# Can I store entire grok pattern in a variable

**URL:** <https://discuss.elastic.co/t/can-i-store-entire-grok-pattern-in-a-variable/179101>\
**Category:** Logstash\
**Created:** [April 30, 2019, 2:09pm UTC](https://discuss.elastic.co/t/can-i-store-entire-grok-pattern-in-a-variable/179101 "2019-04-30T14:09:43Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![rahulkothanath](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rahulkothanath/32/99122_2.png) [@rahulkothanath](https://discuss.elastic.co/u/rahulkothanath)\
**Post date:** [April 30, 2019, 2:09pm UTC](https://discuss.elastic.co/t/can-i-store-entire-grok-pattern-in-a-variable/179101/1 "2019-04-30T14:09:43Z")

</div>

I have filter like below:

```
         filter {
   
	grok {

		match => {
			"message" => "(?<user_agent>^.{3}) %{GREEDYDATA:body}"
		}

	}

```

can I put "**(?\<user\_agent\>^.{3}) %{GREEDYDATA:body}**" inside a variable and use it as per condiion.

```
 a = "(?<user_agent>^.{3}) %{GREEDYDATA:body}"
 b = "(?<user_agent2>^.{3}) %{GREEDYDATA:body}"

 filter {
 	if ("key==a") {
 		grok {
 			match => {
 				"message" => a
 			}
 		}
 	} else {
 		grok {

 			match => {
 				"message" => b
 			}
 		}
 	}

```

Thanks for reading and helping

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [April 30, 2019, 2:48pm UTC](https://discuss.elastic.co/t/can-i-store-entire-grok-pattern-in-a-variable/179101/2 "2019-04-30T14:48:25Z")

</div>

> [@rahulkothanath](#):
>
> can I put " **(?\<user\_agent\>^.{3}) %{GREEDYDATA:body}**" inside a variable and use it as per condiion.

No, you cannot. Nor can you use a sprintf reference in the grok pattern.

---

<div class="post-metadata">

**Author:** ![A\_B](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/a_b/32/17104_2.png) [@A\_B](https://discuss.elastic.co/u/A_B)\
**Post date:** [April 30, 2019, 2:50pm UTC](https://discuss.elastic.co/t/can-i-store-entire-grok-pattern-in-a-variable/179101/3 "2019-04-30T14:50:26Z")

</div>

Hi @rahulkothanath,

I do not think that will work but not 100%...

What you can do is make a pattern file and give names to the combined patterns. You can also try more than one pattern using pipe.

The pattern file would like something like

```
MY_PATTERN_1 "(?<user_agent>^.{3}) %{GREEDYDATA:body}"
MY_PATTERN_2 "(?<user_agent2>^.{3}) %{GREEDYDATA:body}"

ALL_MY_PATTERNS (%{MY_PATTERN_1}|%{MY_PATTERN_2})

```

Put the above pattern file in `/path/to/patterns`. And for the filter you configure

```
grok {
  patterns_dir => ["/path/to/patterns"]
  match => { "message" => "%{ALL_MY_PATTERNS}" }
}

```

Patterns will be tried until the first match is found.

---

<div class="post-metadata">

**Author:** ![rahulkothanath](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rahulkothanath/32/99122_2.png) [@rahulkothanath](https://discuss.elastic.co/u/rahulkothanath)\
**Post date:** [April 30, 2019, 2:57pm UTC](https://discuss.elastic.co/t/can-i-store-entire-grok-pattern-in-a-variable/179101/4 "2019-04-30T14:57:31Z")

</div>

Thanks for the response. Will try pattern\_dir and let u know.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 28, 2019, 2:57pm UTC](https://discuss.elastic.co/t/can-i-store-entire-grok-pattern-in-a-variable/179101/5 "2019-05-28T14:57:37Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
