# Grok filter and pattern in logstash

**URL:** <https://discuss.elastic.co/t/grok-filter-and-pattern-in-logstash/92404>\
**Category:** Logstash\
**Created:** [July 10, 2017, 1:07am UTC](https://discuss.elastic.co/t/grok-filter-and-pattern-in-logstash/92404 "2017-07-10T01:07:36Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![0314e7ff87c297426a9e](https://avatars.discourse-cdn.com/v4/letter/0/a3d4f5/32.png) [@0314e7ff87c297426a9e](https://discuss.elastic.co/u/0314e7ff87c297426a9e)\
**Post date:** [July 10, 2017, 1:07am UTC](https://discuss.elastic.co/t/grok-filter-and-pattern-in-logstash/92404/1 "2017-07-10T01:07:37Z")

</div>

I filtered the log using the grok pattern in logstash. The result logdata is too long. I want to disconnect from the loglevel unit, what should I do?

--my logdata--

[DEBUG] [2017-07-10 09:53:35,411] pporan.maven.framework.db.QueryInterceptor.intercept(QueryInterceptor.java:58) -@@@@@@@@@ parameter @@@@@@@@@@  
{curPage2=1, search\_use\_yn=Y, bn\_sche\_seq=0, pageBlockSize=5, endPage=5, \_servletResponse=jeus.servlet.engine.HttpServletResponseImpl@3132707d, \_servletRequest= jeus.servlet.engine.WebtobServletRequest@667737c6, version\_cd=VER02, startPage=0, pageRowSize=5, bn\_sche\_seq\_arr=[20029, 20028, 20027, 20024, 20022]}  
[DEBUG] [2017-07-10 09:53:35,412] pporan.maven.framework.db.QueryInterceptor.intercept(QueryInterceptor.java:60) -@\>\> end QueryInterceptor.  
[DEBUG] [2017-07-10 09:53:35,418] pporan.maven.framework.db.QueryInterceptor.intercept(QueryInterceptor.java:34) -@\>\> start QueryInterceptor.  
[DEBUG] [2017-07-10 09:53:35,426] pporan.maven.framework.db.QueryInterceptor.intercept(QueryInterceptor.java:56) -@@@@@@@@@ interceptor method is : query  
[DEBUG] [2017-07-10 09:53:35,426] pporan.maven.framework.db.QueryInterceptor.intercept(QueryInterceptor.java:57) -@@@@@@@@@ query @@@@@@@@@@  
SELECT AA.\*  
, CASE WHEN AB.PLT\_SEQ IS NULL THEN 'N' ELSE 'Y' END AS RES\_YN  
, CASE WHEN AB.PLT\_CNT \<= AB.RES\_CNT THEN 'Y' ELSE 'N' END AS ALL\_YN  
FROM (  
SELECT A.SEQ  
, A.SEQ AS SA\_SEQ  
, [A.NAME](http://A.NAME)  
, [A.NAME](http://A.NAME) AS SA\_NAME  
, A.SA\_ID  
, A.RES\_YN  
, COUNT(_) OVER() AS AS\_CNT  
FROM PLATFORM CA  
WHERE A.TT\_YN = 'Y'  
GROUP BY AS.SEQ, [AS.NAME](http://AS.NAME), A.AS\_ID, A.AS\_YN  
) AA  
LEFT OUTER JOIN  
(  
SELECT AS\_SEQ  
, COUNT(_) OVER() AS RES\_CNT  
FROM SCHE\_AS\_MAP  
WHERE SCHE\_SEQ = ?  
AND SCHE\_KRR\_CD = ?  
) BB  
ON AA.SEQ = BB.AS\_SEQ  
ORDER BY AA.SEQ

-------------------------------- LOGSTASH CONF FILE-----------------------  
input {  
file{  
path=\> ["/program/file/log/mylog2\__.log"]  
codec =\> multiline {  
pattern =\> "(^\d+\serror)|(^.+Exception: .+)|(^\s+at .+)|(^\s+... \d+ more)|(^\s_Caused by:.+)|(^\D.+)"  
what =\> "previous"  
}  
}  
}

## filter{ date{ timezone =\> "Asia/Seoul" match =\> ["timestamp" , "yyyy-MM-dd HH:mm:ss, SSS"] locale =\> "kr" remove\_field =\> ["timestamp"] } grok{ patterns\_dir =\> ["../pattern"] match =\> {"message" =\> ["[%{LOGLEVEL:loglevel}] [%{TIMESTAMP\_ISO8601:timestamp}] %{PACKAGE\_NAME:packageName}(%{SOURCE\_INFO}) %{GREEDYDATA:logData}"]} } mutate { add\_field =\>{ "type" =\> "TADMIN" } } } output { if "\_grokparsefailure" not in [tags]{ elasticsearch { hosts =\> "202.3.21.93" index =\> "logstash-%{+YYYY.MM.dd}" document\_type =\> "tadminLog" #index =\> "tadminlogs" } stdout { codec =\> rubydebug { } } file { path=\>["/program/logstash/logstash.log"] } } }

* * *

plz help me

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [July 11, 2017, 8:18pm UTC](https://discuss.elastic.co/t/grok-filter-and-pattern-in-logstash/92404/2 "2017-07-11T20:18:43Z")

</div>

> I want to disconnect from the loglevel unit, what should I do?

I don't understand what you mean. Perhaps an example of what you want to accomplish would help?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 8, 2017, 8:19pm UTC](https://discuss.elastic.co/t/grok-filter-and-pattern-in-logstash/92404/3 "2017-08-08T20:19:07Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
