# Capturing group inside a custom grok pattern

**URL:** <https://discuss.elastic.co/t/capturing-group-inside-a-custom-grok-pattern/163384>\
**Category:** Logstash\
**Created:** [January 8, 2019, 2:47pm UTC](https://discuss.elastic.co/t/capturing-group-inside-a-custom-grok-pattern/163384 "2019-01-08T14:47:57Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![agosmaker](https://avatars.discourse-cdn.com/v4/letter/a/edb3f5/32.png) [@agosmaker](https://discuss.elastic.co/u/agosmaker)\
**Post date:** [January 8, 2019, 2:47pm UTC](https://discuss.elastic.co/t/capturing-group-inside-a-custom-grok-pattern/163384/1 "2019-01-08T14:47:58Z")

</div>

Hello,  
Let's imagine we have string  
`some text aaabbbccc another text`  
We want to extract bbb.

1. we can use "embedded" regex ([https://www.elastic.co/guide/en/logstash/current/plugins-filters-grok.html](https://www.elastic.co/guide/en/logstash/current/plugins-filters-grok.html) Custom Patterns "option 1"  
`aaa(?<superb>.*)ccc`  
and get  
{  
"superb": [  
"bbb"  
]  
}  
But it's more neatly to extract this logic to custom pattern in custom pattern file.

2. we can use custom pattern in custom pattern file ("option 2")  
`BPATTERN aaa(?<superb>.*)ccc`  
result:  
{  
"bvar": [  
"aaabbbccc"  
],  
"superb": [  
"bbb"  
]  
}

Now we have excess variable bvar.  
Of course we can mutate and remove bvar, but does another method exist to not create (and remove further) bvar variable?

I tried syntax like  
`%{BPATTERN:}`  
but it doesn't allow omit variable.

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [January 8, 2019, 3:22pm UTC](https://discuss.elastic.co/t/capturing-group-inside-a-custom-grok-pattern/163384/2 "2019-01-08T15:22:36Z")

</div>

Leave out the colon. This works

```
grok {
    pattern_definitions => { "BPATTERN" => "aaa(?<superb>.*)ccc" }
    match => { "message" => "%{BPATTERN}" }
}

```

It would work with patterns\_dir too.

---

<div class="post-metadata">

**Author:** ![agosmaker](https://avatars.discourse-cdn.com/v4/letter/a/edb3f5/32.png) [@agosmaker](https://discuss.elastic.co/u/agosmaker)\
**Post date:** [January 8, 2019, 5:07pm UTC](https://discuss.elastic.co/t/capturing-group-inside-a-custom-grok-pattern/163384/3 "2019-01-08T17:07:04Z")

</div>

Thank you for the answer. I'll check but it doesn't work at least in [http://grokdebug.herokuapp.com/](http://grokdebug.herokuapp.com/)

---

<div class="post-metadata">

**Author:** ![agosmaker](https://avatars.discourse-cdn.com/v4/letter/a/edb3f5/32.png) [@agosmaker](https://discuss.elastic.co/u/agosmaker)\
**Post date:** [January 17, 2019, 5:56pm UTC](https://discuss.elastic.co/t/capturing-group-inside-a-custom-grok-pattern/163384/4 "2019-01-17T17:56:02Z")

</div>

Yes, it works. Many thanks.  
All uppercase names in [http://grokdebug.herokuapp.com/](http://grokdebug.herokuapp.com/) like  
"YEAR": [  
[  
"2018"  
]  
]  
really aren't included in ouput json by logstash. So everything is OK

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 14, 2019, 5:56pm UTC](https://discuss.elastic.co/t/capturing-group-inside-a-custom-grok-pattern/163384/5 "2019-02-14T17:56:04Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
