# Grok filter with spaces in field

**URL:** <https://discuss.elastic.co/t/grok-filter-with-spaces-in-field/91796>\
**Category:** Logstash\
**Created:** [July 4, 2017, 3:42pm UTC](https://discuss.elastic.co/t/grok-filter-with-spaces-in-field/91796 "2017-07-04T15:42:48Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![matt.wilcock](https://avatars.discourse-cdn.com/v4/letter/m/df705f/32.png) [@matt.wilcock](https://discuss.elastic.co/u/matt.wilcock)\
**Post date:** [July 4, 2017, 3:42pm UTC](https://discuss.elastic.co/t/grok-filter-with-spaces-in-field/91796/1 "2017-07-04T15:42:48Z")

</div>

Hi,

I'm trying to work out how to build a grok filter with spaces in one of the fields but I'm not sure how to do it. The log looks like this:

2017-06-28 14:13:05 Coordinated Universal Time INFO [1234:0x0000019f] Loaded log manager '/path/to/some/interesting/things' for Platform 10.5.6.25.

If I put quotes around "Coordinated Universal Time", I can use this filter:

%{TIMESTAMP\_ISO8601:run\_start} %{QUOTEDSTRING:timezone} %{WORD:log\_level} %{DATA:id} %{GREEDYDATA:message\_detail}

However I can't adjust the format of the original log file to put quotes around that field. Can anybody advise how I can do this with a grok filter please?

Thanks a lot!

---

<div class="post-metadata">

**Author:** ![paz](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/paz/32/28003_2.png) [@paz](https://discuss.elastic.co/u/paz)\
**Post date:** [July 5, 2017, 9:26am UTC](https://discuss.elastic.co/t/grok-filter-with-spaces-in-field/91796/2 "2017-07-05T09:26:08Z")

</div>

The easier way is to look for some form of unique "breakpoints" in the log line and adapt your pattern around it. For instance, those square brackets could help you use GREEDYDATA to capture arbitrary strings and still keep regex greed in check.  
Try this one:

```auto

```

---

<div class="post-metadata">

**Author:** ![matt.wilcock](https://avatars.discourse-cdn.com/v4/letter/m/df705f/32.png) [@matt.wilcock](https://discuss.elastic.co/u/matt.wilcock)\
**Post date:** [July 5, 2017, 10:33am UTC](https://discuss.elastic.co/t/grok-filter-with-spaces-in-field/91796/3 "2017-07-05T10:33:42Z")

</div>

Hi Paz,

That works, thanks!

But I don't understand why it works! I could understand if there were square brackets were around the log\_level (INFO) because that would break the GREEDYDATA capture as it comes after the timezone, so I'd expect this expression to pick up timezone and log\_level as one field?

I suppose I'm asking, why doesn't GREEDYDATA pick up the timezone as "Coordinated Universal Time INFO"? How does it know that they are two separate fields?

Thanks.

---

<div class="post-metadata">

**Author:** ![paz](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/paz/32/28003_2.png) [@paz](https://discuss.elastic.co/u/paz)\
**Post date:** [July 5, 2017, 11:01am UTC](https://discuss.elastic.co/t/grok-filter-with-spaces-in-field/91796/4 "2017-07-05T11:01:07Z")

</div>

> [@matt.wilcock](#):
>
> I suppose I'm asking, why doesn't GREEDYDATA pick up the timezone as "Coordinated Universal Time INFO"? How does it know that they are two separate fields?

Because greediness relies a lot on backtracking. It captures the max possible amount of characters and starts removing characters from the capture group until all conditions are satisfied.

Here's a step-by-step progress in order to visualize it better (I converted the grok patterns to pure regex)

> **[regex101: build, test, and debug regex](https://regex101.com/r/lmEABn/1/debugger)**
>
> Regular expression tester with syntax highlighting, explanation, cheat sheet for PHP/PCRE, Python, GO, JavaScript, Java, C#/.NET, Rust.

As you can imagine it is an expensive process, and depending on the substring position in the log line, it could make sense to use lazy grabbing instead of greedy (DATA instead of GREEDYDATA).

---

<div class="post-metadata">

**Author:** ![matt.wilcock](https://avatars.discourse-cdn.com/v4/letter/m/df705f/32.png) [@matt.wilcock](https://discuss.elastic.co/u/matt.wilcock)\
**Post date:** [July 5, 2017, 12:18pm UTC](https://discuss.elastic.co/t/grok-filter-with-spaces-in-field/91796/5 "2017-07-05T12:18:36Z")

</div>

Thanks a lot for explaining.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 2, 2017, 12:18pm UTC](https://discuss.elastic.co/t/grok-filter-with-spaces-in-field/91796/6 "2017-08-02T12:18:47Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
