# Grok Custom filter

**URL:** <https://discuss.elastic.co/t/grok-custom-filter/151523>\
**Category:** Logstash\
**Created:** [October 8, 2018, 9:44pm UTC](https://discuss.elastic.co/t/grok-custom-filter/151523 "2018-10-08T21:44:42Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![zolthar-z](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/zolthar-z/32/47895_2.png) [@zolthar-z](https://discuss.elastic.co/u/zolthar-z)\
**Post date:** [October 8, 2018, 9:44pm UTC](https://discuss.elastic.co/t/grok-custom-filter/151523/1 "2018-10-08T21:44:42Z")

</div>

Hi

I'm new in ELK and I've installed the app for log management. I have a legacy application and want to make some tranformation to the logs, right now a I recevied the logs in the following format:

2018-10-08 13:06:28,710 DEBUG [Job] SID=[078] ServiceRunning: new service created

The idea is have the output with the next format

Datestamps: 2018-10-08 13:06:28,710  
level: DEBUG  
SID: 078  
Message: ServiceRunning: new service created

I have tried with differents filters like "%{DATESTAMP} %{LOGLEVEL:level} %{WORD:SID}" but the output doesn't show as I expected, So I was wondering if maybe one of you know if is possible create that output with logstash filters

Thanks in advance for your help.

Regards.

---

<div class="post-metadata">

**Author:** ![Tek\_Chand](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tek_chand/32/34318_2.png) [@Tek\_Chand](https://discuss.elastic.co/u/Tek_Chand)\
**Post date:** [October 9, 2018, 9:20am UTC](https://discuss.elastic.co/t/grok-custom-filter/151523/2 "2018-10-09T09:20:39Z")

</div>

@Luis, Please try the below pattern for your log:

```auto
(?<datestamp>[\w\-\s\:]+)\,(?<pid>[\w]+)\s(?<loglevel>[\w]+)\s\[\w+\]\s\w+\=\[(?<SID>[\w]+)\]\s(?<message>.*)

```

Thanks

---

<div class="post-metadata">

**Author:** ![zolthar-z](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/zolthar-z/32/47895_2.png) [@zolthar-z](https://discuss.elastic.co/u/zolthar-z)\
**Post date:** [October 9, 2018, 3:07pm UTC](https://discuss.elastic.co/t/grok-custom-filter/151523/3 "2018-10-09T15:07:35Z")

</div>

> [@Tek\_Chand](#):
>
> (?\<datestamp\>[\w-\s:]+),(?\<pid\>[\w]+)\s(?\<loglevel\>[\w]+)\s[\w+]\s\w+=[(?\<SID\>[\w]+)]\s(?\<message\>.\*)

Hi @Tek_Chand, thanks for the information, it works perfectly!!!, Do you know where I can find the meaning or how I can do all the filters that you apply ? Thanks again.

---

<div class="post-metadata">

**Author:** ![Tek\_Chand](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tek_chand/32/34318_2.png) [@Tek\_Chand](https://discuss.elastic.co/u/Tek_Chand)\
**Post date:** [October 10, 2018, 3:18am UTC](https://discuss.elastic.co/t/grok-custom-filter/151523/4 "2018-10-10T03:18:33Z")

</div>

Hello Luis,

You should have some idea of regex to write the filter. Please refer the below link for some basic regex symbol:

[https://en.wikipedia.org/wiki/Regular\_expression](https://en.wikipedia.org/wiki/Regular_expression)

You can use grok debugger to write filter for your logs pattern. Please refer the below link:

[https://grokdebug.herokuapp.com/](https://grokdebug.herokuapp.com/)

Thanks.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 7, 2018, 3:18am UTC](https://discuss.elastic.co/t/grok-custom-filter/151523/5 "2018-11-07T03:18:38Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
