# Grok log

**URL:** <https://discuss.elastic.co/t/grok-log/154634>\
**Category:** Logstash\
**Created:** [October 30, 2018, 11:27am UTC](https://discuss.elastic.co/t/grok-log/154634 "2018-10-30T11:27:12Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![KAmerad\_Jubei\_Kibaga](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kamerad_jubei_kibaga/32/37110_2.png) [@KAmerad\_Jubei\_Kibaga](https://discuss.elastic.co/u/KAmerad_Jubei_Kibaga)\
**Post date:** [October 30, 2018, 11:27am UTC](https://discuss.elastic.co/t/grok-log/154634/1 "2018-10-30T11:27:13Z")

</div>

- Version: logstash 6.4.2
- Operating System: Ubuntu  
I have log:  
2018-10-30 11:45:02 act\_id: 76698461 st:SED\_AGENT\_SIGN\_ACCEPTED request:c01df4fe1cd62d867934d1903456bfc1

My grok

filter {  
if [type] == "act-process" {  
grok {  
match =\> { "message" =\> "%{DATESTAMP:timestamp} act\_id: %{NUMBER:act\_id} st:%{WORD:stage} %{GREEDYDATA:message}" }  
}  
}  
}

I see in Elastic

| [@timestamp](https://github.com/timestamp) | | October 30th 2018, 12:07:17.003 |
| --- | --- | --- |
| t \_id | | sAg6xGYBD5P5ZfC\_KuxY |
| t \_index | | filebeat-6.4.2-2018.10.30 |
| # \_score | | - |
| t \_type | | doc |
| t beat.hostname | | vlab-agent-app |
| t beat.name | | vlab-agent-app |
| t beat.version | | 6.4.2 |
| t host.name | | vlab-agent-app |
| t input.type | | log |
| t message | | 2018-10-30 11:45:02 act\_id: 76698461 st:SED\_AGENT\_SIGN\_ACCEPTED request:c01df4fe1cd62d867934d1903456bfc1 |
| # offset | | 126 |
| t prospector.type | | log |
| t source | | /mnt/log/act-sign/logs/process/process2.log |
| t type | | act-process |

All my data is placed in the message string....

What is the problem?

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [October 30, 2018, 11:50am UTC](https://discuss.elastic.co/t/grok-log/154634/2 "2018-10-30T11:50:35Z")

</div>

Are you sending the data through Logstash? What does your full Filebeat and Logstash config look like?

---

<div class="post-metadata">

**Author:** ![KAmerad\_Jubei\_Kibaga](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kamerad_jubei_kibaga/32/37110_2.png) [@KAmerad\_Jubei\_Kibaga](https://discuss.elastic.co/u/KAmerad_Jubei_Kibaga)\
**Post date:** [October 30, 2018, 1:53pm UTC](https://discuss.elastic.co/t/grok-log/154634/3 "2018-10-30T13:53:30Z")

</div>

root@vlab-elk-redis:~# cat /etc/logstash/conf.d/02-beats-input.conf  
input {  
beats {  
port =\> 5044  
type =\> "act-process"  
ssl =\> false

# ssl\_certificate =\> "/etc/pki/tls/certs/logstash-beats.crt"

# ssl\_key =\> "/etc/pki/tls/private/logstash-beats.key"

}  
}  
root@vlab-elk-redis:~# cat /etc/logstash/conf.d/  
02-beats-input.conf 12-process.conf 30-output.conf  
root@vlab-elk-redis:~# cat /etc/logstash/conf.d/12-process.conf  
filter {  
grok {  
match =\> { "message" =\> "%{DATESTAMP:timestamp} act\_id: %{NUMBER:act\_id} st:%{WORD:stage} %{GREEDYDATA:message}" }  
add\_tag =\> ["zdes\_bil\_vasya"]  
}  
}

root@vlab-elk-redis:~# cat /etc/logstash/conf.d/30-output.conf  
output {  
elasticsearch {  
hosts =\> ["localhost"]  
manage\_template =\> false  
index =\> "%{[@metadata][beat]}-%{+YYYY.MM.dd}"  
document\_type =\> "%{[@metadata][type]}"  
}  
}  
root@vlab-agent-app:/home/alfa\_agent# grep -v '^ \*#|^ \*$' /etc/filebeat/filebeat.yml  
filebeat.inputs:

- type: log  
enabled: true  
paths:
  - /mnt/log/act-sign/logs/process/_.log  
fields:  
type: act-process  
fields\_under\_root: true  
scan\_frequency: 5s  
filebeat.config.modules:  
path: ${path.config}/modules.d/_.yml  
reload.enabled: false  
setup.template.settings:  
index.number\_of\_shards: 3  
setup.kibana:  
output.elasticsearch:  
hosts: ["172.16.91.43:9200"]

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 27, 2018, 1:53pm UTC](https://discuss.elastic.co/t/grok-log/154634/4 "2018-11-27T13:53:33Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
