# Stop proccesing events/lines after first grok match

**URL:** <https://discuss.elastic.co/t/stop-proccesing-events-lines-after-first-grok-match/214696>\
**Category:** Logstash\
**Created:** [January 11, 2020, 8:45am UTC](https://discuss.elastic.co/t/stop-proccesing-events-lines-after-first-grok-match/214696 "2020-01-11T08:45:48Z")\
**Posts on this page:** 1\
**Showing post:** 3

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [January 11, 2020, 4:23pm UTC](https://discuss.elastic.co/t/stop-proccesing-events-lines-after-first-grok-match/214696/3 "2020-01-11T16:23:59Z")

</div>

break\_on\_match controls behaviour when you are matching a field against an array of patterns. If it is set to false then grok will only match the first entry in the array that matches, and ignore subsequent patterns. You only have a single pattern, so it has no effect.

I would suggest [consuming](https://discuss.elastic.co/t/parsing-array-of-json-objects-with-logstash-and-injesting-to-elastic/203197/2) the entire file as a single event. Then run grok against that, or you might need to use ruby to [scan](https://discuss.elastic.co/t/nested-field-in-a-grok-filter/190758/2) the [message] field and pick out the first match from the array of matches that scan returns.

---

_[View the full topic](https://discuss.elastic.co/t/stop-proccesing-events-lines-after-first-grok-match/214696)._
