# A few questions about grok

**URL:** <https://discuss.elastic.co/t/a-few-questions-about-grok/195237>\
**Category:** Logstash\
**Created:** [August 14, 2019, 4:10pm UTC](https://discuss.elastic.co/t/a-few-questions-about-grok/195237 "2019-08-14T16:10:18Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![thedraketaylor](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/thedraketaylor/32/52283_2.png) [@thedraketaylor](https://discuss.elastic.co/u/thedraketaylor)\
**Post date:** [August 14, 2019, 4:10pm UTC](https://discuss.elastic.co/t/a-few-questions-about-grok/195237/1 "2019-08-14T16:10:18Z")

</div>

_ **EDIT** _  
It looks like my formatting got blown out so all my config changes are now in pastebin in a hopefully easier to read format at [https://pastebin.com/DJ0FawPp](https://pastebin.com/DJ0FawPp)  
_ **End Edit** _

I'm trying to use logstash to parse scrapy logs. My logstash config is as follows:  
_see first config in pastebin link_

This works great and outputs (among other lines) this: (See pastebin)

Now, I also want to get the response code, url and the json entry contained in the new 'message' in the above, so I change my conf filter to the new one in the pastebin

and add a file in /vagrant/patterns that contains this:  
CODE [0-9]{3}  
URL http[s]?://.\*  
JITEM {.\*}

I have checked the above in grok debugger, and it yields the expected results, but running it in logstash does not display the new response code, url, or jitem fields. Is there something wrong with the way I'm doing things? Is there something I have to do to get the new entries to show up?

Thanks

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [August 14, 2019, 4:34pm UTC](https://discuss.elastic.co/t/a-few-questions-about-grok/195237/2 "2019-08-14T16:34:10Z")

</div>

Do not try to match a newline with \n, use a literal newline in the grok pattern.

```
match => { "message" => "<%{CODE} %{URL}>
%{JITEM}" }
```

---

<div class="post-metadata">

**Author:** ![thedraketaylor](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/thedraketaylor/32/52283_2.png) [@thedraketaylor](https://discuss.elastic.co/u/thedraketaylor)\
**Post date:** [August 14, 2019, 5:21pm UTC](https://discuss.elastic.co/t/a-few-questions-about-grok/195237/3 "2019-08-14T17:21:30Z")

</div>

Thanks, but when I try that I get a "\_grokparsefailure" error

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [August 14, 2019, 7:12pm UTC](https://discuss.elastic.co/t/a-few-questions-about-grok/195237/4 "2019-08-14T19:12:38Z")

</div>

You haven't name the fields to be captured.

```
input { generator { count => 1 lines => [''] } }
filter {
    mutate { add_field => { "someField" => "Scraped from <200 https://example.com/new_posts>
{'link': 'https://example.com//3g67o/post/hjg78g78t',
 'image': 'https://cdnthumb2.example.com/liuh89/ios.jpg'}" } }

    grok {
        pattern_definitions => {
            "CODE" => "[0-9]{3}"
            "URL" => "http[s]?://.*"
            "JITEM" => "{.*}"
        }
        match => { "someField" => "<%{CODE:code} %{URL:url}>
%{JITEM:jitem}" }
    }
}

```

results in

```
      "code" => "200",
       "url" => "https://example.com/new_posts",
     "jitem" => "{'link': 'https://example.com//3g67o/post/hjg78g78t',\n 'image': 'https://cdnthumb2.example.com/liuh89/ios.jpg'}"
```

---

<div class="post-metadata">

**Author:** ![thedraketaylor](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/thedraketaylor/32/52283_2.png) [@thedraketaylor](https://discuss.elastic.co/u/thedraketaylor)\
**Post date:** [August 15, 2019, 12:26am UTC](https://discuss.elastic.co/t/a-few-questions-about-grok/195237/5 "2019-08-15T00:26:30Z")

</div>

That was it! Thank you my friend!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 12, 2019, 12:26am UTC](https://discuss.elastic.co/t/a-few-questions-about-grok/195237/6 "2019-09-12T00:26:38Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
