# Elastic Ingest with multiple grok processors

**URL:** <https://discuss.elastic.co/t/elastic-ingest-with-multiple-grok-processors/70451>\
**Category:** Elasticsearch\
**Created:** [January 3, 2017, 3:27pm UTC](https://discuss.elastic.co/t/elastic-ingest-with-multiple-grok-processors/70451 "2017-01-03T15:27:42Z")\
**Posts on this page:** 1\
**Showing post:** 3

<div class="post-metadata">

**Author:** ![JamesFx](https://avatars.discourse-cdn.com/v4/letter/j/94ad74/32.png) [@JamesFx](https://discuss.elastic.co/u/JamesFx)\
**Post date:** [January 3, 2017, 4:06pm UTC](https://discuss.elastic.co/t/elastic-ingest-with-multiple-grok-processors/70451/3 "2017-01-03T16:06:08Z")

</div>

That was my first try.

I am using version 5.1 and it only takes into account the last grok.

```
"processors": [
    {
      "grok": {
        "field": "message",
        "patterns": [
          "%{STATUS:status};\\s+%{WORD:service};\\s+%{MSG:message}\\|\\s+%{WORD:key01}=%{NUMBER:value01}.*",
          "%{STATUS:status};\\s+%{WORD:service};\\s+%{GREEDYDATA:message}"
        ],
        "pattern_definitions": {
          "STATUS": "\\d+",
          "MSG": ".+?"
        }
      },
      "grok": {
          "field": "source",
          "patterns": [".+?%{TIMESTAMP:timestamp}.+"],
          "pattern_definitions" : {
            "TIMESTAMP" : "[0-9]+"}
        }
      ,
      "date" : {
        "field" : "timestamp",
        "formats" : ["UNIX_MS"]
      },
      "remove": {
        "field": "timestamp"
      }
    }
  ]
```

---

_[View the full topic](https://discuss.elastic.co/t/elastic-ingest-with-multiple-grok-processors/70451)._
