# Formatting data as a block in logstash

**URL:** <https://discuss.elastic.co/t/formatting-data-as-a-block-in-logstash/282027>\
**Category:** Logstash\
**Created:** [August 20, 2021, 3:47am UTC](https://discuss.elastic.co/t/formatting-data-as-a-block-in-logstash/282027 "2021-08-20T03:47:31Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![selin](https://avatars.discourse-cdn.com/v4/letter/s/9de053/32.png) [@selin](https://discuss.elastic.co/u/selin)\
**Post date:** [August 20, 2021, 3:47am UTC](https://discuss.elastic.co/t/formatting-data-as-a-block-in-logstash/282027/1 "2021-08-20T03:47:31Z")

</div>

Below is my sample data. How can it be filter based on start time and end time using grok pattern. Any idea friends since the data came as a stream of blocks. Can you guys suggest and provid example. I need to know start time , end time, success or fail. if fail the messge

```auto
++++++++++++++++++++++++++++++++++++++++++++++
Name: My file name
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Begin Date:	MM/DD/YYYY
Begin Time:	HH:MM:SS

Activity
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
YYYY-MM-DD HH:MM:SS message
YYYY-MM-DD HH:MM:SS message
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Result
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
messge Completed
End Date:	MM/DD/YYYY
End Time:	HH:MM:SS
Executed by: Name
++++++++++++++++++++++++++++++++++++++++++++++

++++++++++++++++++++++++++++++++++++++++++++++
Name: My file name
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Begin Date:	MM/DD/YYYY
Begin Time:	HH:MM:SS

Activity
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
YYYY-MM-DD HH:MM:SS message
YYYY-MM-DD HH:MM:SS message
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Result
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
message Failed
ERROR:	message
ERROR:	message
  at stacktrace
  at stacktrace
Caused by: message
  at stacktrace
  at stacktrace
	
End Date:	MM/DD/YYYY
End Time:	HH:MM:SS
Executed by: Name
++++++++++++++++++++++++++++++++++++++++++++++

```

---

<div class="post-metadata">

**Author:** ![AquaX](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/aquax/32/92006_2.png) [@AquaX](https://discuss.elastic.co/u/AquaX)\
**Post date:** [August 24, 2021, 6:36pm UTC](https://discuss.elastic.co/t/formatting-data-as-a-block-in-logstash/282027/2 "2021-08-24T18:36:52Z")

</div>

A couple of hints I can think of.  
First you need to use a multiline input and capture everything between the "++++++" lines.  
Like this:  
`++++++++++++++++++++++++++++++++++++++++++++++ Name: My file name ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~Begin Date:	10/13/1987 Begin Time:	HH:MM:SS Activity~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ YYYY-MM-DD HH:MM:SS message YYYY-MM-DD HH:MM:SS message ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~Result~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ messge Completed End Date:	MM/DD/YYYY End Time:	HH:MM:SS Executed by: Name ++++++++++++++++++++++++++++++++++++++++++++++`

Then use a grok pattern (going to be ugly) to cut out the pieces that you need.

I started playing around with it a little bit (assuming that all newline characters were removed and the entire thing could be handled as a single line event.

`\+ Name: %{DATA:my_file_name} \~%{NOTSPACE} Begin Date:	%{NUMBER:Month}`

This will get you this:

```auto

  "my_file_name": [
    [
      "My file name"
    ]
  ],
  "NOTSPACE": [
    [
      " ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~"
    ]
  ],
  "Month": [
    [
      "10"
    ]
  ],
  "BASE10NUM": [
    [
      "10"
    ]
  ]
}

```

Check out [https://grokdebug.herokuapp.com/](https://grokdebug.herokuapp.com/) to help you figure out the rest.  
Good luck.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 21, 2021, 6:37pm UTC](https://discuss.elastic.co/t/formatting-data-as-a-block-in-logstash/282027/3 "2021-09-21T18:37:03Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
