# GROK match multiple pattern drop the log

**URL:** <https://discuss.elastic.co/t/grok-match-multiple-pattern-drop-the-log/229986>\
**Category:** Logstash\
**Created:** [April 27, 2020, 3:49pm UTC](https://discuss.elastic.co/t/grok-match-multiple-pattern-drop-the-log/229986 "2020-04-27T15:49:36Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![tharu85](https://avatars.discourse-cdn.com/v4/letter/t/e95f7d/32.png) [@tharu85](https://discuss.elastic.co/u/tharu85)\
**Post date:** [April 27, 2020, 3:49pm UTC](https://discuss.elastic.co/t/grok-match-multiple-pattern-drop-the-log/229986/1 "2020-04-27T15:49:36Z")

</div>

I used following grok pattern to extract IIS log. The match message containing multiple grok pattern due to IIS log configuration on several server.

Unfortunately one I have execute this filter, no messages were parsers. dropping all iis log without parsing.

Once I execute this code without grok messages are displaying.

Any issue on this code ?

```
filter {

    if ([type] == "iis-log" or [type] == "iis_log") 
    {
	if "beats_input_codec_plain_applied" in [tags] {
		mutate {
			remove_tag => ["beats_input_codec_plain_applied"]
		}
	}
					
	grok 
	{
		match => ["message", "%{TIMESTAMP_ISO8601:log_timestamp} %{WORD:iis_site} %{IPORHOST:dstip} %{WORD:method} %{URIPATH:page} %{NOTSPACE:querystring} %{NUMBER:dstport} %{NOTSPACE:username} %{IPORHOST:load_balancer_ip} %{NOTSPACE:useragent} %{NOTSPACE:request_host} %{NUMBER:response} %{NUMBER:subresponse} %{NUMBER:windows_status} %{NUMBER:sent_bytes} %{NUMBER:input_bytes} %{NUMBER:time_taken} %{IPORHOST:srcip},\+%{IPORHOST:waf_ip}",
			  "message", "%{TIMESTAMP_ISO8601:log_timestamp} %{IPORHOST:dstip} %{WORD:method} %{URIPATH:page} %{NOTSPACE:querystring} %{NUMBER:dstport} %{NOTSPACE:username} %{IPORHOST:load_balancer_ip} %{NOTSPACE:useragent} %{NOTSPACE:request_host} %{NUMBER:response} %{NUMBER:subresponse} %{NUMBER:windows_status} %{NUMBER:sent_bytes} %{IPORHOST:srcip},\+%{IPORHOST:waf_ip}",
			  "message", "%{TIMESTAMP_ISO8601:log_timestamp} %{WORD:iis_site} %{IPORHOST:dstip} %{WORD:method} %{URIPATH:page} %{NOTSPACE:querystring} %{NUMBER:dstport} %{NOTSPACE:username} %{IPORHOST:load_balancer_ip} %{NOTSPACE:useragent} %{NOTSPACE:request_host} %{NUMBER:response} %{NUMBER:subresponse} %{NUMBER:windows_status} %{NUMBER:sent_bytes} %{NUMBER:input_bytes} %{NUMBER:time_taken}",
			  "message", "%{TIMESTAMP_ISO8601:log_timestamp} %{IPORHOST:dstip} %{WORD:method} %{URIPATH:page} %{NOTSPACE:querystring} %{NUMBER:dstport} %{NOTSPACE:username} %{IPORHOST:load_balancer_ip} %{NOTSPACE:useragent} %{NOTSPACE:request_host} %{NUMBER:response} %{NUMBER:subresponse} %{NUMBER:windows_status} %{NUMBER:sent_bytes}"
		]
	}
				
	mutate 
	{
		convert => ["dstport", "integer"]
		convert => ["response", "integer"]
		convert => ["sent_bytes", "integer"]
		convert => ["input_bytes", "integer"]
		convert => ["time_taken", "integer"]
		convert => ["subresponse", "integer"]
		convert => ["windows_status", "integer"]	
	}
		
	mutate {
		remove_field => ["[beat][hostname]", "[beat][name]", "[beat][version]", "[beat]", "loadbalancer_ip" ]
	}

    }
}
```

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [April 27, 2020, 9:20pm UTC](https://discuss.elastic.co/t/grok-match-multiple-pattern-drop-the-log/229986/2 "2020-04-27T21:20:46Z")

</div>

I would write that match as

```
match => {
    "message" => {
        "%{TIMESTAMP_ISO8601:log_timestamp} %{WORD:iis_site} %{IPORHOST:dstip} %{WORD:method} %{URIPATH:page} %{NOTSPACE:querystring} %{NUMBER:dstport} %{NOTSPACE:username} %{IPORHOST:load_balancer_ip} %{NOTSPACE:useragent} %{NOTSPACE:request_host} %{NUMBER:response} %{NUMBER:subresponse} %{NUMBER:windows_status} %{NUMBER:sent_bytes} %{NUMBER:input_bytes} %{NUMBER:time_taken} %{IPORHOST:srcip},\+%{IPORHOST:waf_ip}",
        "%{TIMESTAMP_ISO8601:log_timestamp} %{IPORHOST:dstip} %{WORD:method} %{URIPATH:page} %{NOTSPACE:querystring} %{NUMBER:dstport} %{NOTSPACE:username} %{IPORHOST:load_balancer_ip} %{NOTSPACE:useragent} %{NOTSPACE:request_host} %{NUMBER:response} %{NUMBER:subresponse} %{NUMBER:windows_status} %{NUMBER:sent_bytes} %{IPORHOST:srcip},\+%{IPORHOST:waf_ip}", 
        "%{TIMESTAMP_ISO8601:log_timestamp} %{WORD:iis_site} %{IPORHOST:dstip} %{WORD:method} %{URIPATH:page} %{NOTSPACE:querystring} %{NUMBER:dstport} %{NOTSPACE:username} %{IPORHOST:load_balancer_ip} %{NOTSPACE:useragent} %{NOTSPACE:request_host} %{NUMBER:response} %{NUMBER:subresponse} %{NUMBER:windows_status} %{NUMBER:sent_bytes} %{NUMBER:input_bytes} %{NUMBER:time_taken}",
        "%{TIMESTAMP_ISO8601:log_timestamp} %{IPORHOST:dstip} %{WORD:method} %{URIPATH:page} %{NOTSPACE:querystring} %{NUMBER:dstport} %{NOTSPACE:username} %{IPORHOST:load_balancer_ip} %{NOTSPACE:useragent} %{NOTSPACE:request_host} %{NUMBER:response} %{NUMBER:subresponse} %{NUMBER:windows_status} %{NUMBER:sent_bytes}"
    ]
}

```

Also, I would strongly recommend you anchor your patterns to start of line ("^%{TIMESTAMP\_ISO8601:log\_timestamp} ...") for reasons explained [here](https://www.elastic.co/blog/do-you-grok-grok).

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 25, 2020, 9:20pm UTC](https://discuss.elastic.co/t/grok-match-multiple-pattern-drop-the-log/229986/3 "2020-05-25T21:20:46Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
