# Create grok for two different kind of logs

**URL:** <https://discuss.elastic.co/t/create-grok-for-two-different-kind-of-logs/180282>\
**Category:** Logstash\
**Created:** [May 9, 2019, 5:45am UTC](https://discuss.elastic.co/t/create-grok-for-two-different-kind-of-logs/180282 "2019-05-09T05:45:55Z")\
**Posts on this page:** 10\
**Page:** 1

<div class="post-metadata">

**Author:** ![shrikantgulia](https://avatars.discourse-cdn.com/v4/letter/s/c68b51/32.png) [@shrikantgulia](https://discuss.elastic.co/u/shrikantgulia)\
**Post date:** [May 9, 2019, 5:45am UTC](https://discuss.elastic.co/t/create-grok-for-two-different-kind-of-logs/180282/1 "2019-05-09T05:45:55Z")

</div>

Hello Can someone Please guide me how to create grok for two different kind of logs.  
A help would be highly appreciated.

2019/05/01 00:52:51.301 \< Success  
2019/05/01 00:53:04.443 \> GET [http://www.testenvironment.com/smsnew.asp?From\_Number=123456&To\_Number=256789f&Message=&Receive\_Date=20190501&Receive\_Time=1253&status=helloworld&message\_type=psm.cli&source\_location=PK&TSMC=](http://www.testenvironment.com/smsnew.asp?From_Number=123456&To_Number=%1b256789f&Message=&Receive_Date=20190501&Receive_Time=1253&status=helloworld&message_type=psm.cli&source_location=PK&TSMC=)

For the time I know but I am unable to separate furthur

Regards

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [May 10, 2019, 10:45am UTC](https://discuss.elastic.co/t/create-grok-for-two-different-kind-of-logs/180282/3 "2019-05-10T10:45:35Z")

</div>

Have you looked [the example in the documentation showing how to specify multiple patterns to match different types of logs](https://www.elastic.co/guide/en/logstash/current/plugins-filters-grok.html#plugins-filters-grok-match)?

---

<div class="post-metadata">

**Author:** ![shrikantgulia](https://avatars.discourse-cdn.com/v4/letter/s/c68b51/32.png) [@shrikantgulia](https://discuss.elastic.co/u/shrikantgulia)\
**Post date:** [May 10, 2019, 10:46am UTC](https://discuss.elastic.co/t/create-grok-for-two-different-kind-of-logs/180282/4 "2019-05-10T10:46:26Z")

</div>

@Christian_Dahlqvist thanks for the response  
Actually both types of logs are repeating in a single log file

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [May 10, 2019, 10:48am UTC](https://discuss.elastic.co/t/create-grok-for-two-different-kind-of-logs/180282/5 "2019-05-10T10:48:56Z")

</div>

That is what that example cover.

---

<div class="post-metadata">

**Author:** ![kirangavali](https://avatars.discourse-cdn.com/v4/letter/k/77aa72/32.png) [@kirangavali](https://discuss.elastic.co/u/kirangavali)\
**Post date:** [May 13, 2019, 7:42am UTC](https://discuss.elastic.co/t/create-grok-for-two-different-kind-of-logs/180282/6 "2019-05-13T07:42:08Z")

</div>

**You can use the below format to grok pattern for two different kind of logs**

```
input {
    file {
        path => ["/test/*"] #file1.log & file2.log in folder
        start_position => "beginning"
    }
}

filter {
    grok {
        match => {"path" => "%{GREEDYDATA}/%{GREEDYDATA:type}"}
    }
    if [type] == "file1.log" {
         grok {
            match => { ... }
        }
    }
    else if [type] == "file2.log" {
         grok {
            match => { ... }
        }
    }
}

```

Please update me if you have any query or concern.

---

<div class="post-metadata">

**Author:** ![shrikantgulia](https://avatars.discourse-cdn.com/v4/letter/s/c68b51/32.png) [@shrikantgulia](https://discuss.elastic.co/u/shrikantgulia)\
**Post date:** [May 13, 2019, 7:44am UTC](https://discuss.elastic.co/t/create-grok-for-two-different-kind-of-logs/180282/7 "2019-05-13T07:44:43Z")

</div>

Hey @kirangavali  
Both type of logs are in a single log file

---

<div class="post-metadata">

**Author:** ![kirangavali](https://avatars.discourse-cdn.com/v4/letter/k/77aa72/32.png) [@kirangavali](https://discuss.elastic.co/u/kirangavali)\
**Post date:** [May 13, 2019, 7:45am UTC](https://discuss.elastic.co/t/create-grok-for-two-different-kind-of-logs/180282/8 "2019-05-13T07:45:31Z")

</div>

> [@shrikantgulia](#):
>
> tually both types of logs are repeating in a single log file

You want to say there is only one single log file?

---

<div class="post-metadata">

**Author:** ![shrikantgulia](https://avatars.discourse-cdn.com/v4/letter/s/c68b51/32.png) [@shrikantgulia](https://discuss.elastic.co/u/shrikantgulia)\
**Post date:** [May 13, 2019, 7:47am UTC](https://discuss.elastic.co/t/create-grok-for-two-different-kind-of-logs/180282/9 "2019-05-13T07:47:38Z")

</div>

yes,

Both type of logs are in a single log file

---

<div class="post-metadata">

**Author:** ![kirangavali](https://avatars.discourse-cdn.com/v4/letter/k/77aa72/32.png) [@kirangavali](https://discuss.elastic.co/u/kirangavali)\
**Post date:** [May 13, 2019, 7:58am UTC](https://discuss.elastic.co/t/create-grok-for-two-different-kind-of-logs/180282/10 "2019-05-13T07:58:04Z")

</div>

> [@shrikantgulia](#):
>
> Both type of logs are in a single log file

Hey @shrikantgulia

In order to filter multiple patterns using grok, you simply need to use multiple "match" patterns as shown below:

```
input { stdin { } }

filter {
  grok {
       match => {"message" => "\A%{WORD:Success}"}
       match => {"message" => "\A%{WORD:GET}"}
  }

}

output {
  stdout { codec => rubydebug }
}

```

Also, in order to filter dates from messages in a single log file, you would need to use match pattern in multiple filters as shown below:

```
input { stdin { } } 

filter { 
  grok { 
    match => { "message" => "%{COMBINEDAPACHELOG}" } 
  } 
  date { 
    match => ["timestamp" , "dd/MMM/yyyy:HH:mm:Ss Z"] 
  } 
} 

output { 
  elasticsearch { hosts => ["localhost:9200"] } 
  stdout { codec => rubydebug } 
} 

```

Please let me know if you have further query or concern.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 10, 2019, 7:58am UTC](https://discuss.elastic.co/t/create-grok-for-two-different-kind-of-logs/180282/11 "2019-06-10T07:58:04Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
