# Where the conditional goes?

**URL:** <https://discuss.elastic.co/t/where-the-conditional-goes/208960>\
**Category:** Logstash\
**Created:** [November 21, 2019, 6:14pm UTC](https://discuss.elastic.co/t/where-the-conditional-goes/208960 "2019-11-21T18:14:04Z")\
**Posts on this page:** 11\
**Page:** 1

<div class="post-metadata">

**Author:** ![Incauto](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/incauto/32/60149_2.png) [@Incauto](https://discuss.elastic.co/u/Incauto)\
**Post date:** [November 21, 2019, 6:14pm UTC](https://discuss.elastic.co/t/where-the-conditional-goes/208960/1 "2019-11-21T18:14:05Z")

</div>

where in the file a conditional that check if a field contains certain string, and if contains it, drop the log, goes?

it goes after the grok? it contains the grok? it goes in the output?

The following code doesnt work...where the conditional goes?

```
filter {

    grok {
            match => { "message" => "%{DATA:server}\s%{NUMBER:swap_space_use}" }
    }
    if [server] == "error" {
            drop {}
    }
}
otuput{
...
}
```

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [November 21, 2019, 6:19pm UTC](https://discuss.elastic.co/t/where-the-conditional-goes/208960/2 "2019-11-21T18:19:43Z")

</div>

> [@Incauto](#):
>
> ```
> grok { match => { "message" => "%{DATA:server}\s%{NUMBER:swap_space_use}" } }
> if [server] == "error" { drop {} }
> 
> ```

That looks right. In what way does it not work?

---

<div class="post-metadata">

**Author:** ![Incauto](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/incauto/32/60149_2.png) [@Incauto](https://discuss.elastic.co/u/Incauto)\
**Post date:** [November 21, 2019, 6:27pm UTC](https://discuss.elastic.co/t/where-the-conditional-goes/208960/3 "2019-11-21T18:27:00Z")

</div>

Hi again Badger...when ever a log doesnt match the grok I send the error to a file, and Im still getting log lines with the "error" string in the server field in that file, with the drop the log should not appears in my errors file, or am i wrong?

```
output{

    if "_grokparsefailure" in [tags] {

            file {
                    path => "/tmp/memoria_sw-warning.txt"
            }
    }

```

}

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [November 21, 2019, 6:30pm UTC](https://discuss.elastic.co/t/where-the-conditional-goes/208960/4 "2019-11-21T18:30:38Z")

</div>

If that grok fails then the server field will not exist.

---

<div class="post-metadata">

**Author:** ![Incauto](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/incauto/32/60149_2.png) [@Incauto](https://discuss.elastic.co/u/Incauto)\
**Post date:** [November 21, 2019, 6:43pm UTC](https://discuss.elastic.co/t/where-the-conditional-goes/208960/5 "2019-11-21T18:43:52Z")

</div>

if the server field didnt exist, it wouldnt be shown in the errors file that is created when a grok parse failure happens, and its there in the message.

Im confused.

by the way there is other fields that I excluded from the example to simplify it.

part of my error file  
 ![image](https://us1.discourse-cdn.com/elastic/original/3X/3/4/34df0c35b3444449591f82a2d3587ad714ae2aee.png)

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [November 21, 2019, 6:50pm UTC](https://discuss.elastic.co/t/where-the-conditional-goes/208960/6 "2019-11-21T18:50:55Z")

</div>

That shows that the message field contains the word error. It does not show that the event contains a field called server.

---

<div class="post-metadata">

**Author:** ![Incauto](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/incauto/32/60149_2.png) [@Incauto](https://discuss.elastic.co/u/Incauto)\
**Post date:** [November 21, 2019, 7:34pm UTC](https://discuss.elastic.co/t/where-the-conditional-goes/208960/7 "2019-11-21T19:34:11Z")

</div>

Mind blown....So the field "server" is not created because the parse error?

The field that is provoking the parse error expect a number, but is getting a number with a colon in beetween _ex: 23:2233_ (I check that with the original log)

I have that field like this: (%{NUMBER:name})? so whenever the value doesn´t match with the type, that field doesnt exist anymore, then the grok parse failure should go away....but still is giving me the parse error.

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [November 21, 2019, 7:42pm UTC](https://discuss.elastic.co/t/where-the-conditional-goes/208960/8 "2019-11-21T19:42:24Z")

</div>

> [@Incauto](#):
>
> So the field "server" is not created because the parse error?

If grok is unable to parse any part of the pattern then it creates no fields and adds a \_grokparsefailure tag.

---

<div class="post-metadata">

**Author:** ![Incauto](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/incauto/32/60149_2.png) [@Incauto](https://discuss.elastic.co/u/Incauto)\
**Post date:** [November 21, 2019, 8:00pm UTC](https://discuss.elastic.co/t/where-the-conditional-goes/208960/9 "2019-11-21T20:00:15Z")

</div>

Hey man you had been very pacient, and I dont want to take your time anymore, so my last doubt, in another conf I have this

```
grok {
            match => {"message" => "%{TIME:hora}\s%{DATA:fecha}\s%{DATA:status}\s%{DATA:server}\s(%{NUMBER:segundos})?"}
    }

    if !([segundos]) {
             mutate {
                        add_field => {"segundos" => "0"}
                }
    }

```

Whenever a non numeric value is in the "segundos" field, only that field is not included, but the rest of fields are created. (the oppsite of what you say) thats why later I check and add the segundos field if it is not present, and it works....

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [November 21, 2019, 8:07pm UTC](https://discuss.elastic.co/t/where-the-conditional-goes/208960/10 "2019-11-21T20:07:42Z")

</div>

In that pattern you have made the last field optional using ()?, so the pattern does match.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 19, 2019, 8:07pm UTC](https://discuss.elastic.co/t/where-the-conditional-goes/208960/11 "2019-12-19T20:07:44Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
