# Grok - Extracting words between two phrases that remain constant

**URL:** <https://discuss.elastic.co/t/grok-extracting-words-between-two-phrases-that-remain-constant/326901>\
**Category:** Logstash\
**Created:** [March 3, 2023, 3:57am UTC](https://discuss.elastic.co/t/grok-extracting-words-between-two-phrases-that-remain-constant/326901 "2023-03-03T03:57:20Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![demonsquatch](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/demonsquatch/32/88611_2.png) [@demonsquatch](https://discuss.elastic.co/u/demonsquatch)\
**Post date:** [March 3, 2023, 3:57am UTC](https://discuss.elastic.co/t/grok-extracting-words-between-two-phrases-that-remain-constant/326901/1 "2023-03-03T03:57:20Z")

</div>

Hi All,

I'm currently trying to extract a VM name from vSphere logs and am having some issues as the VM names can be of variable length and contain an array of characters. So far the only delimiting factor for separating the name out is that part of the message leads with "A ticket for " and immediately after the VM name is "of type". For example, in the below sample data I am trying to extract "CHICAGO - DB" as vm.name. So far I am able to get the first part trimmed out, but have not found any resources on ensuring the name ends whenever the words "of type" appear. Below is the sample data and Grok pattern. Any help would be appreciated!

Sample Data:  
[A ticket for CHICAGO - DB of type webmks on 172.16.124.32 in DATACENTER has been acquired]

Grok Pattern:  
[A ticket for (%{DATA:vm.name})]

Results:  
"vm": {  
"name": "CHICAGO - DB of type webmks on 172.16.124.32 in DATACENTER has been acquired"  
}

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [March 3, 2023, 4:08am UTC](https://discuss.elastic.co/t/grok-extracting-words-between-two-phrases-that-remain-constant/326901/2 "2023-03-03T04:08:17Z")

</div>

> [@demonsquatch](#):
>
> A ticket for (%{DATA:vm.name})

Try `A ticket for %{DATA:vm.name} of `

If you want a [vm] object with a [name] field inside it then use [vm][name] instead of vm.name. vm.name will create a field with a period in its name.

---

<div class="post-metadata">

**Author:** ![demonsquatch](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/demonsquatch/32/88611_2.png) [@demonsquatch](https://discuss.elastic.co/u/demonsquatch)\
**Post date:** [March 3, 2023, 5:47pm UTC](https://discuss.elastic.co/t/grok-extracting-words-between-two-phrases-that-remain-constant/326901/3 "2023-03-03T17:47:46Z")

</div>

Worked like a charm - thank you so much!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 31, 2023, 5:47pm UTC](https://discuss.elastic.co/t/grok-extracting-words-between-two-phrases-that-remain-constant/326901/4 "2023-03-31T17:47:48Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
