# Beginner question grok + pattern matching + different line format

**URL:** <https://discuss.elastic.co/t/beginner-question-grok-pattern-matching-different-line-format/85974>\
**Category:** Logstash\
**Created:** [May 16, 2017, 3:51pm UTC](https://discuss.elastic.co/t/beginner-question-grok-pattern-matching-different-line-format/85974 "2017-05-16T15:51:54Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Goudal](https://avatars.discourse-cdn.com/v4/letter/g/cc9497/32.png) [@Goudal](https://discuss.elastic.co/u/Goudal)\
**Post date:** [May 16, 2017, 3:51pm UTC](https://discuss.elastic.co/t/beginner-question-grok-pattern-matching-different-line-format/85974/1 "2017-05-16T15:51:54Z")

</div>

Hello,  
I'm new to elk and I'm trying to figure out how the grok match keyword works.  
What I wonder is if I want to parse different line format, do I have to put multiple grok filters one after the other one and the first match that is ok will be used ? Or do I have to first filter my line format with a test and than apply a match keyword ?  
In other word does match work as a pattern-matching selector or not ?

My aim is to analyse logs from different applications which have very different formats,

THanks in advance.

---

<div class="post-metadata">

**Author:** ![Nico-DF](https://avatars.discourse-cdn.com/v4/letter/n/ed8c4c/32.png) [@Nico-DF](https://discuss.elastic.co/u/Nico-DF)\
**Post date:** [May 17, 2017, 7:08am UTC](https://discuss.elastic.co/t/beginner-question-grok-pattern-matching-different-line-format/85974/2 "2017-05-17T07:08:55Z")

</div>

What you can do is the following:  
Image you have 3 different patterns:

```auto
filter{
  if ("SUCCESS" not in [tags]) {
    grok{
      match => {"message" => "PATTERN1"}

      add_tag => ["SUCCESS"]
      remove_tag => ["_grokparsefailure"]
  }

  if ("SUCCESS" not in [tags]) {
    grok{
      match => {"message" => "PATTERN2"}

      add_tag => ["SUCCESS"]
      remove_tag => ["_grokparsefailure"]
  }

  if ("SUCCESS" not in [tags]) {
    grok{
      match => {"message" => "PATTERN3"}

      add_tag => ["SUCCESS"]
      remove_tag => ["_grokparsefailure"]
  }
}

```

And then in ouput, only push if the message does not have a \_grokparsefailure tag.

It might also be possible to do this by using multiple patterns in one grok filter and by setting break\_on\_match (or something like that) to true. But as I don't use it, I cannot guide you for this method. (I personnaly prefer splitting them, it's longer, but easier to read and to split them into multiple .conf files)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 14, 2017, 7:09am UTC](https://discuss.elastic.co/t/beginner-question-grok-pattern-matching-different-line-format/85974/3 "2017-06-14T07:09:44Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
