# Finding same pattern multiple times in one log file

**URL:** <https://discuss.elastic.co/t/finding-same-pattern-multiple-times-in-one-log-file/56196>\
**Category:** Logstash\
**Created:** [July 22, 2016, 3:46pm UTC](https://discuss.elastic.co/t/finding-same-pattern-multiple-times-in-one-log-file/56196 "2016-07-22T15:46:47Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![DJ1995](https://avatars.discourse-cdn.com/v4/letter/d/7bcc69/32.png) [@DJ1995](https://discuss.elastic.co/u/DJ1995)\
**Post date:** [July 22, 2016, 3:46pm UTC](https://discuss.elastic.co/t/finding-same-pattern-multiple-times-in-one-log-file/56196/1 "2016-07-22T15:46:47Z")

</div>

Hi, I'm new to using the elk so the question may be easy / make no sense. One pattern appears 3 times with different numbers inside my log file. I can use the grok filter with the match config to find the pattern at all three instances. But I want the field to be called a different name every time this pattern is found so I can make 3 different visuals on kibana. For example I tried something like:

grok {  
break\_on\_match =\> false  
match =\> { "message" =\> "%{NUMBER:blah:int}"}  
match =\> { "message" =\> "%{NUMBER:blah2:int}"}  
match =\> { "message" =\> "%{NUMBER:blah3:int}"}  
}

Thinking it would find the first instance -\> call it blah, find second instance -\> call it blah2, then find third instance -\> call it blah3. But this doesn't work. Is there any way to do such a thing?

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [July 22, 2016, 5:34pm UTC](https://discuss.elastic.co/t/finding-same-pattern-multiple-times-in-one-log-file/56196/2 "2016-07-22T17:34:35Z")

</div>

It's not quite clear from your question is these three occurrences appear in the same line or in different lines. Please show an example from your log file that exhibits the data you want to extract.

---

<div class="post-metadata">

**Author:** ![DJ1995](https://avatars.discourse-cdn.com/v4/letter/d/7bcc69/32.png) [@DJ1995](https://discuss.elastic.co/u/DJ1995)\
**Post date:** [July 22, 2016, 5:47pm UTC](https://discuss.elastic.co/t/finding-same-pattern-multiple-times-in-one-log-file/56196/3 "2016-07-22T17:47:08Z")

</div>

I was able to find a way to do this but thank you!

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [July 24, 2016, 1:02am UTC](https://discuss.elastic.co/t/finding-same-pattern-multiple-times-in-one-log-file/56196/4 "2016-07-24T01:02:25Z")

</div>

Can you share? It might be useful for others 🙂

---

<div class="post-metadata">

**Author:** ![DJ1995](https://avatars.discourse-cdn.com/v4/letter/d/7bcc69/32.png) [@DJ1995](https://discuss.elastic.co/u/DJ1995)\
**Post date:** [July 24, 2016, 6:41am UTC](https://discuss.elastic.co/t/finding-same-pattern-multiple-times-in-one-log-file/56196/5 "2016-07-24T06:41:05Z")

</div>

I still don't have a way to do it but I can use Kibana to add the sums of matches for that pattern which is good enough for me. I am using cucumber testing (u don't need to know what that is) on three components so the output, which is in one log file, is given the same way 3 different times. I can't really break the match up by components because of the way it is ran so I need a way to separate each output by giving it a different name.

Ex:  
-\> logs about running cucumber  
-\> ... (Useless logs)  
-\> "15 scenarios (1 failed, 2 skipped)"  
-\> logs about running cucumber  
-\>... (Useless logs)  
-\> "6 scenarios (2 failed, 0 skipped)"  
-\> logs about running cucumber  
-\>... (Useless logs)  
-\> "8 scenarios (3 failed, 1 skipped)"  
-\> ... (Useless logs)

I wanted to do something that says first time you find this pattern call it this: "%{NUMBER:firstTotal} scenarios ( %{NUMBER:firstFailed} failed, %{NUMBER:firstSkipped} skipped)".

Second time call it: this: "%{NUMBER:secondTotal} scenarios ( %{NUMBER:secondFailed} failed, %{NUMBER:secondSkipped} skipped.

Etc..  
This way I can have separate fields for the 3 instances.

---

<div class="post-metadata">

**Author:** ![mahsa\_b](https://avatars.discourse-cdn.com/v4/letter/m/4af34b/32.png) [@mahsa\_b](https://discuss.elastic.co/u/mahsa_b)\
**Post date:** [May 30, 2017, 4:50pm UTC](https://discuss.elastic.co/t/finding-same-pattern-multiple-times-in-one-log-file/56196/6 "2017-05-30T16:50:44Z")

</div>

I have the same problem.  
I am reading multiline from input and trying to match all the instances of the pattern. but it only output the first instance and not the rest. I'm not sure where I am making the mistake. this is my conf file content:  
input {  
file {  
# change the path in your local to make it work  
path =\> "/usr/local/src/logstash/log1.in"  
start\_position =\> beginning  
sincedb\_path =\> "/dev/null"  
codec =\> multiline {  
pattern =\> "^show"  
negate =\> true  
what =\> next  
}  
}  
}

filter {  
grok {  
# pay attention to the path  
patterns\_dir =\> ["./patterns/mypatterns"]  
match =\> {"message" =\> ["(?m)configure vlan %{WORD:vlan} add ports %{PORTS:ports} %{TAG\_INFO:tag\_info}"]}  
break\_on\_match =\> false  
}  
}

output {  
stdout {  
codec =\> rubydebug  
}  
}

and this is the content of [log1.in](http://log1.in)  
configure snmp sysName "NY\_MPBN\_SS\_1"  
configure snmp sysLocation "GSI New York"  
configure snmp sysContact "JPoserio@globecommsystems.com"  
configure timezone name New\_Yor -240  
configure sys-recovery-level switch reset

configure vlan CH\_ACCESS add ports 19, 28, 46-47 tagged  
configure vlan CN\_GN add ports 10, 46-47 tagged  
configure vlan CN\_GN add ports 12 untagged  
configure vlan CN\_Gn\_GSN\_1 add ports 3-8, 46 tagged  
configure vlan Default add ports 50 untagged  
show switch

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [May 30, 2017, 11:30pm UTC](https://discuss.elastic.co/t/finding-same-pattern-multiple-times-in-one-log-file/56196/7 "2017-05-30T23:30:15Z")

</div>

You should create your own thread for this question 🙂

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 4:26am UTC](https://discuss.elastic.co/t/finding-same-pattern-multiple-times-in-one-log-file/56196/8 "2017-07-06T04:26:13Z")

</div>


