# Grok Debugger 사용 시 결과값이 중복해서 나오는 이유?

**URL:** <https://discuss.elastic.co/t/grok-debugger/189020>\
**Category:** 한국어 질문 및 토론\
**Created:** [July 5, 2019, 7:01am UTC](https://discuss.elastic.co/t/grok-debugger/189020 "2019-07-05T07:01:33Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![philshikkim](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/philshikkim/32/48341_2.png) [@philshikkim](https://discuss.elastic.co/u/philshikkim)\
**Post date:** [July 5, 2019, 7:01am UTC](https://discuss.elastic.co/t/grok-debugger/189020/1 "2019-07-05T07:01:33Z")

</div>

이제 막 시작한 초봅니다.

logstash에 conf 파일에 filter를 적용시키기 전에, Grok Debugger 사용해서 테스트 해 보는대, 원하지 않는 부분이 중복되서 보여 집니다.

원문은 아래와 같은 아래와 같고,  
172.16.12.230 Sep 04 17:20:36 local7 info mdserver VIPM\_detect\_free: \<switch\_mac=001AF4.499244\>\<switch\_ip=172.22.9.216\>\<switch\_hostname=I\_B\_5F\_03\>\<date=2018/09/04\>\<time=17:27:34\>\<port=26\>\<attacker=172.22.9.168\>\<dip=any\>\<protocol=TCP\>\<sport=Any\>\<dport=80\>\<signame=Random\_Attack\>\<action=Drop\>\<packet\_count=547\>\<end\_date=2018/09/04\>\<end\_time=17:29:34\>

패턴은 아래와 같습니다.  
{IP:origin}\t%{SYSLOGTIMESTAMP:syslogSVRtime}\t\t%{DATA:facility}\t%{LOGLEVEL:severity}\t%{DATA:mdserver}\t%{DATA:vipm}: \<%{SwitchMAC:switch\_mac}\>\<%{SwitchIP:switch\_ip}\>\<%{SwitchHOSTNAME:switch\_hostname}\>\<%{STARTD:start\_date}\>\<%{STARTT:start\_time}\>\<%{ETHP:ethport}\>\<%{ATTACKER:attacker\_ip}\>\<%{VICTIM:victim\_ip}\>\<%{PROTO:protocol}\>\<%{SPORT:srcport}\>\<%{DPORT:dstport}\>\<%{SIG:signature}\>\<%{ACT:action}\>\<%{PKTNO:attack\_packet\_count}\>\<%{ENDD:end\_date}\>\<%{ENDT:end\_time}\>

적용한 커스텀 패턴  
ADD Address=%{IP:origin}  
SwitchMAC switch\_mac=%{DATA:switch\_mac}  
SwitchIP switch\_ip=%{DATA:switch\_ip}  
SwitchHOSTNAME switch\_hostname=%{DATA:switch\_hostname}  
STARTD date=%{GREEDYDATA}  
STARTT time=%{DATA:start\_time}  
ETHP port=%{DATA:ethport}  
ATTACKER attacker=%{DATA:attacker\_ip}  
VICTIM dip=%{DATA:victim\_ip}  
PROTO protocol=%{DATA:protocol}  
SPORT sport=%{DATA:srcport}  
DPORT dport=%{DATA:dstport}  
SIG signame=%{GREEDYDATA:signature}  
ACT action=%{DATA:action}  
PKTNO packet\_count=%{NUMBER:attack\_packet\_count}  
ENDD end\_date=%{GREEDYDATA}  
ENDT end\_time=%{DATA:end\_time}

위와 같이 하고 실행 하면, 몇몇 부분에서 중복된 결과값이 보입니다. 예를 들면,

"switch\_ip": [  
[  
"switch\_ip=172.22.9.216"  
],  
[  
"172.22.9.216"  
]  
]

위와 같이 나오는대, 실제로 원하는 결과값은 IP 주소만인데, "switch\_ip=172.22.9.216" 같이 나오네요.

해결책이 있을까요?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 2, 2019, 7:01am UTC](https://discuss.elastic.co/t/grok-debugger/189020/2 "2019-08-02T07:01:38Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
