# GROK filter for JBOSS

**URL:** https://discuss.elastic.co/t/grok-filter-for-jboss/26917
**Category:** Logstash
**Created:** [August 5, 2015, 6:47pm UTC](https://discuss.elastic.co/t/grok-filter-for-jboss/26917 "2015-08-05T18:47:53Z")
**Posts on this page:** 9
**Page:** 1

<div class="post-metadata">

### Author: ![mgirndt](https://avatars.discourse-cdn.com/v4/letter/m/fbc32d/32.png) [@mgirndt](https://discuss.elastic.co/u/mgirndt)
#### Post date: [August 5, 2015, 6:47pm UTC](https://discuss.elastic.co/t/grok-filter-for-jboss/26917/1 "2015-08-05T18:47:53Z")

</div>

I'm new to the ELK stack and I'm trying to setup a GROK filter with multi-line pattern but I'm not having any luck.  
The pattern formatter I am needing is "%d{HH:mm:ss,SSS} %-5p [%c] {%t) %s%E%n"/  
I am also needing for the timestamp in Kibana to so the time from the Log and not the time that Elasticsearch received the log. Any help is greatly appreciated.

Thanks,  
Michael

---

<div class="post-metadata">

### Author: ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)
#### Post date: [August 5, 2015, 7:35pm UTC](https://discuss.elastic.co/t/grok-filter-for-jboss/26917/2 "2015-08-05T19:35:20Z")

</div>

If you post an example log message you're more likely to get help. Keep in mind that these messages can span multiple lines. There should be several examples of how to deal with that in the archives.

---

<div class="post-metadata">

### Author: ![mgirndt](https://avatars.discourse-cdn.com/v4/letter/m/fbc32d/32.png) [@mgirndt](https://discuss.elastic.co/u/mgirndt)
#### Post date: [August 5, 2015, 7:42pm UTC](https://discuss.elastic.co/t/grok-filter-for-jboss/26917/3 "2015-08-05T19:42:45Z")

</div>

Here is an example of a log  
14:33:07,069 INFO [net.jawr.web.resource.bundle.factory.BundlesHandlerFactory] (ServerService Thread Pool -- 74) Adding custom bundle definitions.

---

<div class="post-metadata">

### Author: ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)
#### Post date: [August 5, 2015, 7:48pm UTC](https://discuss.elastic.co/t/grok-filter-for-jboss/26917/4 "2015-08-05T19:48:22Z")

</div>

Does the name of the file contain the date? Otherwise you're going to have problems getting a reliable timestamp. Ignoring the timestamp issue for a while, the following grok filter probably works:

```
filter {
  grok {
    match => [
      "message", 
      "%{TIME:time} %{LOGLEVEL:level} \[(?<logger>[^\]]+)\] \((?<thread>[^)]+)\) %{GREEDYDATA:message}"
    ]
    overwrite => ["message"]
  }
}
```

---

<div class="post-metadata">

### Author: ![mgirndt](https://avatars.discourse-cdn.com/v4/letter/m/fbc32d/32.png) [@mgirndt](https://discuss.elastic.co/u/mgirndt)
#### Post date: [August 10, 2015, 7:45pm UTC](https://discuss.elastic.co/t/grok-filter-for-jboss/26917/5 "2015-08-10T19:45:50Z")

</div>

I have added the date into the log file and the new log looks like:  
August 10 2015 10:07:01,048 INFO [org.jboss.as.naming] (ServerService Thread Pool -- 38) JBAS011800: Activating Naming Subsystem

my current grok filter is:  
filter {  
if [type] == "jboss" {  
grok {  
match =\> [  
"message",  
"%{TIME:time} %{LOGLEVEL:level}.\*[(?[^]]+)] ((?[^)]+)) %{GREEDYDATA:message}"  
]  
overwrite =\> ["message"]  
}  
}

How can I get the date to show up with the time when looking in Kibana. The @timestamp tag in Kibana is showing the time that elasticsearch did its thing, but not the actual time of the log.

Thanks,  
Michael

---

<div class="post-metadata">

### Author: ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)
#### Post date: [August 10, 2015, 8:23pm UTC](https://discuss.elastic.co/t/grok-filter-for-jboss/26917/6 "2015-08-10T20:23:52Z")

</div>

Use the [date filter](https://www.elastic.co/guide/en/logstash/current/plugins-filters-date.html). Something like

```
date {
  match => ["time", "MMM dd YYYY HH:mm:ss,SSS"]
  remove_field => ["time"]
}

```

should work.

---

<div class="post-metadata">

### Author: ![mgirndt](https://avatars.discourse-cdn.com/v4/letter/m/fbc32d/32.png) [@mgirndt](https://discuss.elastic.co/u/mgirndt)
#### Post date: [August 11, 2015, 2:03pm UTC](https://discuss.elastic.co/t/grok-filter-for-jboss/26917/7 "2015-08-11T14:03:11Z")

</div>

Where does it fit into my current filter?

---

<div class="post-metadata">

### Author: ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)
#### Post date: [August 11, 2015, 2:08pm UTC](https://discuss.elastic.co/t/grok-filter-for-jboss/26917/8 "2015-08-11T14:08:05Z")

</div>

Add it after your current grok filter.

```
filter {
  grok {
    ...
  }
  date {
    ..
  }
}
```

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [July 6, 2017, 5:32am UTC](https://discuss.elastic.co/t/grok-filter-for-jboss/26917/9 "2017-07-06T05:32:20Z")

</div>


