# Grok filter to retrieve simple words or character from text/string

**URL:** <https://discuss.elastic.co/t/grok-filter-to-retrieve-simple-words-or-character-from-text-string/109177>\
**Category:** Logstash\
**Created:** [November 27, 2017, 7:25am UTC](https://discuss.elastic.co/t/grok-filter-to-retrieve-simple-words-or-character-from-text-string/109177 "2017-11-27T07:25:41Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![scch](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/scch/32/25504_2.png) [@scch](https://discuss.elastic.co/u/scch)\
**Post date:** [November 27, 2017, 7:25am UTC](https://discuss.elastic.co/t/grok-filter-to-retrieve-simple-words-or-character-from-text-string/109177/1 "2017-11-27T07:25:42Z")

</div>

Hi , I have used CSV filter to import data .  
Can someone share example code to use grok filter to retrieve simple words from fields imported previously through csv filter and add them to new field.  
up to last dot

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [November 27, 2017, 9:10am UTC](https://discuss.elastic.co/t/grok-filter-to-retrieve-simple-words-or-character-from-text-string/109177/2 "2017-11-27T09:10:08Z")

</div>

```nohighlight
grok {
   match => ["filenamefield", "\.(?<extension>[^.]+)$"]
}

```

---

<div class="post-metadata">

**Author:** ![scch](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/scch/32/25504_2.png) [@scch](https://discuss.elastic.co/u/scch)\
**Post date:** [November 27, 2017, 2:39pm UTC](https://discuss.elastic.co/t/grok-filter-to-retrieve-simple-words-or-character-from-text-string/109177/3 "2017-11-27T14:39:27Z")

</div>

> [@magnusbaeck](#):
>
> grok {  
> match =\> ["filenamefield", ".(?\<extension\>[^.]+)$"]  
> }

Thanks Magnus however it is not working 🙂 do i need to make some changes  
Also can you guide me to some tutorial apart from grok resource on Elasticsearch website.

by adding above code, data got accumulated in to one field "type" and there is a field tags which says "\_grokparsefailure"

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [November 27, 2017, 8:56pm UTC](https://discuss.elastic.co/t/grok-filter-to-retrieve-simple-words-or-character-from-text-string/109177/4 "2017-11-27T20:56:39Z")

</div>

> do i need to make some changes

Well, you should obviously replace "filenamefield" with the name of the field containing the filename from which you want to extract the filename extension.

But to help more than that I need to see your configuration and what an example event looks like. Use a `stdout { codec => rubydebug }` output.

> Also can you guide me to some tutorial apart from grok resource on Elasticsearch website.

Grok expressions are more or less regular expressions and there are tons of resources describing how they work.

---

<div class="post-metadata">

**Author:** ![scch](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/scch/32/25504_2.png) [@scch](https://discuss.elastic.co/u/scch)\
**Post date:** [November 30, 2017, 2:00pm UTC](https://discuss.elastic.co/t/grok-filter-to-retrieve-simple-words-or-character-from-text-string/109177/5 "2017-11-30T14:00:25Z")

</div>

Hi Magnus,  
Thanks it is working 😀  
one more issue if the file name does not have any extension .jpg .bmp etc..  
rubydebug say's \>\>\>\>\> **"tags" =\> [[0] "\_grokparsefailure"** ],

how to handle this exception.? is there a way to put "TXT" where file extension not found.

---

<div class="post-metadata">

**Author:** ![scch](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/scch/32/25504_2.png) [@scch](https://discuss.elastic.co/u/scch)\
**Post date:** [November 30, 2017, 2:05pm UTC](https://discuss.elastic.co/t/grok-filter-to-retrieve-simple-words-or-character-from-text-string/109177/6 "2017-11-30T14:05:18Z")

</div>

![image](https://us1.discourse-cdn.com/elastic/original/3X/a/4/a4f629a1f7c902a72a71ac2a0614bcac9705e718.png) and can you explain me whats happening in later part of it basically [^.]+)$]

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [December 1, 2017, 6:43am UTC](https://discuss.elastic.co/t/grok-filter-to-retrieve-simple-words-or-character-from-text-string/109177/7 "2017-12-01T06:43:59Z")

</div>

> how to handle this exception.? is there a way to put "TXT" where file extension not found.

```plaintext
if "_grokparsefailure" in [tags] {
  mutate {
    add_field => {
      "extension" => "txt"
    }
    remove_tag => ["_grokparsefailure"]
  }
}

```

> and can you explain me whats happening in later part of it basically [^.]+)$]

`[^.]` means "any character except a period", `+` means "one or more occurrences of the preceding token", and `$` means end-of-string.

These are standard regular expressions. If you don't know them it should be on your todo list.

---

<div class="post-metadata">

**Author:** ![scch](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/scch/32/25504_2.png) [@scch](https://discuss.elastic.co/u/scch)\
**Post date:** [December 1, 2017, 8:06am UTC](https://discuss.elastic.co/t/grok-filter-to-retrieve-simple-words-or-character-from-text-string/109177/8 "2017-12-01T08:06:53Z")

</div>

Thanks a lot this works..😀

> If you don't know them it should be on your todo list.

agree.. in-fact lot to learn in ELK 😐

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 29, 2017, 8:06am UTC](https://discuss.elastic.co/t/grok-filter-to-retrieve-simple-words-or-character-from-text-string/109177/9 "2017-12-29T08:06:55Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
