# Grok Debugger - hard to find identification string for my difficult example

**URL:** <https://discuss.elastic.co/t/grok-debugger-hard-to-find-identification-string-for-my-difficult-example/182016>\
**Category:** Logstash\
**Created:** [May 21, 2019, 1:50pm UTC](https://discuss.elastic.co/t/grok-debugger-hard-to-find-identification-string-for-my-difficult-example/182016 "2019-05-21T13:50:38Z")\
**Posts on this page:** 12\
**Page:** 1

<div class="post-metadata">

**Author:** ![Datakids](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/datakids/32/39622_2.png) [@Datakids](https://discuss.elastic.co/u/Datakids)\
**Post date:** [May 21, 2019, 1:50pm UTC](https://discuss.elastic.co/t/grok-debugger-hard-to-find-identification-string-for-my-difficult-example/182016/1 "2019-05-21T13:50:39Z")

</div>

> `{Result=[{Index=1, PropertyName=, ResourceA1=here, ResourceA2=heretoo, ResourceA3=hereagain, ResourceA4=herewego, ResourceKey=transactions.ui.rfc.messages.label.defaultMessage, ServiceKey='6457A5674GF01ED98EAC1Z9934909736', ServiceName=transactions_Simulations, Text=alliswellstructured-:o), Type=2},`

Hi @ all,  
i struggle with above mentioned unstructured pattern and would like to extract parts into  
5 new fields while indexing using logstash grok :  
`ResourceA1=here`  
`ResourceA2=heretoo`  
`ResourceA3=hereagain`  
`ResourceA4=herewego`  
`Text=alliswellstructured-:o)`

Due to its specific start and length  
I'm unable to solve the right pattern.  
Hope you can help.

Thanks in advance

---

<div class="post-metadata">

**Author:** ![sjabiulla](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sjabiulla/32/48429_2.png) [@sjabiulla](https://discuss.elastic.co/u/sjabiulla)\
**Post date:** [May 21, 2019, 2:03pm UTC](https://discuss.elastic.co/t/grok-debugger-hard-to-find-identification-string-for-my-difficult-example/182016/2 "2019-05-21T14:03:22Z")

</div>

You can use KV filter, as your log is already in Key Value format.

```
filter{
	kv{ 
		source => "message" 
	}
}

```

Edit : You can use mutate filter to remove the fields that you don't want to index, because kv filter will add all the keys present in the log as fields.

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [May 21, 2019, 2:26pm UTC](https://discuss.elastic.co/t/grok-debugger-hard-to-find-identification-string-for-my-difficult-example/182016/3 "2019-05-21T14:26:18Z")

</div>

I would suggest

```
mutate { gsub => ["message", "^{Result=\[{", ""] }
kv { field_split => "," value_split => "=" trim_key => " " }
```

---

<div class="post-metadata">

**Author:** ![Datakids](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/datakids/32/39622_2.png) [@Datakids](https://discuss.elastic.co/u/Datakids)\
**Post date:** [May 22, 2019, 6:52am UTC](https://discuss.elastic.co/t/grok-debugger-hard-to-find-identification-string-for-my-difficult-example/182016/4 "2019-05-22T06:52:03Z")

</div>

Hi,  
wow if I'd known how easy that is...  
Thanks for reply

---

<div class="post-metadata">

**Author:** ![Datakids](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/datakids/32/39622_2.png) [@Datakids](https://discuss.elastic.co/u/Datakids)\
**Post date:** [May 22, 2019, 7:21am UTC](https://discuss.elastic.co/t/grok-debugger-hard-to-find-identification-string-for-my-difficult-example/182016/5 "2019-05-22T07:21:13Z")

</div>

Hi,  
thanks too for reply but I'm unsure where to close the missing braces in right way?  
Thats like try and error

---

<div class="post-metadata">

**Author:** ![Datakids](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/datakids/32/39622_2.png) [@Datakids](https://discuss.elastic.co/u/Datakids)\
**Post date:** [May 23, 2019, 2:28pm UTC](https://discuss.elastic.co/t/grok-debugger-hard-to-find-identification-string-for-my-difficult-example/182016/6 "2019-05-23T14:28:19Z")

</div>

Hi all,

I found a way to handle this case as good as possible @ my personal experience level but for my knowledge I have one more question:

> {Result=[{ bla=2, bla=4, bla6 ,Type=2}]}

The First Entry removed by:

```
mutate {
gsub => ["getMessage", "^{Result=\[", ""]}

```

_Works!_

Now Id like to remove the last entry with like a similar gsub:

```
mutate {
gsub => ["getMessage", "^,Type=2\}\]\}", "" ]}

```

But it wont work!

Please let me know how I can remove it!

Thanks

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [May 23, 2019, 2:51pm UTC](https://discuss.elastic.co/t/grok-debugger-hard-to-find-identification-string-for-my-difficult-example/182016/7 "2019-05-23T14:51:50Z")

</div>

> [@Datakids](#):
>
> ```
> gsub => ["getMessage", "^,Type=2\}\]\}", "" ]}
> 
> ```

] has a special meaning in a regexp (it closes a character group) so it needs to be escaped using \. That is not the case for }, which does not need to be escaped.

---

<div class="post-metadata">

**Author:** ![Datakids](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/datakids/32/39622_2.png) [@Datakids](https://discuss.elastic.co/u/Datakids)\
**Post date:** [May 23, 2019, 3:08pm UTC](https://discuss.elastic.co/t/grok-debugger-hard-to-find-identification-string-for-my-difficult-example/182016/8 "2019-05-23T15:08:35Z")

</div>

Oh man then I were right but tought I were wrong because the Closed Square Bracket behind Type2 associated to the opening and the obvious to close were not obvious though...

![grafik](https://us1.discourse-cdn.com/elastic/original/3X/8/3/838d29919aba26095fbd387fb212c5d477053a71.png)

Thanks, you saved my day 😉

---

<div class="post-metadata">

**Author:** ![Datakids](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/datakids/32/39622_2.png) [@Datakids](https://discuss.elastic.co/u/Datakids)\
**Post date:** [May 23, 2019, 3:19pm UTC](https://discuss.elastic.co/t/grok-debugger-hard-to-find-identification-string-for-my-difficult-example/182016/9 "2019-05-23T15:19:04Z")

</div>

> [@Badger](#):
>
> > [@Datakids](#):
> >
> > ```
> > gsub => ["getMessage", "^,Type=2\}\]\}", "" ]}
> > 
> > ```
> 
> ] has a special meaning in a regexp (it closes a character group) so it needs to be escaped using \. That is not the case for }, which does not need to be escaped.

me again, its not working  
,Type=2}]}  
still part of the pattern  
What I Did to solve:

First remove all Brackets then the field itself:

```
mutate {
gsub => ["getMessage", "\\[|\\]", "" ]}
	
mutate {
gsub => ["getMessage", "\{\}", ""]}

mutate {
gsub => ["getMessage", "Type=2", ""]}

```

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [May 23, 2019, 3:27pm UTC](https://discuss.elastic.co/t/grok-debugger-hard-to-find-identification-string-for-my-difficult-example/182016/10 "2019-05-23T15:27:56Z")

</div>

```
mutate { gsub => ["message", ",Type=2}\]}$", "" ]}

```

should work. You were anchoring the pattern to ^.

---

<div class="post-metadata">

**Author:** ![Datakids](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/datakids/32/39622_2.png) [@Datakids](https://discuss.elastic.co/u/Datakids)\
**Post date:** [May 23, 2019, 3:38pm UTC](https://discuss.elastic.co/t/grok-debugger-hard-to-find-identification-string-for-my-difficult-example/182016/11 "2019-05-23T15:38:32Z")

</div>

no sadly no 🙂`,Type=2}]}` still there  
and thats the reason why I have headaches of thus hmm... 😤 logstash filter...  
Many ways to Rom but none arrives...

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 20, 2019, 3:44pm UTC](https://discuss.elastic.co/t/grok-debugger-hard-to-find-identification-string-for-my-difficult-example/182016/12 "2019-06-20T15:44:00Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
