# Grok\_help

**URL:** <https://discuss.elastic.co/t/grok-help/131661>\
**Category:** Logstash\
**Created:** [May 14, 2018, 6:20am UTC](https://discuss.elastic.co/t/grok-help/131661 "2018-05-14T06:20:44Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![anush\_jayan](https://avatars.discourse-cdn.com/v4/letter/a/278dde/32.png) [@anush\_jayan](https://discuss.elastic.co/u/anush_jayan)\
**Post date:** [May 14, 2018, 6:20am UTC](https://discuss.elastic.co/t/grok-help/131661/1 "2018-05-14T06:20:44Z")

</div>

{"@timestamp":"2018-03-31T04:00:00.237Z","@version":"1","message":"2018-03-31 03:59:22,12.106.8.702,ABC33&&000012345678,03/31/2018 03:59:59,23.47893,92.38397,0,6,ON,0,0,79.06,0,3395,588,2,0,40430,-71,12,17","tags":["\_grokparsefailure"]}

can anyone help me in building a grok filter for this log i just want this "message":"2018-03-31 03:59:22,12.106.8.702,ABC33&&000012345678,03/31/2018 03:59:59,23.47893,92.38397,0,6,ON,0,0,79.06,0,3395,588,2,0,40430,-71,12,17" in elasticsearch

i made this grok ("message":"%{DATA:data}",) but it is throwing error when im trying to run config test

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [May 14, 2018, 6:29am UTC](https://discuss.elastic.co/t/grok-help/131661/2 "2018-05-14T06:29:53Z")

</div>

I don't understand. What is the desired result? Show us an example.

---

<div class="post-metadata">

**Author:** ![anush\_jayan](https://avatars.discourse-cdn.com/v4/letter/a/278dde/32.png) [@anush\_jayan](https://discuss.elastic.co/u/anush_jayan)\
**Post date:** [May 14, 2018, 6:46am UTC](https://discuss.elastic.co/t/grok-help/131661/3 "2018-05-14T06:46:40Z")

</div>

this is the log {"@timestamp":"2018-03-31T04:00:00.237Z","@version":"1","message":"2018-03-31 03:59:22,12.106.8.702,ABC33&&000012345678,03/31/2018 03:59:59,23.47893,92.38397,0,6,ON,0,0,79.06,0,3395,588,2,0,40430,-71,12,17","tags":["\_grokparsefailure"]}

but i just want to take data starting from "message":"2018-03-31 \*\*\*\*\*\*\*\*\*\*\*\* till ,40430,-71,12,17"  
im using this grok ("message":"%{DATA:data}",) im using this to filter and  
im getting this output in grok debugger and this is what i need

{  
"data": [  
[  
"message":"2018-03-31 03:59:22,12.106.8.702,ABC33&&000012345678,03/31/2018 03:59:59,23.47893,92.38397,0,6,ON,0,0,79.06,0,3395,588,2,0,40430,-71,12,17"  
]  
]  
}

but when running config test im getting this error

ERROR StatusLogger No log4j2 configuration file found. Using default configuration: logging only errors to the console.  
WARNING: Could not find logstash.yml which is typically located in $LS\_HOME/config or /etc/logstash. You can specify the path using --path.settings. Continuing using the defaults  
Could not find log4j2 configuration at path //usr/share/logstash/config/log4j2.properties. Using default config which logs to console  
06:31:43.022 [LogStash::Runner] FATAL logstash.runner - The given configuration is invalid. Reason: Expected one of #, =\> at line 12, column 8 (byte 123) after filter {  
grok {  
match =\> {"message" =\> "("message":"%{DATA:data}",)"}  
}

output {

---

<div class="post-metadata">

**Author:** ![MarkusT](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/markust/32/30037_2.png) [@MarkusT](https://discuss.elastic.co/u/MarkusT)\
**Post date:** [May 14, 2018, 6:59am UTC](https://discuss.elastic.co/t/grok-help/131661/4 "2018-05-14T06:59:37Z")

</div>

Hey anush,

you could try to change your grok call from

`grok { match => {"message" => "("message":"%{DATA:data}",)"} }`

to

`grok { match => {"message" => '("message":"%{DATA:data}",)'} }`

using single qoute chars, then logstash does not get confused about start and end of the commands.

Cheers,  
Markus

---

<div class="post-metadata">

**Author:** ![anush\_jayan](https://avatars.discourse-cdn.com/v4/letter/a/278dde/32.png) [@anush\_jayan](https://discuss.elastic.co/u/anush_jayan)\
**Post date:** [May 14, 2018, 7:02am UTC](https://discuss.elastic.co/t/grok-help/131661/5 "2018-05-14T07:02:13Z")

</div>

thanks a lot it helped me out

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [May 14, 2018, 7:24am UTC](https://discuss.elastic.co/t/grok-help/131661/6 "2018-05-14T07:24:54Z")

</div>

Don't use a grok filter to parse JSON. Use a json codec in your input plugin instead, or possibly a json filter.

---

<div class="post-metadata">

**Author:** ![anush\_jayan](https://avatars.discourse-cdn.com/v4/letter/a/278dde/32.png) [@anush\_jayan](https://discuss.elastic.co/u/anush_jayan)\
**Post date:** [May 14, 2018, 9:43am UTC](https://discuss.elastic.co/t/grok-help/131661/7 "2018-05-14T09:43:43Z")

</div>

but now im getting this  
s":["\_grokparsefailure"]}  
{  
"@timestamp" =\> 2018-05-14T09:29:10.267Z,  
"data" =\> "2018-03-31 03:59:22,12.106.8.702,ABC33&&000012345678,03/31/2018 03:59:59,23.47893,92.38397,0,6,ON,0,0,79.06,0,3395,588,2,0,40430,-71,12,17",  
"@version" =\> "1",  
"host" =\> "ls10",  
"message" =\> "{"@timestamp":"2018-03-31T04:00:00.237Z","@version":"1","message":"2018-03-31 03:59:22,12.106.8.702,ABC33&&000012345678,03/31/2018 03:59:59,23.47893,92.38397,0,6,ON,0,0,79.06,0,3395,588,2,0,40430,-71,12,17","tags":["\_grokparsefailure"]}"  
}

i just want data in message i dont want extra parameters like "{"@timestamp":"2018-03-31T04:00:00.237Z","@version":"1",

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [May 14, 2018, 10:13am UTC](https://discuss.elastic.co/t/grok-help/131661/8 "2018-05-14T10:13:36Z")

</div>

What does your configuration look like? **Always** provide configuration and input together with the output you're getting.

I don't think the `@timestamp` field can be deleted, but for the rest a mutate filter can remove that undesired fields.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 11, 2018, 10:13am UTC](https://discuss.elastic.co/t/grok-help/131661/9 "2018-06-11T10:13:39Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
