# Elb logs grok inside grok

**URL:** <https://discuss.elastic.co/t/elb-logs-grok-inside-grok/82615>\
**Category:** Logstash\
**Created:** [April 17, 2017, 7:22pm UTC](https://discuss.elastic.co/t/elb-logs-grok-inside-grok/82615 "2017-04-17T19:22:47Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![bob-bza](https://avatars.discourse-cdn.com/v4/letter/b/9f8e36/32.png) [@bob-bza](https://discuss.elastic.co/u/bob-bza)\
**Post date:** [April 17, 2017, 7:22pm UTC](https://discuss.elastic.co/t/elb-logs-grok-inside-grok/82615/1 "2017-04-17T19:22:48Z")

</div>

This was my filter looks like for ELB log.  
**filter {**  
**grok {**

\*\* match =\> ["message", "%{TIMESTAMP\_ISO8601:timestamp} %{NOTSPACE:elb\_name} %{IP:elb\_client\_ip}:%{INT:elb\_client\_port:int} (?:%{IP:elb\_backend\_ip}:%{NUMBER:elb\_backend\_port:int}|-) %{NUMBER:request\_processing\_time:float} %{NUMBER:backend\_processing\_time:float} %{NUMBER:response\_processing\_time:float} (?:%{INT:elb\_status\_code:int}|-) (?:%{INT:backend\_status\_code:int}|-) %{INT:elb\_received\_bytes:int} %{INT:elb\_sent\_bytes:int} "(?:%{GREEDYDATA:elb\_request}|-)" "(?:%{GREEDYDATA:userAgent}|-)" %{NOTSPACE:elb\_sslcipher} %{NOTSPACE:elb\_sslprotocol}"]\*\*  
**}**  
**}**

From this i was trying to get only if elb\_status\_code = 400 then only i want to copy my message to ES and only with few fields. i don't want all fields also.  
Ex:  
**filter {**  
**grok {**

\*\* match =\> ["message", "%{TIMESTAMP\_ISO8601:timestamp} %{NOTSPACE:elb\_name} %{IP:elb\_client\_ip}:%{INT:elb\_client\_port:int} (?:%{IP:elb\_backend\_ip}:%{NUMBER:elb\_backend\_port:int}|-) %{NUMBER:request\_processing\_time:float} %{NUMBER:backend\_processing\_time:float} %{NUMBER:response\_processing\_time:float} (?:%{INT:elb\_status\_code:int}|-) (?:%{INT:backend\_status\_code:int}|-) %{INT:elb\_received\_bytes:int} %{INT:elb\_sent\_bytes:int} "(?:%{GREEDYDATA:elb\_request}|-)" "(?:%{GREEDYDATA:userAgent}|-)" %{NOTSPACE:elb\_sslcipher} %{NOTSPACE:elb\_sslprotocol}"]\*\*  
**}**  
**if [elb\_status\_code] =~ "400" {**

**grok { match =\> ["elb\_status\_code", "%{TIMESTAMP\_ISO8601:timestamp} %{NOTSPACE:elb\_sslprotocol}"]**  
\*\* }\*\*  
**}**  
**}**  
is anything wrong in this, this was not working and i was getting my full log to ES.???????

---

<div class="post-metadata">

**Author:** ![jkuang](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jkuang/32/72637_2.png) [@jkuang](https://discuss.elastic.co/u/jkuang)\
**Post date:** [April 18, 2017, 11:19pm UTC](https://discuss.elastic.co/t/elb-logs-grok-inside-grok/82615/2 "2017-04-18T23:19:37Z")

</div>

Can you provide a few lines of the log?

---

<div class="post-metadata">

**Author:** ![bob-bza](https://avatars.discourse-cdn.com/v4/letter/b/9f8e36/32.png) [@bob-bza](https://discuss.elastic.co/u/bob-bza)\
**Post date:** [April 19, 2017, 2:28am UTC](https://discuss.elastic.co/t/elb-logs-grok-inside-grok/82615/3 "2017-04-19T02:28:17Z")

</div>

> [@jkuang](#):
>
> Can you provide a few lines of the log?

2017-03-18T10:14:32.584347Z tf-lb-06d292ba3da94e1d307 64.3.9.38:40979 96.1.1.183:8080 0.00002 0.001577 0.000017 404 404 0 0 "GET [https://96.1.2.0:443/index.htm](https://96.1.2.0:443/index.htm) HTTP/1.1" "-" ECDHE-RSA-AES12HA256 TLSv1.2

---

<div class="post-metadata">

**Author:** ![jkuang](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jkuang/32/72637_2.png) [@jkuang](https://discuss.elastic.co/u/jkuang)\
**Post date:** [April 26, 2017, 11:42pm UTC](https://discuss.elastic.co/t/elb-logs-grok-inside-grok/82615/4 "2017-04-26T23:42:40Z")

</div>

It looks like the \*\* are the problem. Please use the grok below:

```auto
filter {

grok {
    match => ["message", "%{TIMESTAMP_ISO8601:timestamp} %{NOTSPACE:elb_name} %{IP:elb_client_ip}:%{INT:elb_client_port:int} (?:%{IP:elb_backend_ip}:%{NUMBER:elb_backend_port:int}|-) %{NUMBER:request_processing_time:float} %{NUMBER:backend_processing_time:float} %{NUMBER:response_processing_time:float} (?:%{INT:elb_status_code:int}|-) (?:%{INT:backend_status_code:int}|-) %{INT:elb_received_bytes:int} %{INT:elb_sent_bytes:int} \"(?:%{GREEDYDATA:elb_request}|-)\" \"(?:%{GREEDYDATA:userAgent}|-)\" %{NOTSPACE:elb_sslcipher} %{NOTSPACE:elb_sslprotocol}"] }

if [elb_status_code] =~ "400" {

grok { match => ["elb_status_code", "%{TIMESTAMP_ISO8601:timestamp} %{NOTSPACE:elb_sslprotocol}"]}

}
}

```

---

<div class="post-metadata">

**Author:** ![bob-bza](https://avatars.discourse-cdn.com/v4/letter/b/9f8e36/32.png) [@bob-bza](https://discuss.elastic.co/u/bob-bza)\
**Post date:** [April 27, 2017, 7:44pm UTC](https://discuss.elastic.co/t/elb-logs-grok-inside-grok/82615/5 "2017-04-27T19:44:30Z")

</div>

> [@jkuang](#):
>
> filter {
> 
> grok {  
> match =\> ["message", "%{TIMESTAMP\_ISO8601:timestamp} %{NOTSPACE:elb\_name} %{IP:elb\_client\_ip}:%{INT:elb\_client\_port:int} (?:%{IP:elb\_backend\_ip}:%{NUMBER:elb\_backend\_port:int}|-) %{NUMBER:request\_processing\_time:float} %{NUMBER:backend\_processing\_time:float} %{NUMBER:response\_processing\_time:float} (?:%{INT:elb\_status\_code:int}|-) (?:%{INT:backend\_status\_code:int}|-) %{INT:elb\_received\_bytes:int} %{INT:elb\_sent\_bytes:int} "(?:%{GREEDYDATA:elb\_request}|-)" "(?:%{GREEDYDATA:userAgent}|-)" %{NOTSPACE:elb\_sslcipher} %{NOTSPACE:elb\_sslprotocol}"] }
> 
> if [elb\_status\_code] =~ "400" {
> 
> grok { match =\> ["elb\_status\_code", "%{TIMESTAMP\_ISO8601:timestamp} %{NOTSPACE:elb\_sslprotocol}"]}
> 
> }  
> }

I was using same it dint worked as expected as i shown above. these \*\* i was trying to bold those wile posting in elastic discussions . so starts was added.

---

<div class="post-metadata">

**Author:** ![jkuang](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jkuang/32/72637_2.png) [@jkuang](https://discuss.elastic.co/u/jkuang)\
**Post date:** [May 1, 2017, 9:06pm UTC](https://discuss.elastic.co/t/elb-logs-grok-inside-grok/82615/6 "2017-05-01T21:06:07Z")

</div>

What is not working? Please elaborate. Since I only have one line of logging, and it passes through the filter into ES I don't see where the problem is.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 29, 2017, 9:17pm UTC](https://discuss.elastic.co/t/elb-logs-grok-inside-grok/82615/7 "2017-05-29T21:17:26Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
