# Grok filter parsing tibco

**URL:** <https://discuss.elastic.co/t/grok-filter-parsing-tibco/43688>\
**Category:** Logstash\
**Created:** [March 7, 2016, 6:48pm UTC](https://discuss.elastic.co/t/grok-filter-parsing-tibco/43688 "2016-03-07T18:48:09Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![Sureshkumar](https://avatars.discourse-cdn.com/v4/letter/s/c2a13f/32.png) [@Sureshkumar](https://discuss.elastic.co/u/Sureshkumar)\
**Post date:** [March 7, 2016, 6:48pm UTC](https://discuss.elastic.co/t/grok-filter-parsing-tibco/43688/1 "2016-03-07T18:48:09Z")

</div>

Currently i am parsing the tibco log using grok filter  
below is logs  
2016 Mar 07 04:01:04:145 GMT -8 BW.TESServices-APPTST-TESTServices-APPTST-P13 User [BW-User] - Job-129210119 [UtilityProcesses/CreateAuditTrail.process/Log]: AuditTrail: 129210119|DeviceFlags|||||2016-03-07T04:01:04.145-08:00|TESTServices-APPTST-TESTServices-APPTST-P13|LOC|DeviceID - Device Model|Number|||SSS|12|45455.

IN the grok debugger i am getting partial result but when i forwarding to logstash getting grok failure error.

Any help Please.

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [March 7, 2016, 6:57pm UTC](https://discuss.elastic.co/t/grok-filter-parsing-tibco/43688/2 "2016-03-07T18:57:45Z")

</div>

You should edit this message and move it to the Logstash category.

Logstash's grok filter doesn't do partial matches. The expression either matches (and then you get all fields) or it doesn't match (and then you get nothing). If that doesn't answer your question you need to post your current grok filter to get help.

---

<div class="post-metadata">

**Author:** ![Sureshkumar](https://avatars.discourse-cdn.com/v4/letter/s/c2a13f/32.png) [@Sureshkumar](https://discuss.elastic.co/u/Sureshkumar)\
**Post date:** [March 7, 2016, 6:58pm UTC](https://discuss.elastic.co/t/grok-filter-parsing-tibco/43688/3 "2016-03-07T18:58:32Z")

</div>

%{CISCOTIMESTAMP} GMT %{NUMBER} %{URIHOST} %{CISCO\_REASON} %{SYSLOG5424SD:user} - %{URIHOST:jobid} %{SYSLOG5424SD:audit}:%{GREEDYDATA:message}

i am not able to split below things using from audit trail its gives greedy message.

AuditTrail: 129210119|DeviceFlags|||||2016-03-07T04:01:04.145-08:00|TESTServices-APPTST-TESTServices-APPTST-P13|LOC|DeviceID - Device Model|Number|||SSS|12|45455.

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [March 7, 2016, 7:01pm UTC](https://discuss.elastic.co/t/grok-filter-parsing-tibco/43688/4 "2016-03-07T19:01:04Z")

</div>

> i am not able to split below things using from audit trail its gives greedy message.

I don't understand this sentence. Does the grok expression work up until the GREEDYDATA pattern? And you're unsure of how to parse the rest?

---

<div class="post-metadata">

**Author:** ![Sureshkumar](https://avatars.discourse-cdn.com/v4/letter/s/c2a13f/32.png) [@Sureshkumar](https://discuss.elastic.co/u/Sureshkumar)\
**Post date:** [March 7, 2016, 7:03pm UTC](https://discuss.elastic.co/t/grok-filter-parsing-tibco/43688/5 "2016-03-07T19:03:16Z")

</div>

sorry for the confusion.

My question is don't know how to parse the rest of the sentence.

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [March 7, 2016, 7:31pm UTC](https://discuss.elastic.co/t/grok-filter-parsing-tibco/43688/6 "2016-03-07T19:31:08Z")

</div>

You can use the csv filter for that.

---

<div class="post-metadata">

**Author:** ![Sureshkumar](https://avatars.discourse-cdn.com/v4/letter/s/c2a13f/32.png) [@Sureshkumar](https://discuss.elastic.co/u/Sureshkumar)\
**Post date:** [March 7, 2016, 8:48pm UTC](https://discuss.elastic.co/t/grok-filter-parsing-tibco/43688/7 "2016-03-07T20:48:27Z")

</div>

Thanks for the reply. Do you have any samples combined with grok filter along with CSV filter?

OR

You are suggesting me to use csv filter for all?

Thanks and Regards  
Suresh kumar.A

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [March 7, 2016, 9:29pm UTC](https://discuss.elastic.co/t/grok-filter-parsing-tibco/43688/8 "2016-03-07T21:29:58Z")

</div>

Use the grok filter to extract the `|`-separated string into a field of its own (if you want to name that field `message` remember to set the grok filter's [`overwrite` option](https://www.elastic.co/guide/en/logstash/current/plugins-filters-grok.html#plugins-filters-grok-overwrite)), then feed that field through the csv filter.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 5:08am UTC](https://discuss.elastic.co/t/grok-filter-parsing-tibco/43688/9 "2017-07-06T05:08:05Z")

</div>


