# Customer pattern to parse specific data

**URL:** <https://discuss.elastic.co/t/customer-pattern-to-parse-specific-data/154303>\
**Category:** Logstash\
**Created:** [October 27, 2018, 9:12pm UTC](https://discuss.elastic.co/t/customer-pattern-to-parse-specific-data/154303 "2018-10-27T21:12:03Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![bab](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bab/32/86201_2.png) [@bab](https://discuss.elastic.co/u/bab)\
**Post date:** [October 27, 2018, 9:12pm UTC](https://discuss.elastic.co/t/customer-pattern-to-parse-specific-data/154303/1 "2018-10-27T21:12:03Z")

</div>

hey,

i have a problem with my logfiles i want to create a grok pattern which can chek if this log-entry have after `sev` field a string starrt whit com than parse it in package. i try this pattern but not lukcy:

log-entry:

`[9/17/18 4:48:10:436 CEST] 00000072 webapp E com .ibm.ws.webcontainer.webapp.WebApp logServletError SRVE0293E: [Servlet Error]-[PluginServlet]: java.io.IOException: Plugin resource not found!`

my pattern:

`%{DATESTAMP:time} %{NOTSPACE} %{NOTSPACE:thread} %{WORD:log-source} []* %{NOTSPACE:sev}\s+(?<package>[a-z]{3}(?=.*c))\s ?%{GREEDYDATA:msg}`

please help me.  
Thank you

---

<div class="post-metadata">

**Author:** ![bloke](https://avatars.discourse-cdn.com/v4/letter/b/b5e925/32.png) [@bloke](https://discuss.elastic.co/u/bloke)\
**Post date:** [October 27, 2018, 10:02pm UTC](https://discuss.elastic.co/t/customer-pattern-to-parse-specific-data/154303/2 "2018-10-27T22:02:00Z")

</div>

Use this tool to help you construct and test your grok patterns.

[http://grokconstructor.appspot.com/](http://grokconstructor.appspot.com/)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 24, 2018, 10:02pm UTC](https://discuss.elastic.co/t/customer-pattern-to-parse-specific-data/154303/3 "2018-11-24T22:02:00Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
