# Creating a sub field of GROK filter pattern

**URL:** https://discuss.elastic.co/t/creating-a-sub-field-of-grok-filter-pattern/238860
**Category:** Logstash
**Created:** [June 26, 2020, 12:51pm UTC](https://discuss.elastic.co/t/creating-a-sub-field-of-grok-filter-pattern/238860 "2020-06-26T12:51:39Z")
**Posts on this page:** 1
**Showing post:** 2

<div class="post-metadata">

### Author: ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)
#### Post date: [July 12, 2020, 11:42pm UTC](https://discuss.elastic.co/t/creating-a-sub-field-of-grok-filter-pattern/238860/2 "2020-07-12T23:42:40Z")

</div>

Personally I would not grok that, I would [dissect and then use kv](https://discuss.elastic.co/t/parsing-firewall-logs-in-logstash/212786/2).

---

_[View the full topic](https://discuss.elastic.co/t/creating-a-sub-field-of-grok-filter-pattern/238860)._
