syntax error on this? Can you please help it?

Error log from logstash :

[2017-05-19T13:17:20,684][ERROR][logstash.agent] Cannot create pipeline {:reason=\>"Expected one of #, =\> at line 33, column 16 (byte 589) after output {\n \n if "ALARM" in [logmsg] {\n elasticsearch {\n hosts =\> ["localhost:9200"]\n index =\> "alarm"\n }\n else\n{\n\n elasticsearch ", :backtrace=\>["/usr/share/logstash/logstash-core/lib/logstash/pipeline.rb:50:in `initialize'", "/usr/share/logstash/logstash-core/lib/logstash/pipeline.rb:145:in`initialize'", "/usr/share/logstash/logstash-core/lib/logstash/agent.rb:286:in `create_pipeline'", "/usr/share/logstash/logstash-core/lib/logstash/agent.rb:95:in`register\_pipeline'", "/usr/share/logstash/logstash-core/lib/logstash/runner.rb:274:in `execute'", "/usr/share/logstash/vendor/bundle/jruby/1.9/gems/clamp-0.6.5/lib/clamp/command.rb:67:in`run'", "/usr/share/logstash/logstash-core/lib/logstash/runner.rb:185:in `run'", "/usr/share/logstash/vendor/bundle/jruby/1.9/gems/clamp-0.6.5/lib/clamp/command.rb:132:in`run'", "/usr/share/logstash/lib/bootstrap/environment.rb:71:in `(root)'"]}

Thanks in advance

---

<div class="post-metadata">

**Author:** ![Nico-DF](https://avatars.discourse-cdn.com/v4/letter/n/ed8c4c/32.png) [@Nico-DF](https://discuss.elastic.co/u/Nico-DF)\
**Post date:** [May 19, 2017, 2:24pm UTC](https://discuss.elastic.co/t/parsing-a-keyword-from-message/86434/2 "2017-05-19T14:24:08Z")

</div>

> [@Bhargav\_Narine](#):
>
> Cannot create pipeline {:reason=\>"Expected one of #, =\> at line 33, column 16 (byte 589) after output {\n \n if "ALARM" in [logmsg] {\n elasticsearch {\n hosts =\> ["localhost:9200"]\n index =\> "alarm"\n }\n else\n{\n\n elasticsearch "

It basically tells you that you're missing probably a closing bracket, or parenthesis etc.

And in fact, you miss one: before the `else` statement

---

<div class="post-metadata">

**Author:** ![Bhargav\_Narine](https://avatars.discourse-cdn.com/v4/letter/b/0ea827/32.png) [@Bhargav\_Narine](https://discuss.elastic.co/u/Bhargav_Narine)\
**Post date:** [May 19, 2017, 2:35pm UTC](https://discuss.elastic.co/t/parsing-a-keyword-from-message/86434/3 "2017-05-19T14:35:35Z")

</div>

> [@Nico-DF](#):
>
> And in fact, you miss one: before the else statement

Thanks a lot. That was silly 😛

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 16, 2017, 2:35pm UTC](https://discuss.elastic.co/t/parsing-a-keyword-from-message/86434/4 "2017-06-16T14:35:39Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
