# Grok in logstash.conf doesnt work!

**URL:** <https://discuss.elastic.co/t/grok-in-logstash-conf-doesnt-work/130619>\
**Category:** Logstash\
**Created:** [May 4, 2018, 11:54am UTC](https://discuss.elastic.co/t/grok-in-logstash-conf-doesnt-work/130619 "2018-05-04T11:54:58Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![Swantje](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/swantje/32/30244_2.png) [@Swantje](https://discuss.elastic.co/u/Swantje)\
**Post date:** [May 4, 2018, 11:54am UTC](https://discuss.elastic.co/t/grok-in-logstash-conf-doesnt-work/130619/1 "2018-05-04T11:54:58Z")

</div>

Hi all together,

i need your help because i have to finish a project in my company.

**I've got this log:**

> Recovery Manager: Release 12.1.0.2.0 - Production on _Tue Apr 24 18:30:01 2018_  
> Copyright (c) 1982, 2014, Oracle and/or its affiliates. All rights reserved.
> 
> xxx #privateinformationofthecompany
> 
> channel c1: backup set complete, elapsed time: _00:00:01_  
> Finished backup at 24-APR-18
> 
> released channel: c1
> 
> _Recovery Manager complete_.

I want to extract these strings which are written cursive in the log above:

- Tue Apr 24 18:30:01 2018  
as date

- 00:00:01  
as duration

- Recovery Manager complete  
as Status

**This is my logstash.conf:**

> input {  
> beats{  
> port =\> 5044  
> }   
> }  
> if [tag] == "CLD1"{  
> grok {   
> match =\> {"message" =\> ["\ARecovery Manager: Release 12.1.0.2.0 - Production on %{HTTPDERROR\_DATE:timestamp} (?[\r\n]+)"] }  
> }  
> date {  
> match =\> ["timestamp", "E MMM dd HH:mm:ss yyyy"]  
> }  
> #mutate {  
> # remove\_field =\> ["day, month, monthday, time, year"]  
> #}  
> }  
> }
> 
> output {  
> if [@metadata][beat] == "filebeat" {  
> elasticsearch {  
> hosts =\> ["localhost:9200"]  
> user =\> elastic  
> password =\> elastic  
> sniffing =\> true  
> manage\_template =\> false  
> index =\> "%{[@metadata][beat]}-%{[@metadata][version]}-%{+YYYY.MM.dd}"  
> }  
> }  
> }

No matter how i change the grok, there are no new fields in my elasticsearch Events.

Please can somebody help me!

Thank you very much!!

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [May 4, 2018, 7:40pm UTC](https://discuss.elastic.co/t/grok-in-logstash-conf-doesnt-work/130619/2 "2018-05-04T19:40:42Z")

</div>

> if [tag] == "CLD1"{

Is this condition ever true? What does an example event produced by Logstash look like?

---

<div class="post-metadata">

**Author:** ![Swantje](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/swantje/32/30244_2.png) [@Swantje](https://discuss.elastic.co/u/Swantje)\
**Post date:** [May 7, 2018, 5:55am UTC](https://discuss.elastic.co/t/grok-in-logstash-conf-doesnt-work/130619/3 "2018-05-07T05:55:45Z")

</div>

Hello Magnus,

can you speak german? Your Name sounds like...?

No, this condition isn't ever true. There are more tags, but now I just want to Response to this example.

The log you can see above is divided in this to Events in kibana.

> Recovery Manager: Release 12.1.0.2.0 - Production on Fri May 4 09:30:01 2018
> 
> Copyright (c) 1982, 2014, Oracle and/or its affiliates. All rights reserved.
> 
> RMAN\> connect target \*  
> 2\> show all;  
> 3\> run  
> 4\> {  
> 5\> sql "alter system archive log current";  
> 6\> backup as compressed backupset archivelog all delete input format '/pfde-netapp5-v1/oracle/CLD1/rman/20180504\_093001\_%d\_%s\_al.bak';  
> 7\> }  
> 8\> run  
> 9\> {  
> 10\> allocate channel c1 type disk;  
> connected to target database:  
> ...
> 
> using target database control file instead of recovery catalog....  
> CONFIGURE  
> .....  
> Starting backup at 04-MAY-18

> ....  
> Finished backup at 04-MAY-18
> 
> released channel: c1
> 
> Recovery Manager complete.

Fields: timestamp, Version, id, index, score, type, beat.hostname, beat.name, beat.version, host, message with the text above, Offset, prospector type, source, tags...

Now i want to get this two Events into one and create new fields like 'date', 'status', 'duration'.

Please could someone help me?

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [May 7, 2018, 6:19am UTC](https://discuss.elastic.co/t/grok-in-logstash-conf-doesnt-work/130619/4 "2018-05-07T06:19:27Z")

</div>

> can you speak german?

I'm Swedish but I do speak some german.

> No, this condition isn't ever true.

Okay, but then it's pretty obvious why the filters aren't doing anything.

> Now i want to get this two Events into one and create new fields like 'date', 'status', 'duration'.

Parsing multi-line free-form text isn't one of Logstash's strengths. I suppose you'd have to use a multiline codec to merge the group of lines into a single event but it'll be icky.

---

<div class="post-metadata">

**Author:** ![Swantje](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/swantje/32/30244_2.png) [@Swantje](https://discuss.elastic.co/u/Swantje)\
**Post date:** [May 7, 2018, 6:40am UTC](https://discuss.elastic.co/t/grok-in-logstash-conf-doesnt-work/130619/5 "2018-05-07T06:40:47Z")

</div>

So it wont be possible to create new fields like Status, date, Duration etc ?

But for what you can use the grok?

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [May 7, 2018, 6:43am UTC](https://discuss.elastic.co/t/grok-in-logstash-conf-doesnt-work/130619/6 "2018-05-07T06:43:35Z")

</div>

You can certainly use grok to extract parts of a string but the trickier is joining multiple physical lines into a fewer number of Logstash events.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 4, 2018, 6:43am UTC](https://discuss.elastic.co/t/grok-in-logstash-conf-doesnt-work/130619/7 "2018-06-04T06:43:48Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
