# Grok match

**URL:** <https://discuss.elastic.co/t/grok-match/49499>\
**Category:** Logstash\
**Created:** [May 8, 2016, 10:21pm UTC](https://discuss.elastic.co/t/grok-match/49499 "2016-05-08T22:21:18Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Valeriy](https://avatars.discourse-cdn.com/v4/letter/v/5e9695/32.png) [@Valeriy](https://discuss.elastic.co/u/Valeriy)\
**Post date:** [May 8, 2016, 10:21pm UTC](https://discuss.elastic.co/t/grok-match/49499/1 "2016-05-08T22:21:18Z")

</div>

Hello!  
I'm just starting to work with a stack of ELK. Config was created by another engineer. Explain how it works, please.

```
                    grok {
                            match => { "message" => "\A.*%{IP:hostIP}.*%{CISCOTIMESTAMP}.*?(?<APPNAME>%[A-Za-z_]+)-(?<SEVERITY_LEVEL>\d{1})-(?<MSGNAME>[A-Za-z_]+).*?(?<MSG>[^:]+$)" }
                    }
```

---

<div class="post-metadata">

**Author:** ![Valeriy](https://avatars.discourse-cdn.com/v4/letter/v/5e9695/32.png) [@Valeriy](https://discuss.elastic.co/u/Valeriy)\
**Post date:** [May 8, 2016, 10:46pm UTC](https://discuss.elastic.co/t/grok-match/49499/2 "2016-05-08T22:46:10Z")

</div>

Logs file to analyze:

May 8 14:28:22 \*Mar 1 00:00:02.923: %SYS-6-LOGGINGHOST\_STARTSTOP: Logging to host 192.168.109.4 started - CLI initiated  
May 8 14:28:33 \*Mar 1 00:00:03.235: %LINK-3-UPDOWN: Interface FastEthernet0/0, changed state to up  
May 8 14:28:33 \*Mar 1 00:00:03.259: %LINK-3-UPDOWN: Interface FastEthernet0/1, changed state to up  
May 8 14:28:33 \*Mar 1 00:00:03.283: %LINK-3-UPDOWN: Interface FastEthernet1/0, changed state to up  
May 8 14:28:33 Mar 1 00:00:04.235: %LINEPROTO-5-UPDOWN: Line protocol on Interface FastEthernet0/0, changed state to up  
May 8 14:28:33 Mar 1 00:00:04.259: %LINEPROTO-5-UPDOWN: Line protocol on Interface FastEthernet0/1, changed state to up  
May 8 14:28:33 Mar 1 00:00:04.283: %LINEPROTO-5-UPDOWN: Line protocol on Interface FastEthernet1/0, changed state to up  
May 8 14:28:34 Mar 1 00:00:09.239: %SYS-6-LOGGINGHOST\_STARTSTOP: Logging to host 192.168.109.4 started - reconnection  
May 8 14:28:46 Mar 1 00:00:24.095: %DHCP-6-ADDRESS\_ASSIGN: Interface FastEthernet0/1 assigned DHCP address 192.168.137.104, mask 255.255.255.0, hostname R1  
May 8 14:28:46  
May 8 14:56:04 May 8 21:56:03.760: %SYS-5-CONFIG\_I: Configured from console by console

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [May 8, 2016, 11:54pm UTC](https://discuss.elastic.co/t/grok-match/49499/3 "2016-05-08T23:54:35Z")

</div>

What the grok match does is provide a pattern to match the log, so it can extract various fields and build a message with those.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 4:58am UTC](https://discuss.elastic.co/t/grok-match/49499/4 "2017-07-06T04:58:46Z")

</div>


