# Fields are merge grok output

**URL:** <https://discuss.elastic.co/t/fields-are-merge-grok-output/233988>\
**Category:** Logstash\
**Created:** [May 23, 2020, 10:04am UTC](https://discuss.elastic.co/t/fields-are-merge-grok-output/233988 "2020-05-23T10:04:10Z")\
**Posts on this page:** 1\
**Showing post:** 5

<div class="post-metadata">

**Author:** ![pup\_seba](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/pup_seba/32/42988_2.png) [@pup\_seba](https://discuss.elastic.co/u/pup_seba)\
**Post date:** [May 23, 2020, 4:39pm UTC](https://discuss.elastic.co/t/fields-are-merge-grok-output/233988/5 "2020-05-23T16:39:00Z")

</div>

Hi himalc 🙂

I think I did not understand your initial expected output then. So, I guess that instead of this:

```auto
sessionID result=> 731-ufsN
query_field result=> {"myquery","client","time","total_time"}
query_stats result=>{"select * db_states;","tcp:myhost:12336","10","15"}

```

You actually expect this output:

```auto
sessionID result=> 731-ufsN
query_str => myquery
client => client
execution_time_ms => time
total_time_ms => total_time
query_stats => {"select * db_states;","tcp:myhost:12336","10","15"}
query_field => "myquery" + "client" + "time" + "total_time"

```

If this is the case, then I guess you need a grok filter AND a mutate filter. The grok would look like this:

```auto
%{TIME:timex} %{WORD:Ix} %{NUMBER:nox} (?<code>[^\s]*) %{WORD:stdlog} %{WORD:type} %{NUMBER:numbery} %{NUMBER:noh} %{WORD:dbtype} %{WORD:loguserx} (?<sessionID>[^\s]*) {(?<query_str>[^,]*),(?<client>[^,]*),(?<execution_time_ms>[^,]*),(?<total_time_ms>[^}]*)}{(?<query_stats>[^}]*)}$

```

Then, you would need to "construct" the query\_stats field, and this is where you use the "mutate" filter. I can't test it right now, but this post could help you [Adding a field from existing ones](https://discuss.elastic.co/t/adding-a-field-from-existing-ones/77697).

The formula I'm using in the grok is quite easy and is always the same. Basically I use some literals to "pinpoint" somethings (look at the commas for instance, those are just literal matches).  
Then I use this extended group (?subexp) over and over again 🙂 You can see more info about that here: [https://github.com/kkos/oniguruma/blob/master/doc/RE](https://github.com/kkos/oniguruma/blob/master/doc/RE)

Then is only a regular expression where I just match "any character until (^) the character which in most cases is a comma. Then I just use a quantifier (_) so I match "all the characters" until the negation. For this you'll see "(?\<field\_name\>[^,]_).

Hope this helped you.

---

_[View the full topic](https://discuss.elastic.co/t/fields-are-merge-grok-output/233988)._
