# Grok match everything up to certain character sequence?

**URL:** <https://discuss.elastic.co/t/grok-match-everything-up-to-certain-character-sequence/82268>\
**Category:** Logstash\
**Created:** [April 13, 2017, 9:55am UTC](https://discuss.elastic.co/t/grok-match-everything-up-to-certain-character-sequence/82268 "2017-04-13T09:55:00Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![jovanmal](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jovanmal/32/17330_2.png) [@jovanmal](https://discuss.elastic.co/u/jovanmal)\
**Post date:** [April 13, 2017, 9:55am UTC](https://discuss.elastic.co/t/grok-match-everything-up-to-certain-character-sequence/82268/1 "2017-04-13T09:55:00Z")

</div>

Hi guys,

does anybody know how to grok all text from log entry until certain character sequence?

For example, how to seperate only

**SiteController::actionThankYou() Displaying random premium game.**

from the following log entry:

`[Wed Feb 22 18:09:30.705389 2017] [:error] [pid 28652] [client 192.168.10.111:53660] INFO: SiteController::actionThankYou() Displaying random premium game. [game id 3439] [Project Id: 32] [Project AdrenoGame Id: 32], referer: http://www.adrenogame.com/thank-you?aj=OTQzMDUxOTkwMaX934OiiCKghdfipgshjigshjgsdhjkfshiwFAW4G%2B5ftq68QBZVHpcbmMc6tmZ%2B%2FAxVqz51501mBQVrv4bY7ZWSkNHOpi%2BLs686IavsBkGOfTYUIvbfNLvY%2FRCP&c=`

I have grok construction for the preceding data (I can post it if needed).

Thank you in advance

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [April 13, 2017, 9:56am UTC](https://discuss.elastic.co/t/grok-match-everything-up-to-certain-character-sequence/82268/2 "2017-04-13T09:56:58Z")

</div>

You can use `%{GREEDYDATA}` (i.e. `.*`) to match any character sequence.

---

<div class="post-metadata">

**Author:** ![jovanmal](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jovanmal/32/17330_2.png) [@jovanmal](https://discuss.elastic.co/u/jovanmal)\
**Post date:** [April 13, 2017, 10:05am UTC](https://discuss.elastic.co/t/grok-match-everything-up-to-certain-character-sequence/82268/3 "2017-04-13T10:05:04Z")

</div>

@magnusbaeck Thank you for quick reply

%{GREEDYDATA} will select all text upon the end of the log entry. I need to select text only upon character sequence "[game id 3439]" (game id will be another field).

---

<div class="post-metadata">

**Author:** ![jovanmal](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jovanmal/32/17330_2.png) [@jovanmal](https://discuss.elastic.co/u/jovanmal)\
**Post date:** [April 13, 2017, 12:42pm UTC](https://discuss.elastic.co/t/grok-match-everything-up-to-certain-character-sequence/82268/4 "2017-04-13T12:42:59Z")

</div>

I've made following grok construction:

`\[%{APACHE_ERROR_TIME:timestamp}\] \[:%{DATA:messagetype}\] \[pid %{NUMBER:pid}\] \[client %{IPV4:proxyaddr}:%{NUMBER:localport}\] %{LOGLEVEL:loglevel}: (?<action>.*\[g)`

Applied to mentioned log entry, I got following:

```
{
  "timestamp": [
    [
      "Wed Feb 22 18:09:30.705389 2017"
    ]
  ],
  "DAY": [
    [
      "Wed"
    ]
  ],
  "MONTH": [
    [
      "Feb"
    ]
  ],
  "MONTHDAY": [
    [
      "22"
    ]
  ],
  "TIME": [
    [
      "18:09:30.705389"
    ]
  ],
  "HOUR": [
    [
      "18"
    ]
  ],
  "MINUTE": [
    [
      "09"
    ]
  ],
  "SECOND": [
    [
      "30.705389"
    ]
  ],
  "YEAR": [
    [
      "2017"
    ]
  ],
  "messagetype": [
    [
      "error"
    ]
  ],
  "pid": [
    [
      "28652"
    ]
  ],
  "BASE10NUM": [
    [
      "28652",
      "53660"
    ]
  ],
  "proxyaddr": [
    [
      "192.168.10.111"
    ]
  ],
  "localport": [
    [
      "53660"
    ]
  ],
  "loglevel": [
    [
      "INFO"
    ]
  ],
  "action": [
    [
      "SiteController::actionThankYou() Displaying random premium game. [g"
    ]
  ]
}

```

I just need to cut last 3 characters in action field - " [g"

I tried multiple combinations, without success...

---

<div class="post-metadata">

**Author:** ![riddhijit\_roy](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/riddhijit_roy/32/19049_2.png) [@riddhijit\_roy](https://discuss.elastic.co/u/riddhijit_roy)\
**Post date:** [April 13, 2017, 2:07pm UTC](https://discuss.elastic.co/t/grok-match-everything-up-to-certain-character-sequence/82268/5 "2017-04-13T14:07:04Z")

</div>

\[%{APACHE\_ERROR\_TIME:timestamp}\] \[:%{DATA:messagetype}\] \[pid %{NUMBER:pid}\] \[client %{IPV4:proxyaddr}:%{NUMBER:localport}\] %{LOGLEVEL:loglevel}: %{DATA:Action}. \[%{DATA:gid}\] %{GREEDYDATA}

Try this!!

---

<div class="post-metadata">

**Author:** ![jovanmal](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jovanmal/32/17330_2.png) [@jovanmal](https://discuss.elastic.co/u/jovanmal)\
**Post date:** [April 13, 2017, 2:34pm UTC](https://discuss.elastic.co/t/grok-match-everything-up-to-certain-character-sequence/82268/6 "2017-04-13T14:34:49Z")

</div>

Yes, you got it, it is working 🙂

Just seperated dot and added another %{DATA} field. Great.

Thank you very much

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [April 13, 2017, 2:52pm UTC](https://discuss.elastic.co/t/grok-match-everything-up-to-certain-character-sequence/82268/7 "2017-04-13T14:52:05Z")

</div>

> %{GREEDYDATA} will select all text upon the end of the log entry.

No, that's not true. It matches any (possibly empty) character sequence.

---

<div class="post-metadata">

**Author:** ![jovanmal](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jovanmal/32/17330_2.png) [@jovanmal](https://discuss.elastic.co/u/jovanmal)\
**Post date:** [April 14, 2017, 4:18am UTC](https://discuss.elastic.co/t/grok-match-everything-up-to-certain-character-sequence/82268/8 "2017-04-14T04:18:12Z")

</div>

Thank you @magnusbaeck and @riddhijit_roy

I now figured out how %{GREEDYDATA} works

🕶

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 12, 2017, 4:19am UTC](https://discuss.elastic.co/t/grok-match-everything-up-to-certain-character-sequence/82268/9 "2017-05-12T04:19:57Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
