# Create multiple groks for different logs

**URL:** <https://discuss.elastic.co/t/create-multiple-groks-for-different-logs/127623>\
**Category:** Logstash\
**Created:** [April 11, 2018, 12:10pm UTC](https://discuss.elastic.co/t/create-multiple-groks-for-different-logs/127623 "2018-04-11T12:10:03Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![Arpit\_Gulati](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/arpit_gulati/32/48349_2.png) [@Arpit\_Gulati](https://discuss.elastic.co/u/Arpit_Gulati)\
**Post date:** [April 11, 2018, 12:10pm UTC](https://discuss.elastic.co/t/create-multiple-groks-for-different-logs/127623/1 "2018-04-11T12:10:03Z")

</div>

Hey , I want to create a grok parser filter rules for 2 different logs . For example for nginx logs , a different grok parser rule and for apache a different grok parser in a same filter block of logstash.conf(/etc/logstash/conf.d/logstash.conf)  
Can it be possible ? If yes please provide a solution.

---

<div class="post-metadata">

**Author:** ![atira](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/atira/32/28699_2.png) [@atira](https://discuss.elastic.co/u/atira)\
**Post date:** [April 11, 2018, 12:39pm UTC](https://discuss.elastic.co/t/create-multiple-groks-for-different-logs/127623/2 "2018-04-11T12:39:33Z")

</div>

Depends on Logstash version. Logstash 5.x can handle only one config file, 6.x can handle multiple ones. It makes a huge difference.  
I haven't worked with 6.x yet, so I only know 5.x.  
You could send the different logs on different ports, then you can tag the documents in the input plugin. You can then define conditionals based on the tags, but first, info on Logstash version would be good to know.

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [April 11, 2018, 1:23pm UTC](https://discuss.elastic.co/t/create-multiple-groks-for-different-logs/127623/3 "2018-04-11T13:23:20Z")

</div>

> You could send the different logs on different ports, then you can tag the documents in the input plugin.

Whenever possible add tags or fields as close to the source as possible to avoid having to use different ports for different kinds of files. If you use Filebeat each prospector can add custom tags or fields that you can use in Logstash to select the right filter(s).

---

<div class="post-metadata">

**Author:** ![Arpit\_Gulati](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/arpit_gulati/32/48349_2.png) [@Arpit\_Gulati](https://discuss.elastic.co/u/Arpit_Gulati)\
**Post date:** [April 12, 2018, 8:12am UTC](https://discuss.elastic.co/t/create-multiple-groks-for-different-logs/127623/4 "2018-04-12T08:12:29Z")

</div>

I defined nginx and squid logs in twi different prospector like below

- type: log

- type: log  
enabled: true  
paths:

But how I will parse these two different logs through a grok parser in logstash config file? What I will write in if condition?

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [April 12, 2018, 8:34am UTC](https://discuss.elastic.co/t/create-multiple-groks-for-different-logs/127623/5 "2018-04-12T08:34:58Z")

</div>

Always format configuration snippets as preformatted text. Use Markdown notation. There's a toolbar button for it if you don't know Markdown.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 10, 2018, 8:35am UTC](https://discuss.elastic.co/t/create-multiple-groks-for-different-logs/127623/6 "2018-05-10T08:35:22Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
