# Disappearing logs when using regex in grok match

**URL:** <https://discuss.elastic.co/t/disappearing-logs-when-using-regex-in-grok-match/58460>\
**Category:** Logstash\
**Created:** [August 19, 2016, 1:19pm UTC](https://discuss.elastic.co/t/disappearing-logs-when-using-regex-in-grok-match/58460 "2016-08-19T13:19:57Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![harrytewkesbury](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/harrytewkesbury/32/11010_2.png) [@harrytewkesbury](https://discuss.elastic.co/u/harrytewkesbury)\
**Post date:** [August 19, 2016, 1:19pm UTC](https://discuss.elastic.co/t/disappearing-logs-when-using-regex-in-grok-match/58460/1 "2016-08-19T13:19:57Z")

</div>

Hi - I have a strange issue that I can't make heads or tails of. When I parse a log type for %{HTTPDATE} it works fine, but when I also want to add %{IPORHOST}, then the entire log never makes it to elasticsearch - I look by tag, and by text search etc. Here are the stanzas:

`if "apache" in [tags] and "external" in [tags] and "legacy" in [tags] { grok { match => ["message", "%{IPORHOST:src_ip}.+*%{HTTPDATE:timestamp}"] overwrite => ["timestamp", "message"] tag_on_failure => ["grokfail_legacy"] } date { match => ["timestamp", "dd/MMM/yyyy:HH:mm:ss Z"] add_tag => "dateparsesuccess_legacy" } }`

Filebeat is tagging correctly (I can see the fields when grepping redis-cli) and when I remove that IPORHOST pattern, and have it just:

`match => ["message", "%{HTTPDATE:timestamp}"]`

It works ok. Trouble is, I want that IPAddress! Is this a bug, or am I doing something dumb? Thanks.

---

<div class="post-metadata">

**Author:** ![harrytewkesbury](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/harrytewkesbury/32/11010_2.png) [@harrytewkesbury](https://discuss.elastic.co/u/harrytewkesbury)\
**Post date:** [August 19, 2016, 1:42pm UTC](https://discuss.elastic.co/t/disappearing-logs-when-using-regex-in-grok-match/58460/2 "2016-08-19T13:42:36Z")

</div>

And of course, inevitably I discover that regex actually chops off the 1 of the 19th. I could swear I couldn't find the relevant tags though.

Any idea how I could match the IP and the timestamp of a log like this without screwing up?

`95.87.154.242, 141.101.92.152 [-] - - [19/Aug/2016:13:13:02 +0000] "GET /blog/feed/ HTTP/1.1" 301 519 "-" "UniversalFeedParser/5.2.1 +https://code.google.com/p/feedparser/"`

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [August 22, 2016, 11:00am UTC](https://discuss.elastic.co/t/disappearing-logs-when-using-regex-in-grok-match/58460/3 "2016-08-22T11:00:29Z")

</div>

Which IP address(es) do you want to capture? If you want to capture more than one, where should they be stored? All in one field (i.e. making it an array field)? Something else?

---

<div class="post-metadata">

**Author:** ![harrytewkesbury](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/harrytewkesbury/32/11010_2.png) [@harrytewkesbury](https://discuss.elastic.co/u/harrytewkesbury)\
**Post date:** [August 22, 2016, 11:38am UTC](https://discuss.elastic.co/t/disappearing-logs-when-using-regex-in-grok-match/58460/4 "2016-08-22T11:38:53Z")

</div>

I managed to work out the capture, thanks. Just a stupid typo in my regex - the second IP is Cloud Flare, so not necessary to keep. . The correct (or at least working) solution for me is simply:

`match => ["message", "%{IPORHOST:clientip}+.*\[%{HTTPDATE:timestamp}"]`

This claims the first IP, skips everything else up until the HTTPDATE and claims that as "timestamp". All good. Thanks.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 4:42am UTC](https://discuss.elastic.co/t/disappearing-logs-when-using-regex-in-grok-match/58460/5 "2017-07-06T04:42:19Z")

</div>


