# Grok filter patterns for syslog

**URL:** <https://discuss.elastic.co/t/grok-filter-patterns-for-syslog/43628>\
**Category:** Logstash\
**Created:** [March 7, 2016, 8:50am UTC](https://discuss.elastic.co/t/grok-filter-patterns-for-syslog/43628 "2016-03-07T08:50:15Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Shreejit\_Nair](https://avatars.discourse-cdn.com/v4/letter/s/13edae/32.png) [@Shreejit\_Nair](https://discuss.elastic.co/u/Shreejit_Nair)\
**Post date:** [March 7, 2016, 8:50am UTC](https://discuss.elastic.co/t/grok-filter-patterns-for-syslog/43628/1 "2016-03-07T08:50:15Z")

</div>

Hi All,

I am new to logstash and still learning something new about this cool tool everyday.

I found that grok pattens work only with the patter we define

Like %{IP:client} %{WORD:method} %{URIPATHPARAM:request} %{NUMBER:bytes} %{NUMBER:duration} will work only for this "55.3.244.1 GET /index.html 15824 0.043" log entry in log file.

I want to know if there is any way to deal with grok patterns for log files which have huge records (with different patterns). In that case defining pattern for each line in Syslog will not be possible.

Please suggest how to deal with such a situation.

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [March 7, 2016, 6:29pm UTC](https://discuss.elastic.co/t/grok-filter-patterns-for-syslog/43628/2 "2016-03-07T18:29:47Z")

</div>

> I found that grok pattens work only with the patter we define

Not sure what you mean, but Logstash won't guess how to parse your logs. You need to tell it how to do it.

> I want to know if there is any way to deal with grok patterns for log files which have huge records (with different patterns). In that case defining pattern for each line in Syslog will not be possible.

Please give some examples.

---

<div class="post-metadata">

**Author:** ![michalterbert](https://avatars.discourse-cdn.com/v4/letter/m/848f3c/32.png) [@michalterbert](https://discuss.elastic.co/u/michalterbert)\
**Post date:** [March 7, 2016, 7:12pm UTC](https://discuss.elastic.co/t/grok-filter-patterns-for-syslog/43628/3 "2016-03-07T19:12:11Z")

</div>

one of the best sites for grok patterns (with autodiscovery function):  
[https://grokdebug.herokuapp.com/](https://grokdebug.herokuapp.com/)

take a look.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 5:08am UTC](https://discuss.elastic.co/t/grok-filter-patterns-for-syslog/43628/4 "2017-07-06T05:08:07Z")

</div>


