# Add field in logstash config

**URL:** <https://discuss.elastic.co/t/add-field-in-logstash-config/25513>\
**Category:** Logstash\
**Created:** [July 14, 2015, 10:56am UTC](https://discuss.elastic.co/t/add-field-in-logstash-config/25513 "2015-07-14T10:56:02Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![Smasell](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/smasell/32/43483_2.png) [@Smasell](https://discuss.elastic.co/u/Smasell)\
**Post date:** [July 14, 2015, 10:56am UTC](https://discuss.elastic.co/t/add-field-in-logstash-config/25513/1 "2015-07-14T10:56:02Z")

</div>

Hi!!!  
I have logs like this:  
GetLoginGata: login: 'G:59423457'; deviceId: 'FF7567DE-8822-4D0F-9E2E-651A202B6B58'  
And I want to get fields with grok filter in my config:  
grok {  
match =\> ["message", " login: %{WORD:login}"]  
tag\_on\_failure =\> []  
}  
grok {  
match =\> ["message", " deviceid: %{WORD:device-id}"]  
tag\_on\_failure =\> []  
}  
But it's didn't come. Where is mistake?

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [July 14, 2015, 11:21am UTC](https://discuss.elastic.co/t/add-field-in-logstash-config/25513/2 "2015-07-14T11:21:16Z")

</div>

There are multiple problems here.

- The device-id string contains hyphens. I don't think WORD matches hyphens.
- There's a single quote on each side of the value and single quotes are also not included in WORD.

You could e.g. use this grok filter:

```
filter {
  grok {
    match => [
      "message",
      "^GetLoginGata: login: '(?<login>[^']+)'; deviceId: '(?<deviceid>[^']+)'"
    ]
  }
}
```

---

<div class="post-metadata">

**Author:** ![Smasell](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/smasell/32/43483_2.png) [@Smasell](https://discuss.elastic.co/u/Smasell)\
**Post date:** [July 14, 2015, 11:49am UTC](https://discuss.elastic.co/t/add-field-in-logstash-config/25513/3 "2015-07-14T11:49:24Z")

</div>

Brilliant, many thanks  
Where I can get more information about syntax in grok filter?  
For example what does it means '(?[^']+)'?

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [July 14, 2015, 12:06pm UTC](https://discuss.elastic.co/t/add-field-in-logstash-config/25513/4 "2015-07-14T12:06:11Z")

</div>

Grok expressions are regular expressions with the addition of `%{PATTERN:variable}` captures. `(?<deviceid>[^']+)` isn't grok-specific but a good old regular expression that means "match and save one or more characters that aren't single quotes into the named capture 'deviceid'".

---

<div class="post-metadata">

**Author:** ![Smasell](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/smasell/32/43483_2.png) [@Smasell](https://discuss.elastic.co/u/Smasell)\
**Post date:** [July 14, 2015, 12:26pm UTC](https://discuss.elastic.co/t/add-field-in-logstash-config/25513/5 "2015-07-14T12:26:31Z")

</div>

@magnusbaeck  
ok, and just for me, if I want to break your code like this:  
grok {  
match =\> ["message", " login: '(?[^']+)' "]  
tag\_on\_failure =\> []  
}

grok {  
match =\> ["message", " deviceId: '(?[^']+)' "]  
tag\_on\_failure =\> []  
}  
fields not coming. Where is mistake here? Sorry for noob questions.

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [July 14, 2015, 12:37pm UTC](https://discuss.elastic.co/t/add-field-in-logstash-config/25513/6 "2015-07-14T12:37:13Z")

</div>

Please make configuration snippets preformatted so that things that look like HTML tags aren't stripped. I'm going to assume your configuration actually says `(?<login>[^']+)` rather than `(?[^']+)`.

I don't know off the top of my head why the above doesn't work and I don't have time to debug it. Why do you want multiple filters?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 5:34am UTC](https://discuss.elastic.co/t/add-field-in-logstash-config/25513/7 "2017-07-06T05:34:49Z")

</div>


