# Grok Filter..so close... yet so far

**URL:** <https://discuss.elastic.co/t/grok-filter-so-close-yet-so-far/303592>\
**Category:** Logstash\
**Created:** [April 29, 2022, 10:22am UTC](https://discuss.elastic.co/t/grok-filter-so-close-yet-so-far/303592 "2022-04-29T10:22:38Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![joshn](https://avatars.discourse-cdn.com/v4/letter/j/d2c977/32.png) [@joshn](https://discuss.elastic.co/u/joshn)\
**Post date:** [April 29, 2022, 10:22am UTC](https://discuss.elastic.co/t/grok-filter-so-close-yet-so-far/303592/1 "2022-04-29T10:22:38Z")

</div>

I'm using this website to debug my Grok code: [https://grokdebug.herokuapp.com/](https://grokdebug.herokuapp.com/)

Two different logs I'm trying to ingest:

1:

```auto
<134>1 1651225979.448642514 EMEA_ISP ip_flow_end src=192.168.15.6 dst=8.8.4.4 protocol=udp sport=43026 dport=53 translated_src_ip=193.117.158.139 translated_port=4302

```

2:

```auto
<134>1 1651226889.364970820 EMEA_ISP ip_flow_start src=192.168.15.115 dst=8.8.8.8 protocol=icmp translated_src_ip=193.117.158.13

```

Grok Filter that gets me 99% of the way there:

```auto
ip_flow_end src=%{IP:src_ip} dst=%{IP:dst_ip} protocol=%{WORD:protocol} sport=%{NUMBER:src_port} dport=%{NUMBER:dst_port} 

```

This gives me the following fields, however it would be REALLY nice to have the "ip\_flow\_endorstart" message broken up to give me the end/start as a field I can then search on.

I tried this, but it doesn't seem to like it or work?

```auto
ip_flow_%{WORD:action} src=%{IP:src_ip} dst=%{IP:dst_ip} protocol=%{WORD:protocol} sport=%{NUMBER:src_port} dport=%{NUMBER:dst_port} 

```

Any help is much appreciated.

---

<div class="post-metadata">

**Author:** ![aaron-nimocks](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/aaron-nimocks/32/73965_2.png) [@aaron-nimocks](https://discuss.elastic.co/u/aaron-nimocks)\
**Post date:** [April 29, 2022, 11:55am UTC](https://discuss.elastic.co/t/grok-filter-so-close-yet-so-far/303592/2 "2022-04-29T11:55:48Z")

</div>

Try `ip_flow_%{GREEDYDATA:action}`.

---

<div class="post-metadata">

**Author:** ![joshn](https://avatars.discourse-cdn.com/v4/letter/j/d2c977/32.png) [@joshn](https://discuss.elastic.co/u/joshn)\
**Post date:** [April 29, 2022, 2:13pm UTC](https://discuss.elastic.co/t/grok-filter-so-close-yet-so-far/303592/3 "2022-04-29T14:13:16Z")

</div>

eurgh - you guys and girls are just the best! thanks 🙂

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 27, 2022, 2:14pm UTC](https://discuss.elastic.co/t/grok-filter-so-close-yet-so-far/303592/4 "2022-05-27T14:14:08Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
