# Problem with if statement in GROK filter

**URL:** <https://discuss.elastic.co/t/problem-with-if-statement-in-grok-filter/282466>\
**Category:** Logstash\
**Created:** [August 25, 2021, 9:24am UTC](https://discuss.elastic.co/t/problem-with-if-statement-in-grok-filter/282466 "2021-08-25T09:24:31Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![vp096](https://avatars.discourse-cdn.com/v4/letter/v/da6949/32.png) [@vp096](https://discuss.elastic.co/u/vp096)\
**Post date:** [August 25, 2021, 9:24am UTC](https://discuss.elastic.co/t/problem-with-if-statement-in-grok-filter/282466/1 "2021-08-25T09:24:31Z")

</div>

Hello,

I send syslog data from a WiFi controller to ElasticSearch. This controller sends me different types of packets and I want to keep only the packets of this type:

```auto
Aug 25 11:19:50 2021 MC72-WI-AS1-06-B authmgr[3647]: <124006> <3647> <WARN> <MC72-WI-AS1-06-B 172.20.10.11> {10069} TCP srcip=172.20.40.39 srcport=65178 dstip=87.117.121.3 dstport=443, action=permit, role=guest, policy=_syslog

```

So I made a filter as follows:

```auto
#Filtering data using grok parser
filter
{
        if [type] == "wifilogs" 
        {
            if "policy=_syslog" in [message]
            {
                grok 
                {    
                    match => { "message" => "(?<timestamp>%{MONTH} +%{MONTHDAY} %{TIME} %{YEAR}) %{HOSTNAME:ControllerName} %{NOTSPACE} %{NOTSPACE} %{NOTSPACE} %{NOTSPACE} (<%{NOTSPACE} %{IP:IPController}>|%{NOTSPACE}) %{NOTSPACE} %{NOTSPACE} %{NOTSPACE:Protocol} srcip=%{IP:srcIP} srcport=%{NOTSPACE:srcPort} dstip=%{NOTSPACE:destIP} dstport=%{NOTSPACE:dstPort}, action=%{NOTSPACE:action}, role=%{NOTSPACE:role}, policy=%{NOTSPACE:ArubaPolicy}"}
                }
            }
        }
}

```

The grok filter works well ! No problem with that.  
But I find that this filter does not work, because it still sends all packets to logstash. How can I keep only the packets that contain "policy=\_syslog"?

Thanks in advance for your help.

---

<div class="post-metadata">

**Author:** ![Cad](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/cad/32/86661_2.png) [@Cad](https://discuss.elastic.co/u/Cad)\
**Post date:** [August 25, 2021, 11:02am UTC](https://discuss.elastic.co/t/problem-with-if-statement-in-grok-filter/282466/2 "2021-08-25T11:02:23Z")

</div>

Hi,

One possibilty is to product a grok pattern who recognised only syslog message. So for all other, it gonna product the `tag` `_grokparsefailure` so you can use this in a if expression in your output.

```auto
filter
{
    if [type] == "wifilogs" 
    {
#I edit the grok pattern, look a the end of it
        grok 
        {    
            match => { "message" => "(?<timestamp>%{MONTH} +%{MONTHDAY} %{TIME} %{YEAR}) %{HOSTNAME:ControllerName} %{NOTSPACE} %{NOTSPACE} %{NOTSPACE} %{NOTSPACE} (<%{NOTSPACE} %{IP:IPController}>|%{NOTSPACE}) %{NOTSPACE} %{NOTSPACE} %{NOTSPACE:Protocol} srcip=%{IP:srcIP} srcport=%{NOTSPACE:srcPort} dstip=%{NOTSPACE:destIP} dstport=%{NOTSPACE:dstPort}, action=%{NOTSPACE:action}, role=%{NOTSPACE:role}, policy=_syslog"}
        }  
   }
}

output {
  if "_grokparsefailure" not in [tags] {
    elasticsearch {...}
  }
}

```

---

<div class="post-metadata">

**Author:** ![aaron-nimocks](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/aaron-nimocks/32/73965_2.png) [@aaron-nimocks](https://discuss.elastic.co/u/aaron-nimocks)\
**Post date:** [August 25, 2021, 11:07am UTC](https://discuss.elastic.co/t/problem-with-if-statement-in-grok-filter/282466/3 "2021-08-25T11:07:57Z")

</div>

Think this is what you are trying to do. If policy = syslog then grok. If not then drop the message.

```auto
#Filtering data using grok parser
filter
{
        if [type] == "wifilogs" 
        {
            if "policy=_syslog" in [message]
            {
                grok 
                {    
                    match => { "message" => "(?<timestamp>%{MONTH} +%{MONTHDAY} %{TIME} %{YEAR}) %{HOSTNAME:ControllerName} %{NOTSPACE} %{NOTSPACE} %{NOTSPACE} %{NOTSPACE} (<%{NOTSPACE} %{IP:IPController}>|%{NOTSPACE}) %{NOTSPACE} %{NOTSPACE} %{NOTSPACE:Protocol} srcip=%{IP:srcIP} srcport=%{NOTSPACE:srcPort} dstip=%{NOTSPACE:destIP} dstport=%{NOTSPACE:dstPort}, action=%{NOTSPACE:action}, role=%{NOTSPACE:role}, policy=%{NOTSPACE:ArubaPolicy}"}
                }
            } else {
               drop { }
            }
        }
}

```

---

<div class="post-metadata">

**Author:** ![vp096](https://avatars.discourse-cdn.com/v4/letter/v/da6949/32.png) [@vp096](https://discuss.elastic.co/u/vp096)\
**Post date:** [August 25, 2021, 11:20am UTC](https://discuss.elastic.co/t/problem-with-if-statement-in-grok-filter/282466/4 "2021-08-25T11:20:04Z")

</div>

Thanks for your help @Cad and @aaron-nimocks.

It's now working for me.

It works for me.

I would like to take this opportunity for a second question. I have to eat this kind of logs with grok :

```auto
2021-08-25 11:06:07,366 172.30.20.244 Syslog 1 1 0 Radius.Username=grs7yq5j,Radius.Framed-IP-Address=172.20.40.92,Radius.Start-Time=2021-08-25 11:03:43+02,Radius.End-Time=2021-08-25 11:03:51+02,Radius.Duration=8

```

Which GROK synthaxis should I use to catch the structured timestamp in this way?

I try something like this, but it doesn't work :

```auto
(?<timestamp>%{YEAR} -%{MONTHDAY} -%{DAY} %{TIME} )

```

Thanks in advance for your help!

---

<div class="post-metadata">

**Author:** ![vp096](https://avatars.discourse-cdn.com/v4/letter/v/da6949/32.png) [@vp096](https://discuss.elastic.co/u/vp096)\
**Post date:** [August 25, 2021, 11:27am UTC](https://discuss.elastic.co/t/problem-with-if-statement-in-grok-filter/282466/5 "2021-08-25T11:27:13Z")

</div>

Il finally find the solution : 😃

```auto
%{TIMESTAMP_ISO8601:timestamp}

```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 22, 2021, 11:28am UTC](https://discuss.elastic.co/t/problem-with-if-statement-in-grok-filter/282466/6 "2021-09-22T11:28:11Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
