# Usage of "or" operator in logstash grok filters

**URL:** <https://discuss.elastic.co/t/usage-of-or-operator-in-logstash-grok-filters/197132>\
**Category:** Logstash\
**Created:** [August 28, 2019, 2:07pm UTC](https://discuss.elastic.co/t/usage-of-or-operator-in-logstash-grok-filters/197132 "2019-08-28T14:07:07Z")\
**Posts on this page:** 12\
**Page:** 1

<div class="post-metadata">

**Author:** ![naveenrt23](https://avatars.discourse-cdn.com/v4/letter/n/47e85d/32.png) [@naveenrt23](https://discuss.elastic.co/u/naveenrt23)\
**Post date:** [August 28, 2019, 2:07pm UTC](https://discuss.elastic.co/t/usage-of-or-operator-in-logstash-grok-filters/197132/1 "2019-08-28T14:07:07Z")

</div>

Hello,

I have a condition to check if the 7th-word matches either /list/ or /list or /simple/ or /simple using below condition

`[@metadata][copyOfMessage][6] =~ /^\/list\// or /^\/list/ or /^\/simple\// or /^\/simple/`

This is not working because all the requests are passing through this condition. Is there a different way to check this?

---

<div class="post-metadata">

**Author:** ![Thiago\_Paiva](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/thiago_paiva/32/52326_2.png) [@Thiago\_Paiva](https://discuss.elastic.co/u/Thiago_Paiva)\
**Post date:** [August 28, 2019, 2:16pm UTC](https://discuss.elastic.co/t/usage-of-or-operator-in-logstash-grok-filters/197132/2 "2019-08-28T14:16:42Z")

</div>

> [@naveenrt23](#):
>
> a condition to check if the 7th-word matches either /list/ or /list or /simple/ or /simple using below condition

Try use (|)

`((/^\/list\// | /^\/list/ | /^\/simple\// | /^\/simple/)`

In my pipiline ai used in gsub:

`(^\t|Processing Request,\s|Invoke Action,\s|Check Row,\s|Row in violation,\s|\s+seconds)`

att

---

<div class="post-metadata">

**Author:** ![naveenrt23](https://avatars.discourse-cdn.com/v4/letter/n/47e85d/32.png) [@naveenrt23](https://discuss.elastic.co/u/naveenrt23)\
**Post date:** [August 28, 2019, 2:19pm UTC](https://discuss.elastic.co/t/usage-of-or-operator-in-logstash-grok-filters/197132/3 "2019-08-28T14:19:46Z")

</div>

I've tried this  
`elseif [@metadata][copyOfMessage][6] =~ (/^\/list\// | /^\/list/ | /^\/simple\// | /^\/simple/)` but it gives me syntax error

---

<div class="post-metadata">

**Author:** ![Thiago\_Paiva](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/thiago_paiva/32/52326_2.png) [@Thiago\_Paiva](https://discuss.elastic.co/u/Thiago_Paiva)\
**Post date:** [August 28, 2019, 2:35pm UTC](https://discuss.elastic.co/t/usage-of-or-operator-in-logstash-grok-filters/197132/4 "2019-08-28T14:35:27Z")

</div>

> [@naveenrt23](#):
>
> list

I thing that is resolve:

`((^/list/|^/list)|(^/simple/|^/simple))`

---

<div class="post-metadata">

**Author:** ![naveenrt23](https://avatars.discourse-cdn.com/v4/letter/n/47e85d/32.png) [@naveenrt23](https://discuss.elastic.co/u/naveenrt23)\
**Post date:** [August 28, 2019, 2:39pm UTC](https://discuss.elastic.co/t/usage-of-or-operator-in-logstash-grok-filters/197132/5 "2019-08-28T14:39:09Z")

</div>

I've got the same syntax error

`Failed to execute action {:id=>:main, :action_type=>LogStash::ConvergeResult::FailedAction, :message=>"Expected one of #, \", ', / at line 31, column 47 (byte 995) after filter {\n # Create a copy of original message\n mutate {\n add_field => {\n \"[@metadata][copyOfMessage]\" => \"%{[message]}\"\n }\n }\n # split message\n mutate {\n split => {\n \"[@metadata][copyOfMessage]\" => \"|\"\n }\n }\n grok {\n break_on_match => false\n`

```
  elseif [@metadata][copyOfMessage][6] =~ ((^/list/|^/list)|(^/simple/|^/simple)) {
```

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [August 28, 2019, 2:54pm UTC](https://discuss.elastic.co/t/usage-of-or-operator-in-logstash-grok-filters/197132/6 "2019-08-28T14:54:19Z")

</div>

Surround the regexp with / and /

---

<div class="post-metadata">

**Author:** ![naveenrt23](https://avatars.discourse-cdn.com/v4/letter/n/47e85d/32.png) [@naveenrt23](https://discuss.elastic.co/u/naveenrt23)\
**Post date:** [August 28, 2019, 3:04pm UTC](https://discuss.elastic.co/t/usage-of-or-operator-in-logstash-grok-filters/197132/7 "2019-08-28T15:04:32Z")

</div>

I've tried testing with

/(/^/list// or /^/list/ or /^/simple// or /^/simple/)/  
/((^/list/|^/list)|(^/simple/|^/simple))/

and it has syntax errors. Is this what you suggested to try?

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [August 28, 2019, 3:16pm UTC](https://discuss.elastic.co/t/usage-of-or-operator-in-logstash-grok-filters/197132/8 "2019-08-28T15:16:32Z")

</div>

> [@naveenrt23](#):
>
> Is this what you suggested to try?

Yes. Does this work for you?...

```
/^\/(list|simple)($|\/)/

```

---

<div class="post-metadata">

**Author:** ![naveenrt23](https://avatars.discourse-cdn.com/v4/letter/n/47e85d/32.png) [@naveenrt23](https://discuss.elastic.co/u/naveenrt23)\
**Post date:** [August 28, 2019, 3:20pm UTC](https://discuss.elastic.co/t/usage-of-or-operator-in-logstash-grok-filters/197132/9 "2019-08-28T15:20:58Z")

</div>

Yes sir. Thank you!

---

<div class="post-metadata">

**Author:** ![Thiago\_Paiva](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/thiago_paiva/32/52326_2.png) [@Thiago\_Paiva](https://discuss.elastic.co/u/Thiago_Paiva)\
**Post date:** [August 28, 2019, 4:46pm UTC](https://discuss.elastic.co/t/usage-of-or-operator-in-logstash-grok-filters/197132/10 "2019-08-28T16:46:52Z")

</div>

Sir,

After @Badger give me helps, I found a good website that helps with regexp in ruby:  
[https://rubular.com](https://rubular.com/)

Maybe will help you in next.

---

<div class="post-metadata">

**Author:** ![naveenrt23](https://avatars.discourse-cdn.com/v4/letter/n/47e85d/32.png) [@naveenrt23](https://discuss.elastic.co/u/naveenrt23)\
**Post date:** [August 28, 2019, 5:31pm UTC](https://discuss.elastic.co/t/usage-of-or-operator-in-logstash-grok-filters/197132/11 "2019-08-28T17:31:18Z")

</div>

Thank you! @Thiago_Paiva

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 25, 2019, 5:31pm UTC](https://discuss.elastic.co/t/usage-of-or-operator-in-logstash-grok-filters/197132/12 "2019-09-25T17:31:19Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
