# Grok filter logstash config

**URL:** <https://discuss.elastic.co/t/grok-filter-logstash-config/45306>\
**Category:** Logstash\
**Created:** [March 24, 2016, 5:54am UTC](https://discuss.elastic.co/t/grok-filter-logstash-config/45306 "2016-03-24T05:54:22Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![bishaka](https://avatars.discourse-cdn.com/v4/letter/b/e480ec/32.png) [@bishaka](https://discuss.elastic.co/u/bishaka)\
**Post date:** [March 24, 2016, 5:54am UTC](https://discuss.elastic.co/t/grok-filter-logstash-config/45306/1 "2016-03-24T05:54:22Z")

</div>

Hi,  
Can somebody help me out here?  
So i am trying to use grok filter on a particular log file and I am having some trouble.

I used [http://grokdebug.herokuapp.com/](http://grokdebug.herokuapp.com/) to make a pattern, but I am having trouble with it

so I have the following log entry  
10:47:57,434 INFO [ACTIVE] ExecuteThread: '0' for queue: 'weblogic.kernel.Default (self-tuning)' access:14 - |rio|provisionWSG|https://129.4.7.96:543/mobile20/v1/provision/navo

I am having trouble extracting details from the following:  
|rio|provisionWSG|https://129.4.7.96:543/mobile20/v1/provision/navo

I am not able to separate the entire string and turn them into fields

I tried  
{  
"USERNAME": [  
[  
"rio"  
]  
],  
"NOTSPACE": [  
[  
"|provisionWSG|https://129.4.7.96:543/mobile20/v1/provision/navo"  
]  
]  
}

please help!

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [March 24, 2016, 5:57am UTC](https://discuss.elastic.co/t/grok-filter-logstash-config/45306/2 "2016-03-24T05:57:14Z")

</div>

What grok expression do you have so far?

---

<div class="post-metadata">

**Author:** ![bishaka](https://avatars.discourse-cdn.com/v4/letter/b/e480ec/32.png) [@bishaka](https://discuss.elastic.co/u/bishaka)\
**Post date:** [March 24, 2016, 7:39am UTC](https://discuss.elastic.co/t/grok-filter-logstash-config/45306/3 "2016-03-24T07:39:51Z")

</div>

For this line: |rio|provisionWSG|https://129.4.7.96:543/mobile20/v1/provision/navo

I have:  
%{USERNAME}%{NOTSPACE}

I have this for the entire line:  
10:47:57,434 INFO [ACTIVE] ExecuteThread: '0' for queue: 'weblogic.kernel.Default (self-tuning)' access:14 - |rio|provisionWSG|https://129.4.7.96:543/mobile20/v1/provision/navo

%{TIME},%{NUMBER} %{SPACE}%{WORD} %{NOTSPACE} %{SPACE}%{WORD:}%{NOTSPACE} %{NOTSPACE:Threadnumber} %{WORD} %{WORD}%{NOTSPACE} %{NOTSPACE} %{NOTSPACE} %{NOTSPACE} %{NOTSPACE} %{NOTSPACE}%{SYSLOGHOST}

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [March 24, 2016, 9:00am UTC](https://discuss.elastic.co/t/grok-filter-logstash-config/45306/4 "2016-03-24T09:00:41Z")

</div>

As I believe I said in another thread, you need to match the "|" characters. For your first example something like

```
\| %{NOTSPACE} \| %{NOTSPACE} \| %{NOTSPACE} 

```

would work.

---

<div class="post-metadata">

**Author:** ![bishaka](https://avatars.discourse-cdn.com/v4/letter/b/e480ec/32.png) [@bishaka](https://discuss.elastic.co/u/bishaka)\
**Post date:** [March 24, 2016, 4:31pm UTC](https://discuss.elastic.co/t/grok-filter-logstash-config/45306/5 "2016-03-24T16:31:28Z")

</div>

Thank you so much!  
This is what exactly I needed!

---

<div class="post-metadata">

**Author:** ![bishaka](https://avatars.discourse-cdn.com/v4/letter/b/e480ec/32.png) [@bishaka](https://discuss.elastic.co/u/bishaka)\
**Post date:** [March 24, 2016, 9:28pm UTC](https://discuss.elastic.co/t/grok-filter-logstash-config/45306/6 "2016-03-24T21:28:55Z")

</div>

Hi,  
Writing the queries in the grok filter will be bit of hassle if we have more complicated logs. Is there any alternatives I can use so that the fields are extracted from the logs without manually writing a query in logstash file with grok filter?

Please let me know! Thanks.

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [March 25, 2016, 10:09am UTC](https://discuss.elastic.co/t/grok-filter-logstash-config/45306/7 "2016-03-25T10:09:37Z")

</div>

Logstash doesn't contain any magic feature that parses your logs. You will, somehow, have to describe how they should be interpreted. Sometimes a grok filter is the best tool, other times a kv or csv filter is better, and sometimes you need a combination of these filters.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 5:05am UTC](https://discuss.elastic.co/t/grok-filter-logstash-config/45306/8 "2017-07-06T05:05:25Z")

</div>


