# Using logstash, How to filter Errors only from logs?

**URL:** <https://discuss.elastic.co/t/using-logstash-how-to-filter-errors-only-from-logs/43234>\
**Category:** Logstash\
**Created:** [March 2, 2016, 11:32am UTC](https://discuss.elastic.co/t/using-logstash-how-to-filter-errors-only-from-logs/43234 "2016-03-02T11:32:45Z")\
**Posts on this page:** 11\
**Page:** 1

<div class="post-metadata">

**Author:** ![devalkars](https://avatars.discourse-cdn.com/v4/letter/d/e9a140/32.png) [@devalkars](https://discuss.elastic.co/u/devalkars)\
**Post date:** [March 2, 2016, 11:32am UTC](https://discuss.elastic.co/t/using-logstash-how-to-filter-errors-only-from-logs/43234/1 "2016-03-02T11:32:45Z")

</div>

Hi, I am using logstash in our project, How to filter Errors only from logs ?

i am using below configuration:

input {

file {  
path =\> "D:/apache-tomcat-7.0.67/logs/cpe.log"  
start\_position =\> "beginning"  
}  
}

filter {  
grok {  
match =\> { "message" =\> "%{APACHEERRORLOG}" } #it wont worked for me  
}  
}

output {  
elasticsearch {  
hosts =\> ["localhost:9200"]  
}  
stdout { codec =\> rubydebug }  
}

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [March 2, 2016, 6:44pm UTC](https://discuss.elastic.co/t/using-logstash-how-to-filter-errors-only-from-logs/43234/2 "2016-03-02T18:44:24Z")

</div>

> How to filter Errors only from logs ?

It's not clear what this means.

> it wont worked for me

What does this mean? Please be explicit. What's the input? What's the actual result? What's the expected result?

---

<div class="post-metadata">

**Author:** ![devalkars](https://avatars.discourse-cdn.com/v4/letter/d/e9a140/32.png) [@devalkars](https://discuss.elastic.co/u/devalkars)\
**Post date:** [March 3, 2016, 4:25am UTC](https://discuss.elastic.co/t/using-logstash-how-to-filter-errors-only-from-logs/43234/3 "2016-03-03T04:25:18Z")

</div>

> [@magnusbaeck](#):
>
> What's the expected result?

input is log file containing loglevels INFO, ERROR.  
i want logs output to be filtered only ERROR loglevels.  
below configuration results : pattern %{APACHEERRORLOG} not defined  
filter {  
grok {  
match =\> { "message" =\> "%{APACHEERRORLOG}" } #it wont worked for me  
}  
}

what should be configuration so that i can see only ERROR logs filtered in output.

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [March 3, 2016, 6:31am UTC](https://discuss.elastic.co/t/using-logstash-how-to-filter-errors-only-from-logs/43234/4 "2016-03-03T06:31:13Z")

</div>

> input is log file containing loglevels INFO, ERROR.  
> i want logs output to be filtered only ERROR loglevels.

Either wrap the output in a conditional that look at the field containing the log level,

```auto
if [level] == "ERROR" {
  output {
     ...
  }
}

```

or use a similar conditional that wraps the drop filter (which deletes the current event). See [Accessing event data and fields | Logstash Reference [8.11] | Elastic](https://www.elastic.co/guide/en/logstash/current/event-dependent-configuration.html).

> below configuration results : pattern %{APACHEERRORLOG} not defined

AFAICT Logstash doesn't ship with pattern with that name. I don't know where you got that pattern name from. However, it _does_ ship with a few other patterns that might be useful to you:

> <https://github.com/logstash-plugins/logstash-patterns-core/blob/v2.0.2/patterns/grok-patterns#L95-L97>

---

<div class="post-metadata">

**Author:** ![devalkars](https://avatars.discourse-cdn.com/v4/letter/d/e9a140/32.png) [@devalkars](https://discuss.elastic.co/u/devalkars)\
**Post date:** [March 3, 2016, 9:28am UTC](https://discuss.elastic.co/t/using-logstash-how-to-filter-errors-only-from-logs/43234/5 "2016-03-03T09:28:43Z")

</div>

Thanks this solved my problem.

---

<div class="post-metadata">

**Author:** ![baha1](https://avatars.discourse-cdn.com/v4/letter/b/b77776/32.png) [@baha1](https://discuss.elastic.co/u/baha1)\
**Post date:** [June 7, 2017, 1:48pm UTC](https://discuss.elastic.co/t/using-logstash-how-to-filter-errors-only-from-logs/43234/6 "2017-06-07T13:48:11Z")

</div>

Hi community,  
i have a log like :`17:37:17,103 ERROR [org.apache.catalina.core.ContainerBase.[jboss.web].[default-host].....rest of text.`  
what is the convenient grok to filter that.  
Any help is appreciate.

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [June 7, 2017, 1:57pm UTC](https://discuss.elastic.co/t/using-logstash-how-to-filter-errors-only-from-logs/43234/7 "2017-06-07T13:57:49Z")

</div>

@baha1, please start a new thread for your unrelated question.

---

<div class="post-metadata">

**Author:** ![baha1](https://avatars.discourse-cdn.com/v4/letter/b/b77776/32.png) [@baha1](https://discuss.elastic.co/u/baha1)\
**Post date:** [June 7, 2017, 2:31pm UTC](https://discuss.elastic.co/t/using-logstash-how-to-filter-errors-only-from-logs/43234/8 "2017-06-07T14:31:58Z")

</div>

thank you for answering,this is the link of the new thread.

> [@How to filter only error from log file](https://discuss.elastic.co/t/how-to-filter-only-error-from-log-file/88591):
>
> Hi community, i have a log file contains INFO,WARN and ERROR like : 17:37:17,103 ERROR [org.apache.catalina.core.ContainerBase.[jboss.web].[default-host].....rest of text. what is the convenient grok to filter only All errors. Thanks for any help.

---

<div class="post-metadata">

**Author:** ![naga\_kunchala](https://avatars.discourse-cdn.com/v4/letter/n/d9b06d/32.png) [@naga\_kunchala](https://discuss.elastic.co/u/naga_kunchala)\
**Post date:** [July 25, 2018, 10:41am UTC](https://discuss.elastic.co/t/using-logstash-how-to-filter-errors-only-from-logs/43234/9 "2018-07-25T10:41:04Z")

</div>

i am also have same issue. i want save the only errors in formation for that which filter i need to use

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [July 25, 2018, 11:56am UTC](https://discuss.elastic.co/t/using-logstash-how-to-filter-errors-only-from-logs/43234/10 "2018-07-25T11:56:22Z")

</div>

> i am also have same issue. i want save the only errors in formation for that which filter i need to use

Then start a new thread (topic) for your question, and include more details about your configuration and your requirements. The more specific question you ask the more specific and exact replies you'll get.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 4, 2022, 4:15am UTC](https://discuss.elastic.co/t/using-logstash-how-to-filter-errors-only-from-logs/43234/11 "2022-11-04T04:15:39Z")

</div>


