Grok for - [BT:CHROME, BV:55, BL:en, CC:CZ]


(Nikhil Pawar) #1

Hi , i am trying to capture the while block in the grok along with the square brackets [] . The grok filter field should be displaying the data with the pattern inside it . Can someone please advise what should be grok for this.

[BT:CHROME, BV:55, BL:en, CC:CZ]


(Magnus Bäck) #2

It's very hard to understand what you're asking. You want to match a string like "[BT:CHROME, BV:55, BL:en, CC:CZ]" and include the square brackets in the resulting field?


(Nikhil Pawar) #3

Hi @magnusbaeck yes .. i want to match a string like "[BT:CHROME, BV:55, BL:en, CC:CZ]" and include the square brackets in resulting field.


(Magnus Bäck) #4

Then perhaps (?<name-of-field>\[[^\]]*\]) would do. It should match a [ followed by zero or more characters of any kind except ], followed by ].


(Nikhil Pawar) #5

Awesome ..Thanks magnusbaeck. It works


(system) #6

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.