# Can I get a specific part of the referrer in the nginx log when parsing it via logstash

**URL:** <https://discuss.elastic.co/t/can-i-get-a-specific-part-of-the-referrer-in-the-nginx-log-when-parsing-it-via-logstash/269865>\
**Category:** Logstash\
**Created:** [April 12, 2021, 10:50am UTC](https://discuss.elastic.co/t/can-i-get-a-specific-part-of-the-referrer-in-the-nginx-log-when-parsing-it-via-logstash/269865 "2021-04-12T10:50:39Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![pradeep\_gadkari](https://avatars.discourse-cdn.com/v4/letter/p/a6a055/32.png) [@pradeep\_gadkari](https://discuss.elastic.co/u/pradeep_gadkari)\
**Post date:** [April 12, 2021, 10:50am UTC](https://discuss.elastic.co/t/can-i-get-a-specific-part-of-the-referrer-in-the-nginx-log-when-parsing-it-via-logstash/269865/1 "2021-04-12T10:50:39Z")

</div>

My grok pattern is as below:

```auto
 grok{
			match => {
			"message" => ["%{IPV4:IP_address} (?:-|(%{WORD}.%{WORD})) %{USER:ident} \[%{HTTPDATE:message_timestamp}\] \"(?:%{WORD:message_type} %{NOTSPACE:request}(?: HTTP/%{NUMBER:httpversion})?|%{DATA:rawrequest})\" %{NUMBER:response} (?:%{NUMBER:bytes}|-) %{QS:referrer} %{QS:agent} %{QS:forwarder}"]
		
			}
		}

```

Example log:

XXX.XXX.XXX.XX - - [17/Feb/2021:13:20:56 +0000] "GET /secure/useravatar?size=small&avatarId=10123 HTTP/1.1" 200 655 "[https://jira.xx.io/browse/MINAUTO-100?focusedCommentId=10099&page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel](https://jira.xx.io/browse/MINAUTO-100?focusedCommentId=10099&page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel)" "XX/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/XX.0.4240.XXX Safari/537.36" "-"

I need to extract "[jira.xx.io](http://jira.xx.io)" from the referrer. Basically anything between "https:// and the first / "

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [April 12, 2021, 3:49pm UTC](https://discuss.elastic.co/t/can-i-get-a-specific-part-of-the-referrer-in-the-nginx-log-when-parsing-it-via-logstash/269865/2 "2021-04-12T15:49:10Z")

</div>

You could try

```
grok { match => { "referrer" => '"http[s]?://(?<someField>[^/]+/)' } }
```

---

<div class="post-metadata">

**Author:** ![pradeep\_gadkari](https://avatars.discourse-cdn.com/v4/letter/p/a6a055/32.png) [@pradeep\_gadkari](https://discuss.elastic.co/u/pradeep_gadkari)\
**Post date:** [April 13, 2021, 12:25pm UTC](https://discuss.elastic.co/t/can-i-get-a-specific-part-of-the-referrer-in-the-nginx-log-when-parsing-it-via-logstash/269865/3 "2021-04-13T12:25:33Z")

</div>

This worked fine but it was returning [jira.xx.io/](http://jira.xx.io/) . So I used

```auto
grok { match => { "referrer" => '"http[s]?://(?<someField>[^/]+)' } } 

```

and now I get [jira.xx.io](http://jira.xx.io)  
Thanks for your help @Badger

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [April 13, 2021, 3:13pm UTC](https://discuss.elastic.co/t/can-i-get-a-specific-part-of-the-referrer-in-the-nginx-log-when-parsing-it-via-logstash/269865/4 "2021-04-13T15:13:04Z")

</div>

Right, the / should have been outside the parentheses of the capture group: `'"http[s]?://(?<someField>[^/]+)/'`

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 11, 2021, 3:13pm UTC](https://discuss.elastic.co/t/can-i-get-a-specific-part-of-the-referrer-in-the-nginx-log-when-parsing-it-via-logstash/269865/5 "2021-05-11T15:13:25Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
