# Filebeat ingest pipeline Grok pattern

**URL:** <https://discuss.elastic.co/t/filebeat-ingest-pipeline-grok-pattern/243866>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [August 5, 2020, 12:31pm UTC](https://discuss.elastic.co/t/filebeat-ingest-pipeline-grok-pattern/243866 "2020-08-05T12:31:45Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![vladtepes](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/vladtepes/32/64982_2.png) [@vladtepes](https://discuss.elastic.co/u/vladtepes)\
**Post date:** [August 5, 2020, 12:31pm UTC](https://discuss.elastic.co/t/filebeat-ingest-pipeline-grok-pattern/243866/1 "2020-08-05T12:31:45Z")

</div>

Must be something really simple, but am struggling to make it work. 😕  
The sample log line:  
2020-07-29 12:17:16.948 **+02:00** [80000025-0002-ff00-b63f-84710c7967bb] [Some.Text.Goes.Here.Controllers.UserController] [DBG] Starting api/me

This timezone segment is giving me a headache. I cannot match it with TIMESTAMP\_ISO8601.  
If we ignore the date and timezone, so far I can Grok it with this pattern:  
[%{UUID:Correlation}] [%{GREEDYDATA:Source}] [%{WORD:Level}] %{GREEDYDATA:Message}

Did somebody work with this kind of Date format?

---

<div class="post-metadata">

**Author:** ![vladtepes](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/vladtepes/32/64982_2.png) [@vladtepes](https://discuss.elastic.co/u/vladtepes)\
**Post date:** [August 5, 2020, 12:43pm UTC](https://discuss.elastic.co/t/filebeat-ingest-pipeline-grok-pattern/243866/2 "2020-08-05T12:43:20Z")

</div>

I figured it out. Should be no space between the datetime and timezone

2020-07-29 12:17:16.948 **+02:00** =\> **2020-07-29 12:17:16.948+02:00**

Then this would Grok it successfully:  
%{TIMESTAMP\_ISO8601:timestamp} [%{UUID:Correlation}] [%{GREEDYDATA:Source}] [%{WORD:Level}] %{GREEDYDATA:Message}

---

<div class="post-metadata">

**Author:** ![Rom1](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rom1/32/49699_2.png) [@Rom1](https://discuss.elastic.co/u/Rom1)\
**Post date:** [August 5, 2020, 12:46pm UTC](https://discuss.elastic.co/t/filebeat-ingest-pipeline-grok-pattern/243866/3 "2020-08-05T12:46:38Z")

</div>

Yes, I was writting the same.

If you can not change your logs, you have to separate the date and the timezone with this following grok pattern:

```auto
%{TIMESTAMP_ISO8601:date} %{ISO8601_TIMEZONE:timezone} \[%{UUID:Correlation}\] \[%{GREEDYDATA:Source}\] \[%{WORD:Level}\] %{GREEDYDATA:Message}

```

Then you have to concatenate 'date' and 'timezone' and use the date filter plugin to transform your date to a valid UTC date.

---

<div class="post-metadata">

**Author:** ![vladtepes](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/vladtepes/32/64982_2.png) [@vladtepes](https://discuss.elastic.co/u/vladtepes)\
**Post date:** [August 5, 2020, 12:51pm UTC](https://discuss.elastic.co/t/filebeat-ingest-pipeline-grok-pattern/243866/4 "2020-08-05T12:51:28Z")

</div>

Thanks @Rom1! That is a better answer. 😉

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 2, 2020, 2:51pm UTC](https://discuss.elastic.co/t/filebeat-ingest-pipeline-grok-pattern/243866/5 "2020-09-02T14:51:37Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
