# Can you reference a dynamic variable in the grok filter?

**URL:** <https://discuss.elastic.co/t/can-you-reference-a-dynamic-variable-in-the-grok-filter/286838>\
**Category:** Logstash\
**Created:** [October 15, 2021, 12:59pm UTC](https://discuss.elastic.co/t/can-you-reference-a-dynamic-variable-in-the-grok-filter/286838 "2021-10-15T12:59:44Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Cibot](https://avatars.discourse-cdn.com/v4/letter/c/bbe5ce/32.png) [@Cibot](https://discuss.elastic.co/u/Cibot)\
**Post date:** [October 15, 2021, 12:59pm UTC](https://discuss.elastic.co/t/can-you-reference-a-dynamic-variable-in-the-grok-filter/286838/1 "2021-10-15T12:59:44Z")

</div>

I have been trying to split up the input of a script from execbeat.  
So far everything has been going smooth.

I have input of similar fashion.

rpm-2109130090009900.x86-64 Thu 2019 ... and so on.

So basically an information of the installed RPM package and the DATE it has been installed.  
Now I was trying the following grok in logstash:

```auto
if [type] == "execbeat" {
                split {
                        field => "[exec][stdout]"
                }
                grok {
                        match => {
                                "[exec][stdout]" => "%{NOTSPACE:rpm} %{GREEDYDATA:installdate}"
                                "rpm" => "%{GREEDYDATA}-%{INT:rpmtimestamp}"
                        }
                }
        }

```

I was thinking that I could access the 'rpm' variable for the 2nd match but it doesn't appear to work. Is there a better way to make this work or do I have an error somewhere? If i use the second grok on **[exec][stdout]** then I get the rpmtimestamp variable in the index, so the grok pattern itself is correct.

---

<div class="post-metadata">

**Author:** ![Cibot](https://avatars.discourse-cdn.com/v4/letter/c/bbe5ce/32.png) [@Cibot](https://discuss.elastic.co/u/Cibot)\
**Post date:** [October 15, 2021, 1:13pm UTC](https://discuss.elastic.co/t/can-you-reference-a-dynamic-variable-in-the-grok-filter/286838/2 "2021-10-15T13:13:30Z")

</div>

The solution is the following:

```auto
        if [type] == "execbeat" {
                split {
                        field => "[exec][stdout]"
                }
                grok {
                        match => {
                                "[exec][stdout]" => "%{NOTSPACE:rpm} %{GREEDYDATA:installdate}"
                        }
                        match => {
                                "[exec][stdout]" => "%{GREEDYDATA}-%{INT:rpmtimestamp}"
                        }
                        break_on_match => false
                }
        }

```

So you can't define multiple references to "[exec][stdout]" in the same MATCH block, thus you split the match blocks into multiple once. But here you have to be careful as GROK has the default behaviour to break/stop after the first successful match. As such it is necessary to add the last line:  
**break\_on\_match =\> false**

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [October 15, 2021, 4:57pm UTC](https://discuss.elastic.co/t/can-you-reference-a-dynamic-variable-in-the-grok-filter/286838/3 "2021-10-15T16:57:52Z")

</div>

> [@Cibot](#):
>
> ```auto
> match => {
> "[exec][stdout]" => "%{NOTSPACE:rpm} %{GREEDYDATA:installdate}"
> }
> match => {
> "[exec][stdout]" => "%{GREEDYDATA}-%{INT:rpmtimestamp}"
> }
> 
> ```

If you want to match a field against multiple patterns the standard way to do it would be

```
match => {
    "[exec][stdout]" => [ 
        "%{NOTSPACE:rpm} %{GREEDYDATA:installdate}",
        "%{GREEDYDATA}-%{INT:rpmtimestamp}"
    ]
}

```

Combining multiple occurrences of a filter option (two match options) works differently in different versions of logstash and will sometimes do very unexpected things. I advise against doing it.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 12, 2021, 4:58pm UTC](https://discuss.elastic.co/t/can-you-reference-a-dynamic-variable-in-the-grok-filter/286838/4 "2021-11-12T16:58:24Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
