# Different Grok expressions for the same log file

**URL:** <https://discuss.elastic.co/t/different-grok-expressions-for-the-same-log-file/184622>\
**Category:** Logstash\
**Created:** [June 6, 2019, 3:29pm UTC](https://discuss.elastic.co/t/different-grok-expressions-for-the-same-log-file/184622 "2019-06-06T15:29:33Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![habi](https://avatars.discourse-cdn.com/v4/letter/h/bbe5ce/32.png) [@habi](https://discuss.elastic.co/u/habi)\
**Post date:** [June 6, 2019, 3:29pm UTC](https://discuss.elastic.co/t/different-grok-expressions-for-the-same-log-file/184622/1 "2019-06-06T15:29:33Z")

</div>

Hey all, i have a question with regards to the grok filter,  
so i have different types log formats in my nginx-access.log and i want to parse them out seperately, in my kibana, i did try adding the optional fields but they did not work properly, i could add a second grok expression but i dont know how to set the conditions so as it will select the correct grok expression when needed. can any one suggest me on how to set these filters? I hope i made myself clear.  
my two log examples are something like this:  
a. 0.0.0.0 0.0.0.0 - - [06/Jun/2019:13:38:24 +0000] "GET /homepage/v1?HTTP/1.0" 200 25853 "[test.com](http://test.com)" "[https://test.com/homepage](https://test.com/homepage)" "useragent" "-" - 0.05 0.24  
b. 0.0.0.0 0.0.0.0 - - [06/Jun/2019:13:38:24 +0000] "GET /customersupport/form/v1?submission=yes&repeat=no&id=123?HTTP/1.0" 200 25853 "[test.com](http://test.com)" "[https://test.com/homepage](https://test.com/homepage)" "useragent" "-" - 0.05 0.24

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 4, 2019, 3:29pm UTC](https://discuss.elastic.co/t/different-grok-expressions-for-the-same-log-file/184622/2 "2019-07-04T15:29:38Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
