# Either white space or a %{WORD:\_\_\_\_\_}

**URL:** <https://discuss.elastic.co/t/either-white-space-or-a-word/329357>\
**Category:** Logstash\
**Created:** [April 4, 2023, 10:33pm UTC](https://discuss.elastic.co/t/either-white-space-or-a-word/329357 "2023-04-04T22:33:08Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Jim\_Thunder](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jim_thunder/32/45439_2.png) [@Jim\_Thunder](https://discuss.elastic.co/u/Jim_Thunder)\
**Post date:** [April 4, 2023, 10:33pm UTC](https://discuss.elastic.co/t/either-white-space-or-a-word/329357/1 "2023-04-04T22:33:08Z")

</div>

I have two different kinds of messages that are very similar:

`"Rec": " 10:33:38 +HCXPCTA-E CW83 ISMDAYS ASRA"}`  
`"Rec": " 10:31:56 +HCXPCTA-E IS60 RX1 ISMDAYS ASRA"}`

In the REC field one message has `RX1` while the other is just 6 white spaces. (This text box doesn't allow for white space it seems, but the message w/o the rx1 has 6 white spaces. So both messages have the same number of characters).

How do I code something like "if white space ignore, else if _not_ white space do: %{WORD:NAME}" ?

Here's what I have now that works only when there's white space, it fails if the RX1 exists:

> grok { match =\> {"Rec" =\> " (?\<Time\_Stamp\>[0-9][0-9]:[0-9][0-9]:[0-9][0-9]) +%{WORD:Message\_Code}\-\E %{WORD:Tran\_ID} %{WORD:Program} %{WORD:Abend\_Code}"}}

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [April 5, 2023, 1:12am UTC](https://discuss.elastic.co/t/either-white-space-or-a-word/329357/2 "2023-04-05T01:12:02Z")

</div>

> [@Jim\_Thunder](#):
>
> %{WORD:Tran\_ID} %{WORD:Program}

Try `%{WORD:Tran_ID}\s+(%{WORD:Program})?` and anchor the end of the pattern to end-of-line using $.

---

<div class="post-metadata">

**Author:** ![Jim\_Thunder](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jim_thunder/32/45439_2.png) [@Jim\_Thunder](https://discuss.elastic.co/u/Jim_Thunder)\
**Post date:** [April 5, 2023, 1:32pm UTC](https://discuss.elastic.co/t/either-white-space-or-a-word/329357/3 "2023-04-05T13:32:31Z")

</div>

What does \s+ do? Ignore any amount of white space?

But it looks like that worked.

How would I ignore 2 or 3 white space characters? Later on in the message I'm getting issues because sometimes there's a 7 char program name and sometimes there's an 8 char program name. So there's white space that's either 2 or 3 characters.

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [April 5, 2023, 2:35pm UTC](https://discuss.elastic.co/t/either-white-space-or-a-word/329357/4 "2023-04-05T14:35:12Z")

</div>

\s+ is one or more whitespace characters. The ()? around the Program means it occurs zero or more times.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 3, 2023, 2:35pm UTC](https://discuss.elastic.co/t/either-white-space-or-a-word/329357/5 "2023-05-03T14:35:59Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
