# Grok: filter options match not create new field

**URL:** <https://discuss.elastic.co/t/grok-filter-options-match-not-create-new-field/170499>\
**Category:** Logstash\
**Created:** [March 1, 2019, 1:01pm UTC](https://discuss.elastic.co/t/grok-filter-options-match-not-create-new-field/170499 "2019-03-01T13:01:58Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Ret](https://avatars.discourse-cdn.com/v4/letter/r/87869e/32.png) [@Ret](https://discuss.elastic.co/u/Ret)\
**Post date:** [March 1, 2019, 1:01pm UTC](https://discuss.elastic.co/t/grok-filter-options-match-not-create-new-field/170499/1 "2019-03-01T13:01:59Z")

</div>

Hi everyone !

I am collecting Windows Event Logs from winlogbeat with Logstash. And I have some problem grok filter.

I created custom pattren for find user account in event log ..... And the pattern working in Kibana Grok Debuger but grok filter not create new field.

**Text wich need parsing**

> TF53010: The following error has occurred in a Team Foundation component or extension:  
> Date (UTC): 3/1/2019 9:55:44 AM  
> Machine: ALMVMTEST2  
> Application Domain: /LM/W3SVC/2/ROOT/tfs-1-131956424397262984  
> Assembly: Microsoft.TeamFoundation.Framework.Server, Version=16.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a; v4.0.30319  
> Service Host: d162e475-ce02-44b3-b3c5-9da898c7efed (DefaultCollection)  
> Process Details:  
> Process Name: w3wp  
> Process Id: 4220  
> Thread Id: 5412  
> Account name: contoso\user

Grok pattern config file **winevent.grok:**

`EVENT_ACCOUNT (?<=Account name: ).*(?<!\s)`

**logstah config**

```
    input {
      beats {
        port => 5044
      }
    }

    filter {
        grok {
    	patterns_dir => "/etc/logstash/patterns"
    	match => { "message" => ["%{EVENT_ACCOUNT}: Account"] }

         }
    }

    output {
      stdout { 
    	codec => rubydebug
        }
     
      elasticsearch {
        hosts => ["http://localhost:9200"]
        index => "%{[@metadata][beat]}-%{[@metadata][version]}-%{+YYYY.MM.dd}"
        #user => "elastic"
        #password => "changeme"
      }
    }

```

Any thoughts why not working?  
Thanks!

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [March 1, 2019, 1:54pm UTC](https://discuss.elastic.co/t/grok-filter-options-match-not-create-new-field/170499/2 "2019-03-01T13:54:17Z")

</div>

Since account name is the last item in the message you can use

```
    grok { match => { message => "^Account name: (?<accountName>.*)" } }

```

If you wanted to extract a line from the middle of the message you could use a pattern that matches zero-or-more characters that are not newline followed by a newline.

```
    grok { match => { message => "^Process Name: (?<processName>[^
]*)
" } }
```

---

<div class="post-metadata">

**Author:** ![Ret](https://avatars.discourse-cdn.com/v4/letter/r/87869e/32.png) [@Ret](https://discuss.elastic.co/u/Ret)\
**Post date:** [March 4, 2019, 7:12am UTC](https://discuss.elastic.co/t/grok-filter-options-match-not-create-new-field/170499/3 "2019-03-04T07:12:51Z")

</div>

@Badger, thank you very much. This solved my problem.

Pattern that works for me:

`grok { match => { message => "Process Name: (?<processName>[^\s]*)" } }`

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 1, 2019, 7:12am UTC](https://discuss.elastic.co/t/grok-filter-options-match-not-create-new-field/170499/4 "2019-04-01T07:12:51Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
