# Custom grok write for my message

**URL:** <https://discuss.elastic.co/t/custom-grok-write-for-my-message/325728>\
**Category:** Elasticsearch\
**Created:** [February 16, 2023, 11:47am UTC](https://discuss.elastic.co/t/custom-grok-write-for-my-message/325728 "2023-02-16T11:47:49Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![dharminfadia](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dharminfadia/32/119587_2.png) [@dharminfadia](https://discuss.elastic.co/u/dharminfadia)\
**Post date:** [February 16, 2023, 11:47am UTC](https://discuss.elastic.co/t/custom-grok-write-for-my-message/325728/1 "2023-02-16T11:47:49Z")

</div>

Hello Everyone I am having following example logs

I want to extract field using filebeat any one can help ?

0.0.0.0 - - [16/Feb/2023:09:54:40 +0000] "POST /api/WebsiteCategory/ProductDesigns HTTP/1.1" 200 95521 "[https://www.contrado.co.uk/"](https://www.xyz.com/%22) "AdsBot-Google (+[http://www.google.com/adsbot.html)"](http://www.google.com/adsbot.html)%22) "0.0.0.0, 0.0.0.0" "0.104" "0.100" "1102"

---

<div class="post-metadata">

**Author:** ![Wave](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/wave/32/117242_2.png) [@Wave](https://discuss.elastic.co/u/Wave)\
**Post date:** [February 17, 2023, 3:17am UTC](https://discuss.elastic.co/t/custom-grok-write-for-my-message/325728/2 "2023-02-17T03:17:25Z")

</div>

Hi @dharminfadia,  
Is there a specific field you are trying to extract or all of them? Also there might be a module already created for this type of data. What kind of device are the logs coming from?

---

<div class="post-metadata">

**Author:** ![dharminfadia](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dharminfadia/32/119587_2.png) [@dharminfadia](https://discuss.elastic.co/u/dharminfadia)\
**Post date:** [February 17, 2023, 5:22am UTC](https://discuss.elastic.co/t/custom-grok-write-for-my-message/325728/3 "2023-02-17T05:22:52Z")

</div>

@Wave  
Thank you for reply logs coming from nginx and I am using NGINX Module in filebeat for custom logs above log sample is semistructure can you please try to help write grok pattern.

---

<div class="post-metadata">

**Author:** ![Wave](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/wave/32/117242_2.png) [@Wave](https://discuss.elastic.co/u/Wave)\
**Post date:** [February 17, 2023, 12:12pm UTC](https://discuss.elastic.co/t/custom-grok-write-for-my-message/325728/4 "2023-02-17T12:12:51Z")

</div>

Ok try this as a starting point:

```auto
%{IP:IP0} - - %{DATA:WHEN} "%{GREEDYDATA:REQUEST}" %{INT:RESPONSE_CODE} %{INT:CODE} "%{GREEDYDATA:REFERRER}"%{GREEDYDATA} "%{IP:IP1}, %{IP:IP2}" "%{NUMBER:NUMBER1}" "%{NUMBER:NUMBER2}" "%{NUMBER:NUMBER3}" 

```

Please modify this for your use case. based upon a sample of 1 data row I don't really know what those fields are. The grok debugger in Kibana (Dev Tools \> Grok Debugger) is your friend and what I used to play around with your sample input. Also, see the [grok documentation](https://www.elastic.co/guide/en/elasticsearch/reference/current/grok.html) for more info.  
Good luck and happy groking.

p.s. You don't say but if you can use more than grok to modify this data I'd personally use [dissect](https://www.elastic.co/guide/en/elasticsearch/reference/current/dissect-processor.html) first then perhaps grok.

---

<div class="post-metadata">

**Author:** ![dharminfadia](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dharminfadia/32/119587_2.png) [@dharminfadia](https://discuss.elastic.co/u/dharminfadia)\
**Post date:** [February 17, 2023, 12:35pm UTC](https://discuss.elastic.co/t/custom-grok-write-for-my-message/325728/5 "2023-02-17T12:35:02Z")

</div>

@Wave

Thank you for reply this grok is not working properly but now this project on hold thank you for quick response if I got any solution for this I will post here now no any emergancy.

---

<div class="post-metadata">

**Author:** ![Wave](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/wave/32/117242_2.png) [@Wave](https://discuss.elastic.co/u/Wave)\
**Post date:** [February 17, 2023, 2:37pm UTC](https://discuss.elastic.co/t/custom-grok-write-for-my-message/325728/6 "2023-02-17T14:37:47Z")

</div>

Sure thing. I ran it on a 8.6.1 cluster in the Grok Debugger. Like I said just treat it as a place to start. You can just just try with `%{IP:IP0}` and add pieces back to see what works in your case. I would recommend doing that before throwing anything straight into filebeat. Also, this might be a good use case for an [ingest pipeline](https://www.elastic.co/guide/en/elasticsearch/reference/current/ingest.html) instead. It can handle grok and provides you with a UI in kibana.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 17, 2023, 2:37pm UTC](https://discuss.elastic.co/t/custom-grok-write-for-my-message/325728/7 "2023-03-17T14:37:59Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
