# Regex in filter plugin not working

**URL:** <https://discuss.elastic.co/t/regex-in-filter-plugin-not-working/214641>\
**Category:** Logstash\
**Created:** [January 10, 2020, 5:05pm UTC](https://discuss.elastic.co/t/regex-in-filter-plugin-not-working/214641 "2020-01-10T17:05:12Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![srbhklkrn](https://avatars.discourse-cdn.com/v4/letter/s/e480ec/32.png) [@srbhklkrn](https://discuss.elastic.co/u/srbhklkrn)\
**Post date:** [January 10, 2020, 5:05pm UTC](https://discuss.elastic.co/t/regex-in-filter-plugin-not-working/214641/1 "2020-01-10T17:05:13Z")

</div>

Hello,

I'm trying to tag one host by using `syslog5424_host` but it's not matching anything.

First, can I tag syslog5424\_host? if yes can I use it directly in the output section and forward it to the destination instead of first tagging and then by using tag send it to the destination?

```
filter {
  if [syslog5424_host] = ~ /^sharedservices.prod.authorization-prod(...)/ {
    mutate {
      add_tag => ["Prod_Auth"]
    }
  }
}

```

The string I'm trying to match : `sharedservices.prod.authorization-prod-16`

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [January 10, 2020, 7:23pm UTC](https://discuss.elastic.co/t/regex-in-filter-plugin-not-working/214641/2 "2020-01-10T19:23:16Z")

</div>

Have you tried removing the parentheses around the three periods?

---

<div class="post-metadata">

**Author:** ![srbhklkrn](https://avatars.discourse-cdn.com/v4/letter/s/e480ec/32.png) [@srbhklkrn](https://discuss.elastic.co/u/srbhklkrn)\
**Post date:** [January 10, 2020, 7:25pm UTC](https://discuss.elastic.co/t/regex-in-filter-plugin-not-working/214641/3 "2020-01-10T19:25:07Z")

</div>

Yeah I did

I tried this as well : `^sharedservices.prod.authorization-prod.*` its matching in ruby regex tester but not in logstash

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [January 10, 2020, 7:50pm UTC](https://discuss.elastic.co/t/regex-in-filter-plugin-not-working/214641/4 "2020-01-10T19:50:07Z")

</div>

If you use

```
output { stdout { codec => rubydebug } }

```

what does that field look like?

---

<div class="post-metadata">

**Author:** ![srbhklkrn](https://avatars.discourse-cdn.com/v4/letter/s/e480ec/32.png) [@srbhklkrn](https://discuss.elastic.co/u/srbhklkrn)\
**Post date:** [January 10, 2020, 7:56pm UTC](https://discuss.elastic.co/t/regex-in-filter-plugin-not-working/214641/5 "2020-01-10T19:56:27Z")

</div>

How do I see stdout in terminal?

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [January 10, 2020, 8:21pm UTC](https://discuss.elastic.co/t/regex-in-filter-plugin-not-working/214641/6 "2020-01-10T20:21:25Z")

</div>

If you are running as a service then you could try using a file output with a rubydebug codec.

---

<div class="post-metadata">

**Author:** ![srbhklkrn](https://avatars.discourse-cdn.com/v4/letter/s/e480ec/32.png) [@srbhklkrn](https://discuss.elastic.co/u/srbhklkrn)\
**Post date:** [January 10, 2020, 8:57pm UTC](https://discuss.elastic.co/t/regex-in-filter-plugin-not-working/214641/7 "2020-01-10T20:57:54Z")

</div>

I got it working I was forget to escape period

here is the working regex

`^sharedservices\.prod\.authorization.*`

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [January 10, 2020, 9:22pm UTC](https://discuss.elastic.co/t/regex-in-filter-plugin-not-working/214641/8 "2020-01-10T21:22:23Z")

</div>

But period in a regexp matches anything, including a period. It has to be the change at the end of the regexp that fixed it.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 7, 2020, 9:22pm UTC](https://discuss.elastic.co/t/regex-in-filter-plugin-not-working/214641/9 "2020-02-07T21:22:26Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
