# Add grok filter for costume log data in Filebeat's NGINX module

**URL:** <https://discuss.elastic.co/t/add-grok-filter-for-costume-log-data-in-filebeats-nginx-module/161855>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [December 21, 2018, 1:59pm UTC](https://discuss.elastic.co/t/add-grok-filter-for-costume-log-data-in-filebeats-nginx-module/161855 "2018-12-21T13:59:39Z")\
**Posts on this page:** 1\
**Showing post:** 4

<div class="post-metadata">

**Author:** ![TheNmaptomyHeartBeat](https://avatars.discourse-cdn.com/v4/letter/t/47e85d/32.png) [@TheNmaptomyHeartBeat](https://discuss.elastic.co/u/TheNmaptomyHeartBeat)\
**Post date:** [January 16, 2019, 3:25pm UTC](https://discuss.elastic.co/t/add-grok-filter-for-costume-log-data-in-filebeats-nginx-module/161855/4 "2019-01-16T15:25:58Z")

</div>

Hi Steffens,  
Thanks for assisting me.

I have tried using those tools to get it to work. I removed the original content in `default.json` and replaced it with the following as a test.

```auto
{
  "description": "Pipeline for parsing Tailored Nginx access logs used for TLS.",
  "processors": [{
    "grok": {
      "field": "message",
      "patterns":[
        "%{IP:nginx.access.remote_ip} %{DATA:nginx.access.protocol} %{DATA:nginx.access.cipher} %{WORD:nginx.access.request} / HTTP/%{NUMBER:nginx.access.http_version}"
       ],
      "ignore_missing": true
    }
  }]
}

```

This is the pattern for the costume log formats. When I reloaded the pipeline it worked. the filter broke down the message field.

I have seen in other questions people having [more than one pattern](https://discuss.elastic.co/t/nginx-logs-provided-grok-expressions-do-not-match-field-value/128518/7?u=thenmaptomyheartbeat) in a Filebeat module.

I just can't seem to add the costume log format pattern without it coming up with a syntax error or failing completely.

---

_[View the full topic](https://discuss.elastic.co/t/add-grok-filter-for-costume-log-data-in-filebeats-nginx-module/161855)._
