# Doubts about Grok

**URL:** <https://discuss.elastic.co/t/doubts-about-grok/257129>\
**Category:** Logstash\
**Created:** [November 30, 2020, 9:04pm UTC](https://discuss.elastic.co/t/doubts-about-grok/257129 "2020-11-30T21:04:57Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![rildo](https://avatars.discourse-cdn.com/v4/letter/r/eb9ed0/32.png) [@rildo](https://discuss.elastic.co/u/rildo)\
**Post date:** [November 30, 2020, 9:04pm UTC](https://discuss.elastic.co/t/doubts-about-grok/257129/1 "2020-11-30T21:04:57Z")

</div>

Hello People , I have a doubt about my filter

I have this content in my log file

{"other\_logs": "127.0.0.1|28614|2018-11-28 23:51:57|srcport 50389 mwtype AvalancheBotnet-andromeda destaddr 2.2.2.2 destinyurl: dogs.ru|Moscou, RU", "source\_port": "50389", "malware\_name": "AvalancheBotnet-andromeda", "subject": "Host with malware malware"}

When I did the filter as below it works

```auto
    if "|" in [other_logs] {
                     mutate {
                     split => ["other_logs", "|"]
                    add_field => { "ASN" => "%{[other_logs][1]}" }
                    add_field => { "teste3" => "%{[other_logs][3]}" }
                                              }

                                   grok {
                                              match => { "teste3" => "%{IPV4:CC}" }
                                              add_tag => ["contains_ip"]
                                                }
                                           grok {
                                              match => { "teste3" => "\: %{GREEDYDATA:domain}" }
                                              add_tag => ["contains_url"]
                                               }
                                                               }

```

But when I try to do as below it does not work, the filter just get the C&C IP  
...  
` grok {`  
` match => { "teste3" => "%{IPV4:CC}%{SPACE}%{WORD}\:%{SPACE}%{DATA:domain}" }`

Someone could help me ?

Thanks

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [November 30, 2020, 10:53pm UTC](https://discuss.elastic.co/t/doubts-about-grok/257129/2 "2020-11-30T22:53:59Z")

</div>

> [@rildo](#):
>
> `grok {`  
> ` match => { "teste3" => "%{IPV4:CC}%{SPACE}%{WORD}\:%{SPACE}%{DATA:domain}" }`

The problem with DATA is that it can match as much or as little as it wants. In this case it is matching nothing, as you will see if you add

```
 keep_empty_captures => true

```

to your grok filter, which will result in you getting

```
      "domain" => "",

```

Try

```
 grok { match => { "teste3" => "%{IPV4:CC}%{SPACE}%{WORD}:%{SPACE}%{NOTSPACE:domain}" } }

```

HOSTNAME is another option instead of NOTSPACE.

---

<div class="post-metadata">

**Author:** ![rildo](https://avatars.discourse-cdn.com/v4/letter/r/eb9ed0/32.png) [@rildo](https://discuss.elastic.co/u/rildo)\
**Post date:** [December 1, 2020, 8:37pm UTC](https://discuss.elastic.co/t/doubts-about-grok/257129/3 "2020-12-01T20:37:15Z")

</div>

Thank you Badger !

It works

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 29, 2020, 8:37pm UTC](https://discuss.elastic.co/t/doubts-about-grok/257129/4 "2020-12-29T20:37:17Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
