# Grok parser and nested brackets

**URL:** <https://discuss.elastic.co/t/grok-parser-and-nested-brackets/327454>\
**Category:** Logstash\
**Created:** [March 10, 2023, 12:57pm UTC](https://discuss.elastic.co/t/grok-parser-and-nested-brackets/327454 "2023-03-10T12:57:30Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![ddoroshenko](https://avatars.discourse-cdn.com/v4/letter/d/b9e5f3/32.png) [@ddoroshenko](https://discuss.elastic.co/u/ddoroshenko)\
**Post date:** [March 10, 2023, 12:57pm UTC](https://discuss.elastic.co/t/grok-parser-and-nested-brackets/327454/1 "2023-03-10T12:57:30Z")

</div>

Hi,

I have log event like this

```auto
2023-03-03T11:11:11.000Z INFO (foo (bar) bla bla [bla]) 2023-03-03T11:11:11.000Z [foo (bar) bla bla [bla]]

```

I want to parse it with grok filter like

```auto
timestamp: 2023-03-03T11:11:11.000Z
level: INFO
thread: foo (bar) bla bla [bla]
message: 2023-03-03T11:11:11.000Z [foo (bar) bla bla [bla]]

```

When I use grok parser

```auto
%{TIMESTAMP_ISO8601:timestamp}%{SPACE}%{LOGLEVEL:level}%{SPACE}\(%{DATA:thread}\)%{SPACE}%{GREEDYDATA:message}

```

I get

```auto
thread: foo (bar

```

When I use

```auto
%{TIMESTAMP_ISO8601:timestamp}%{SPACE}%{LOGLEVEL:level}%{SPACE}\(%{GREEDYDATA:thread}\)%{SPACE}%{GREEDYDATA:message}

```

I get

```auto
thread: foo (bar) bla bla [bla]) 2023-03-03T11:11:11.000Z [foo (bar

```

How should I parse nested brackets to get what I want?

---

<div class="post-metadata">

**Author:** ![Wave](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/wave/32/117242_2.png) [@Wave](https://discuss.elastic.co/u/Wave)\
**Post date:** [March 10, 2023, 3:09pm UTC](https://discuss.elastic.co/t/grok-parser-and-nested-brackets/327454/2 "2023-03-10T15:09:22Z")

</div>

I wasn't able to get it 100% what you want but close. If you are able to combine the two message fields in a subsequent step that might get you all the way.

```auto
%{TIMESTAMP_ISO8601:timestamp} %{LOGLEVEL:level} %{GREEDYDATA:thread} %{TIMESTAMP_ISO8601:message0} %{GREEDYDATA:message1}

```

---

<div class="post-metadata">

**Author:** ![Rios](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rios/32/95745_2.png) [@Rios](https://discuss.elastic.co/u/Rios)\
**Post date:** [March 10, 2023, 3:50pm UTC](https://discuss.elastic.co/t/grok-parser-and-nested-brackets/327454/3 "2023-03-10T15:50:59Z")

</div>

> [@ddoroshenko](#):
>
> ```auto
> 2023-03-03T11:11:11.000Z INFO (foo (bar) bla bla [bla]) 2023-03-03T11:11:11.000Z [foo (bar) bla bla [bla]]
> 
> ```

Is this a single line or multiline? Is the level field optional?

---

<div class="post-metadata">

**Author:** ![ddoroshenko](https://avatars.discourse-cdn.com/v4/letter/d/b9e5f3/32.png) [@ddoroshenko](https://discuss.elastic.co/u/ddoroshenko)\
**Post date:** [March 10, 2023, 4:40pm UTC](https://discuss.elastic.co/t/grok-parser-and-nested-brackets/327454/4 "2023-03-10T16:40:03Z")

</div>

@Rios this a single line

`level` field is mandatory

but the `thread` field in log event sometime could be `(foo bar bla bla bla)`

---

<div class="post-metadata">

**Author:** ![ddoroshenko](https://avatars.discourse-cdn.com/v4/letter/d/b9e5f3/32.png) [@ddoroshenko](https://discuss.elastic.co/u/ddoroshenko)\
**Post date:** [March 13, 2023, 9:30am UTC](https://discuss.elastic.co/t/grok-parser-and-nested-brackets/327454/5 "2023-03-13T09:30:15Z")

</div>

@Wave thank you for your advice, but the second timestamp is not always in message.

The common form of the log record is

```auto
2023-03-03T11:11:11.000Z INFO (foo bar bla bla bla) a message text

```

And I'd like to make the parser more universal

---

<div class="post-metadata">

**Author:** ![Rios](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rios/32/95745_2.png) [@Rios](https://discuss.elastic.co/u/Rios)\
**Post date:** [March 13, 2023, 4:03pm UTC](https://discuss.elastic.co/t/grok-parser-and-nested-brackets/327454/6 "2023-03-13T16:03:57Z")

</div>

You can use something like this:

```auto
   grok {
       break_on_match => true
       match => {
       "message" => [
               "%{TIMESTAMP_ISO8601:timestamp} %{LOGLEVEL:level} \((?<thread>.*)\) %{TIMESTAMP_ISO8601:timestamp2}%{SPACE}%{GREEDYDATA:msg}",
               "%{TIMESTAMP_ISO8601:timestamp} %{LOGLEVEL:level} \((?<thread>.*)\) %{GREEDYDATA:msg}"
               
           ]
       }
   }

```

It will separate the 2nd date field and rest of data.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 10, 2023, 4:04pm UTC](https://discuss.elastic.co/t/grok-parser-and-nested-brackets/327454/7 "2023-04-10T16:04:21Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
