# Grok filter multiple match

**URL:** <https://discuss.elastic.co/t/grok-filter-multiple-match/202248>\
**Category:** Logstash\
**Created:** [October 3, 2019, 9:46pm UTC](https://discuss.elastic.co/t/grok-filter-multiple-match/202248 "2019-10-03T21:46:58Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![cactus](https://avatars.discourse-cdn.com/v4/letter/c/f475e1/32.png) [@cactus](https://discuss.elastic.co/u/cactus)\
**Post date:** [October 3, 2019, 9:46pm UTC](https://discuss.elastic.co/t/grok-filter-multiple-match/202248/1 "2019-10-03T21:46:58Z")

</div>

Hello,

Can someone point me to a proper way with grok parsing? 🙂

I want to parse syslog messages, for this purpose I created 2 syslog pattern within grok:

```auto
filter {
  if [type] == 'syslog' {
  	grok {
      match => { 'message' => ['%{TIMESTAMP_ISO8601:syslog_timestamp} %{SYSLOGHOST:syslog_hostname} %{DATA:syslog_program}(?:\[%{POSINT:syslog_pid}\])?: %{GREEDYDATA:syslog_message}',
                '%{SYSLOGTIMESTAMP:syslog_timestamp} %{SYSLOGHOST:syslog_hostname} %{DATA:syslog_program}(?:\[%{POSINT:syslog_pid}\])?: %{GREEDYDATA:syslog_message}'] }
      add_field => ['received_from', "%{host}"]
    }
    syslog_pri { }
    date {
      match => ["syslog_timestamp", "MMM d HH:mm:ss", "MMM dd HH:mm:ss", "ISO8601"]
      target => ["@timestamp"]
    }

```

I need to have 2 patterns because some hosts sends log in ISO8601 format and the rest in traditional(I might b wrong here but I understand it like that).

According to LS documentation - it's correct code for grok:  
[https://www.elastic.co/guide/en/logstash/current/plugins-filters-grok.html#plugins-filters-grok-match](https://www.elastic.co/guide/en/logstash/current/plugins-filters-grok.html#plugins-filters-grok-match)

`If you need to match multiple patterns against a single field, the value can be an array of patterns:`

```auto
filter {
      grok {
        match => {
          "message" => [
            "Duration: %{NUMBER:duration}",
            "Speed: %{NUMBER:speed}"
          ]
        }
      }
    }

```

Is it possible to parse syslog messages using next construction:

```auto
filter {
  if [type] == 'syslog' {
  	grok {
      match => { 'message' => '%{TIMESTAMP_ISO8601:syslog_timestamp} %{SYSLOGHOST:syslog_hostname} %{DATA:syslog_program}(?:\[%{POSINT:syslog_pid}\])?: %{GREEDYDATA:syslog_message}' }
      add_field => ['received_from', "%{host}"]
    }
    syslog_pri { }
    date {
      match => ["syslog_timestamp", "ISO8601"]
      target => ["@timestamp"]
    }

filter {
  if [type] == 'syslog' {
  	grok {
      match => { 'message' => '%{SYSLOGTIMESTAMP:syslog_timestamp} %{SYSLOGHOST:syslog_hostname} %{DATA:syslog_program}(?:\[%{POSINT:syslog_pid}\])?: %{GREEDYDATA:syslog_message}' }
      add_field => ['received_from', "%{host}"]
    }
    syslog_pri { }
    date {
      match => ["syslog_timestamp", "MMM d HH:mm:ss", "MMM dd HH:mm:ss"]
      target => ["@timestamp"]
    }

```

1. Can I use more than 1 pattern within grok filter?
2. If I will use more than 1 pattern - will it cause delays in log parsing or logs going to parse in wrong way(I will get \_grokparsefailure for example)?
3. What approach is best - first or second and why?
4. What is the best way to parse logs using more than 1 pattern.

Thank you.

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [October 3, 2019, 10:14pm UTC](https://discuss.elastic.co/t/grok-filter-multiple-match/202248/2 "2019-10-03T22:14:17Z")

</div>

You can use more than one pattern in a filter. You should read [this](https://www.elastic.co/blog/do-you-grok-grok), which will help you understand why you should anchor your patterns using ^ if they are expected to match the start of a line. There is very little overhead using multiple patterns if you do that.

---

<div class="post-metadata">

**Author:** ![cactus](https://avatars.discourse-cdn.com/v4/letter/c/f475e1/32.png) [@cactus](https://discuss.elastic.co/u/cactus)\
**Post date:** [October 3, 2019, 10:35pm UTC](https://discuss.elastic.co/t/grok-filter-multiple-match/202248/3 "2019-10-03T22:35:27Z")

</div>

Thank you, reading now....  
How about constructions above? What of them is more correct - when I used multiple matching or when I used grok filter twice against one type: syslog?

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [October 3, 2019, 10:54pm UTC](https://discuss.elastic.co/t/grok-filter-multiple-match/202248/4 "2019-10-03T22:54:16Z")

</div>

Personally I would use an array of patterns.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 31, 2019, 10:54pm UTC](https://discuss.elastic.co/t/grok-filter-multiple-match/202248/5 "2019-10-31T22:54:22Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
