# Best way to right grok filters

**URL:** https://discuss.elastic.co/t/best-way-to-right-grok-filters/181676
**Category:** Logstash
**Created:** [May 18, 2019, 9:28am UTC](https://discuss.elastic.co/t/best-way-to-right-grok-filters/181676 "2019-05-18T09:28:00Z")
**Posts on this page:** 3
**Page:** 1

<div class="post-metadata">

### Author: ![nuwancs](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nuwancs/32/46419_2.png) [@nuwancs](https://discuss.elastic.co/u/nuwancs)
#### Post date: [May 18, 2019, 9:28am UTC](https://discuss.elastic.co/t/best-way-to-right-grok-filters/181676/1 "2019-05-18T09:28:01Z")

</div>

Hi all,  
We can use two approaches to right a grok filter as follows. My concern is what is the best approach performance wise?

1st Approach  
Having a single grok for all the variables

> grok {  
> match =\> { "message" =\> "[%{TIMESTAMP\_ISO8601:timestamp}] %{LOGLEVEL:level}}  
> }

2nd Approach  
Having separate grok filters per variable

> grok {  
> match =\> { "message" =\> "[%{TIMESTAMP\_ISO8601:timestamp}] }  
> }

> grok {  
> match =\> { "message" =\> "%{LOGLEVEL:level}}  
> }

---

<div class="post-metadata">

### Author: ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)
#### Post date: [May 18, 2019, 11:05am UTC](https://discuss.elastic.co/t/best-way-to-right-grok-filters/181676/2 "2019-05-18T11:05:44Z")

</div>

> [@nuwancs](#):
>
> My concern is what is the best approach performance wise?

The first approach will result in less back-tracking and be more efficient.

Also, [anchor](https://www.elastic.co/blog/do-you-grok-grok) your patterns whenever possible.

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [June 15, 2019, 11:05am UTC](https://discuss.elastic.co/t/best-way-to-right-grok-filters/181676/3 "2019-06-15T11:05:46Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
