# Grok filter for a custom message

**URL:** <https://discuss.elastic.co/t/grok-filter-for-a-custom-message/163527>\
**Category:** Logstash\
**Created:** [January 9, 2019, 12:27pm UTC](https://discuss.elastic.co/t/grok-filter-for-a-custom-message/163527 "2019-01-09T12:27:54Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![mrashid](https://avatars.discourse-cdn.com/v4/letter/m/9fc348/32.png) [@mrashid](https://discuss.elastic.co/u/mrashid)\
**Post date:** [January 9, 2019, 12:27pm UTC](https://discuss.elastic.co/t/grok-filter-for-a-custom-message/163527/1 "2019-01-09T12:27:54Z")

</div>

\*\*

> The build ID of the run is : 104

\*\*

I have the above line in the message field . I am trying to use Grok filter to extract the entire line to a new field by the name of "filteredValue".

**_WHat I have tried :_**

filter {  
grok {  
**match =\> { "message =\>%{{The build ID of the run is %{NUMBER}:filteredValue}}"}**  
}  
}

Please let me know where exactly I am making the mistake. Thank you.

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [January 9, 2019, 1:41pm UTC](https://discuss.elastic.co/t/grok-filter-for-a-custom-message/163527/2 "2019-01-09T13:41:24Z")

</div>

Try

```
grok { match => { "message" => "^The build ID of the run is : %{NUMBER:filteredValue}" } }
```

---

<div class="post-metadata">

**Author:** ![mrashid](https://avatars.discourse-cdn.com/v4/letter/m/9fc348/32.png) [@mrashid](https://discuss.elastic.co/u/mrashid)\
**Post date:** [January 10, 2019, 7:24am UTC](https://discuss.elastic.co/t/grok-filter-for-a-custom-message/163527/3 "2019-01-10T07:24:47Z")

</div>

Thank you so much for the input. I am able to filter. However, I am not getting the entire line in the field - "filteredValue" . I am getting only the number i.e 104 in the above line.

Is there any way to get the entire line ? Thanks in advance.

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [January 10, 2019, 2:01pm UTC](https://discuss.elastic.co/t/grok-filter-for-a-custom-message/163527/4 "2019-01-10T14:01:06Z")

</div>

If you want the entire event copied to a new field then I would suggest using a conditional to test that it is a line you care about and then using [mutate+copy](https://www.elastic.co/guide/en/logstash/current/plugins-filters-mutate.html#plugins-filters-mutate-copy) to copy message to some other field.

---

<div class="post-metadata">

**Author:** ![mrashid](https://avatars.discourse-cdn.com/v4/letter/m/9fc348/32.png) [@mrashid](https://discuss.elastic.co/u/mrashid)\
**Post date:** [January 10, 2019, 7:40pm UTC](https://discuss.elastic.co/t/grok-filter-for-a-custom-message/163527/5 "2019-01-10T19:40:22Z")

</div>

okay. Thank you. I will try and get back.

---

<div class="post-metadata">

**Author:** ![mrashid](https://avatars.discourse-cdn.com/v4/letter/m/9fc348/32.png) [@mrashid](https://discuss.elastic.co/u/mrashid)\
**Post date:** [January 10, 2019, 7:41pm UTC](https://discuss.elastic.co/t/grok-filter-for-a-custom-message/163527/6 "2019-01-10T19:41:32Z")

</div>

@Badger kindly give some input on this : [Copy data from a field and make it available for all the documents](https://discuss.elastic.co/t/copy-data-from-a-field-and-make-it-available-for-all-the-documents/163735)

Thanks a lot.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 7, 2019, 7:41pm UTC](https://discuss.elastic.co/t/grok-filter-for-a-custom-message/163527/7 "2019-02-07T19:41:35Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
