# Assistance with Grok and regex

**URL:** <https://discuss.elastic.co/t/assistance-with-grok-and-regex/309600>\
**Category:** Logstash\
**Created:** [July 14, 2022, 3:52am UTC](https://discuss.elastic.co/t/assistance-with-grok-and-regex/309600 "2022-07-14T03:52:38Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![JeremyP](https://avatars.discourse-cdn.com/v4/letter/j/43a26b/32.png) [@JeremyP](https://discuss.elastic.co/u/JeremyP)\
**Post date:** [July 14, 2022, 3:52am UTC](https://discuss.elastic.co/t/assistance-with-grok-and-regex/309600/1 "2022-07-14T03:52:38Z")

</div>

Hello,

I'm attempting to pull the name of a software package from a CPE from NIST. This is my sample data:

```auto
cpe:2.3:a:libexpat_project:libexpat:*:*:*:*:*:*:*:*

```

With regular regex the following expression matches the string between the 4th and 5th colon just fine, however, using Grok within Logstash using the round brackets it unfortunately no longer matches what I want. From all the examples I've seen, round brackets are required.

Code:

```auto
grok {
  match => { "[software][cpe]" => "(?<[software][name]>^(?:[^:]+:){4}\K[^:]+)"
}

```

Output:

```auto
{
  "[software][name]": "cpe:2.3:a:libexpat_project:libexpat"
}

```

Desired Output:

```auto
{
  "[software][name]": "libexpat"
}

```

I'd appreciate some guidance.

Thanks.

---

<div class="post-metadata">

**Author:** ![JeremyP](https://avatars.discourse-cdn.com/v4/letter/j/43a26b/32.png) [@JeremyP](https://discuss.elastic.co/u/JeremyP)\
**Post date:** [July 14, 2022, 2:48pm UTC](https://discuss.elastic.co/t/assistance-with-grok-and-regex/309600/2 "2022-07-14T14:48:22Z")

</div>

It's possible I've answered my own question....

```auto
%{WORD}[:]%{BASE10NUM}[:]%{WORD}[:]%{WORD}[:]%{WORD:[software][name]}

```

---

<div class="post-metadata">

**Author:** ![Rios](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rios/32/95745_2.png) [@Rios](https://discuss.elastic.co/u/Rios)\
**Post date:** [July 15, 2022, 7:00am UTC](https://discuss.elastic.co/t/assistance-with-grok-and-regex/309600/3 "2022-07-15T07:00:18Z")

</div>

You can use CSV plugin as well, separator ":"

If you want to have only "libexpat" from the field "libexpat\_project" you can use:

- split by \_ and use the firstpart, if you don't know what is behind underscore
- gsub and replace "\_project" with "", if you know what is behind underscore

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 12, 2022, 7:00am UTC](https://discuss.elastic.co/t/assistance-with-grok-and-regex/309600/4 "2022-08-12T07:00:27Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
