# Grok multiple pattern definitions

**URL:** <https://discuss.elastic.co/t/grok-multiple-pattern-definitions/254797>\
**Category:** Logstash\
**Created:** [November 9, 2020, 5:04pm UTC](https://discuss.elastic.co/t/grok-multiple-pattern-definitions/254797 "2020-11-09T17:04:02Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Carlos\_Fernando\_Palm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/carlos_fernando_palm/32/77804_2.png) [@Carlos\_Fernando\_Palm](https://discuss.elastic.co/u/Carlos_Fernando_Palm)\
**Post date:** [November 9, 2020, 5:04pm UTC](https://discuss.elastic.co/t/grok-multiple-pattern-definitions/254797/1 "2020-11-09T17:04:02Z")

</div>

Hello, I am trying to define several patterns to use on logstash.conf.  
So far I have tried this:

```auto
grok{
	     tag_on_failure => []	
	     pattern_definitions => {"text1" => "((?<=responses=)[a-zA-z]+(?=,))"}
	     pattern_definions => {"text2"=> "([,][][a-zA-z ?]+)"}	
	     match => {"message" => "%{text1:response_text}"}
	  }

```

This one makes logstash stop with exit code 1  
and this:

```auto
pattern_definitions => {["text1" => "((?<=responses=)[a-zA-z]+(?=,))", "text2" => "([,][][a-zA-z ?]+)"]}	

```

This one makes logstash stop with exit code 0

What is the proper syntax for this? I can't find anything in the documentation. The closest I found was this:

> **[Grok processor | Elasticsearch Reference \[7.9\] | Elastic](https://www.elastic.co/guide/en/elasticsearch/reference/7.9/grok-processor.html)**

But all of that refers to using REST endpoints. I am using a logstash.conf file

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [November 9, 2020, 5:14pm UTC](https://discuss.elastic.co/t/grok-multiple-pattern-definitions/254797/2 "2020-11-09T17:14:42Z")

</div>

pattern\_definitions is a hash, so it should be

```
pattern_definitions => {
    "foo" => "SomePattern"
    "bar" => "SomeOtherPattern"
}
```

---

<div class="post-metadata">

**Author:** ![Carlos\_Fernando\_Palm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/carlos_fernando_palm/32/77804_2.png) [@Carlos\_Fernando\_Palm](https://discuss.elastic.co/u/Carlos_Fernando_Palm)\
**Post date:** [November 9, 2020, 5:24pm UTC](https://discuss.elastic.co/t/grok-multiple-pattern-definitions/254797/3 "2020-11-09T17:24:57Z")

</div>

Now it starts without errors, thanks!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 7, 2020, 5:25pm UTC](https://discuss.elastic.co/t/grok-multiple-pattern-definitions/254797/4 "2020-12-07T17:25:07Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
