# Grok filter some entries have additional fields

**URL:** https://discuss.elastic.co/t/grok-filter-some-entries-have-additional-fields/308092
**Category:** Logstash
**Created:** [June 24, 2022, 9:19am UTC](https://discuss.elastic.co/t/grok-filter-some-entries-have-additional-fields/308092 "2022-06-24T09:19:34Z")
**Posts on this page:** 4
**Page:** 1

<div class="post-metadata">

### Author: ![tartaarsap](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tartaarsap/32/99611_2.png) [@tartaarsap](https://discuss.elastic.co/u/tartaarsap)
#### Post date: [June 24, 2022, 9:19am UTC](https://discuss.elastic.co/t/grok-filter-some-entries-have-additional-fields/308092/1 "2022-06-24T09:19:34Z")

</div>

I have the following dataset:

```auto
1613766382 FILE %computerName% MACB [4096] c:/$MFTMirr
1613766382 FILE %computerName% MACB [4096] c:/$MFTMirr ($FILE_NAME)

```

I am trying to build a GROK filter to match on both lines. However, I can only seem to get them both individually working.

My current filter (trying to work with optional a field):

```auto
grok
	{
	    match => {"message" => "%{INT:Date} %{GREEDYDATA:File} %{GREEDYDATA:ComputerName} %{GREEDYDATA:MACB} %{GREEDYDATA:Size} %{GREEDYDATA:Path} (%{GREEDYDATA:Filename})?"}
	}

```

This filter works on all lines with the $(FILE\_NAME) behind it, but will give a parsing error on the first line in my dataset.

What is the best way to get this to work?

---

<div class="post-metadata">

### Author: ![sudhagar\_ramesh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sudhagar_ramesh/32/105673_2.png) [@sudhagar\_ramesh](https://discuss.elastic.co/u/sudhagar_ramesh)
#### Post date: [June 24, 2022, 11:15am UTC](https://discuss.elastic.co/t/grok-filter-some-entries-have-additional-fields/308092/2 "2022-06-24T11:15:30Z")

</div>

Hello @tartaarsap

You can try this below grok pattern which is working fine for the both of log lines.

`%{INT:Date} %{DATA:File} %{DATA:ComputerName} %{DATA:MACB} \[%{DATA:Size}\] %{GREEDYDATA:Filename}`

PFA for the result

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/0/3/03d62ed071f8e413b7b276e8eaaad3973f7a42b0.png)

Keep Posted !!! Thanks !!!

---

<div class="post-metadata">

### Author: ![tartaarsap](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tartaarsap/32/99611_2.png) [@tartaarsap](https://discuss.elastic.co/u/tartaarsap)
#### Post date: [June 24, 2022, 1:55pm UTC](https://discuss.elastic.co/t/grok-filter-some-entries-have-additional-fields/308092/3 "2022-06-24T13:55:46Z")

</div>

> [@tartaarsap](#):
>
> ```auto
> 1613766382 FILE %computerName% MACB [4096] c:/$MFTMirr ($FILE_NAME)
> 
> ```

Thanks a lot this is perfect :)!

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [July 22, 2022, 1:56pm UTC](https://discuss.elastic.co/t/grok-filter-some-entries-have-additional-fields/308092/4 "2022-07-22T13:56:39Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
