# Best practice to organize Grok patterns in production

**URL:** <https://discuss.elastic.co/t/best-practice-to-organize-grok-patterns-in-production/36615>\
**Category:** Logstash\
**Created:** [December 8, 2015, 9:35am UTC](https://discuss.elastic.co/t/best-practice-to-organize-grok-patterns-in-production/36615 "2015-12-08T09:35:50Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Krzysztof](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/krzysztof/32/6157_2.png) [@Krzysztof](https://discuss.elastic.co/u/Krzysztof)\
**Post date:** [December 8, 2015, 9:35am UTC](https://discuss.elastic.co/t/best-practice-to-organize-grok-patterns-in-production/36615/1 "2015-12-08T09:35:50Z")

</div>

Hello,

In our system we're progressing with ELK stack usage on a larger scale. We're are about to connect a large amount of systems and almost all of them require a custom Grok pattern for log parsing.  
I'm wondering what is the best practice to organize all this patterns, so that they're easy to maintain.  
Right now my idea look as follows:

1. In a common location like /etc/logstash/patterns I will create a directory for each system - for example /etc/logstash/patterns/system\_xyz

2. In this folder I will create a file "system\_xyz\_pattern", which will store the Grok pattern for that system

3. In logstash config folder I will add a file system\_xyz.conf with the configuration inside:

Is there any way to simplify this? Step #3 seems to be redundant - it does nothing but match the pattern name from Grok file with a filed from an event. Is it possible to to write some generic code to handle this for all systems?

Can you propose any better way to organize hundreds of Grok patterns?

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [December 8, 2015, 11:55am UTC](https://discuss.elastic.co/t/best-practice-to-organize-grok-patterns-in-production/36615/2 "2015-12-08T11:55:59Z")

</div>

Well, if the configuration files are sufficiently similar you could of course write a piece of code to generate the configuration files from whatever form is most convenient for you.

FWIW I've never bothered setting up pattern files. If the stock grok patterns have been insufficient I've just inlined the necessary regexps in the configuration files.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 5:19am UTC](https://discuss.elastic.co/t/best-practice-to-organize-grok-patterns-in-production/36615/3 "2017-07-06T05:19:34Z")

</div>


