# Doubts about Grok

**URL:** <https://discuss.elastic.co/t/doubts-about-grok/257129>\
**Category:** Logstash\
**Created:** [November 30, 2020, 9:04pm UTC](https://discuss.elastic.co/t/doubts-about-grok/257129 "2020-11-30T21:04:57Z")\
**Posts on this page:** 1\
**Showing post:** 2

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [November 30, 2020, 10:53pm UTC](https://discuss.elastic.co/t/doubts-about-grok/257129/2 "2020-11-30T22:53:59Z")

</div>

> [@rildo](#):
>
> `grok {`  
> ` match => { "teste3" => "%{IPV4:CC}%{SPACE}%{WORD}\:%{SPACE}%{DATA:domain}" }`

The problem with DATA is that it can match as much or as little as it wants. In this case it is matching nothing, as you will see if you add

```
 keep_empty_captures => true

```

to your grok filter, which will result in you getting

```
      "domain" => "",

```

Try

```
 grok { match => { "teste3" => "%{IPV4:CC}%{SPACE}%{WORD}:%{SPACE}%{NOTSPACE:domain}" } }

```

HOSTNAME is another option instead of NOTSPACE.

---

_[View the full topic](https://discuss.elastic.co/t/doubts-about-grok/257129)._
