# Grok create an array not a string

**URL:** <https://discuss.elastic.co/t/grok-create-an-array-not-a-string/227352>\
**Category:** Logstash\
**Created:** [April 9, 2020, 2:56pm UTC](https://discuss.elastic.co/t/grok-create-an-array-not-a-string/227352 "2020-04-09T14:56:07Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![nico88](https://avatars.discourse-cdn.com/v4/letter/n/c0e974/32.png) [@nico88](https://discuss.elastic.co/u/nico88)\
**Post date:** [April 9, 2020, 2:56pm UTC](https://discuss.elastic.co/t/grok-create-an-array-not-a-string/227352/1 "2020-04-09T14:56:07Z")

</div>

Hello,

I try to grok a tacacs authentification log file from tac plus.

Ex of log line :  
2020-04-09 16:13:26 +0200 10.2.0.163 test tty2 8.8.8.8 shell login succeeded

This is my filter :

```auto
   filter {
     if [type] == "Tacacs" {

     if [log][file][path] == "/var/log/tac_plus/authentication.log" {
     grok {
           match => { "message" => "%{YEAR}-%{MONTHNUM}-%{MONTHDAY} %{HOUR}:%{MINUTE}:%{SECOND} \+0200	%{IP:destination.ip}	%{USER:user.name}%{SPACE}(%{NOTSPACE}%{SPACE})?%{IP:source.ip}	shell login %{WORD:tacacs.outcome}(%{GREEDYDATA})?" }
     }
     if [tacacs.outcome] == "succeeded" {
       mutate {
         add_field => { "event.outcome" => "success" }
       }
     } else {
       mutate {
         add_field => { "event.outcome" => "failure" }
       }
     }

     mutate {
       add_field => { "event.category" => "authentication" }
     }
   }
     }
   }

```

I don't know why but I get value as array:

```
  "destination.ip": [
      "10.2.0.163",
      "10.2.0.163"
    ],

  "event.outcome": [
      "success",
      "failure"
    ],    
"event.category": [
      "authentication",
      "authentication"
    ],
    "source.ip": [
      "8.8.8.8",
      "8.8.8.8"
    ],

```

Can you help me to understand where is my problem ?

Thank you for your help 😊

---

<div class="post-metadata">

**Author:** ![grumo35](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/grumo35/32/59451_2.png) [@grumo35](https://discuss.elastic.co/u/grumo35)\
**Post date:** [April 9, 2020, 3:57pm UTC](https://discuss.elastic.co/t/grok-create-an-array-not-a-string/227352/2 "2020-04-09T15:57:01Z")

</div>

Hi,

The values you showed as array are they from an actual document request in elasticsearch ?

Can you be more precise about how you ship the logs to logstash and the configuration used ? It looks like the log is parsed by something else.

---

<div class="post-metadata">

**Author:** ![nico88](https://avatars.discourse-cdn.com/v4/letter/n/c0e974/32.png) [@nico88](https://discuss.elastic.co/u/nico88)\
**Post date:** [April 9, 2020, 4:14pm UTC](https://discuss.elastic.co/t/grok-create-an-array-not-a-string/227352/3 "2020-04-09T16:14:08Z")

</div>

Thanks for the solution, it was that, I copy paste twice my filter...

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 7, 2020, 4:17pm UTC](https://discuss.elastic.co/t/grok-create-an-array-not-a-string/227352/4 "2020-05-07T16:17:59Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
