# Grok part of message

**URL:** <https://discuss.elastic.co/t/grok-part-of-message/234534>\
**Category:** Logstash\
**Created:** [May 27, 2020, 11:54am UTC](https://discuss.elastic.co/t/grok-part-of-message/234534 "2020-05-27T11:54:02Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![GedeoN](https://avatars.discourse-cdn.com/v4/letter/g/e9c0ed/32.png) [@GedeoN](https://discuss.elastic.co/u/GedeoN)\
**Post date:** [May 27, 2020, 11:54am UTC](https://discuss.elastic.co/t/grok-part-of-message/234534/1 "2020-05-27T11:54:02Z")

</div>

Hi,

I'm trying to parse a part of message.  
My general grok is working, but this one doesn't.

I have message like that:

```auto
Login failed for user 'USR_DELTA'. Reason: The account is disabled. [CLIENT: xxx.xxx.xxx.xxx]

```

In first time, i grok parse IP with:

```auto
            match => { "message" => "%{IPV4:ipClient}" }
            add_tag => ["ipClient"]

```

And it works well.  
In a second time, i try to just parse Login failed for user 'USR\_DELTA' with:

```auto
            match => { "message" => "Login failed for user={USERNAME:user}" }
            add_tag => ["user"]

```

But it doesn't work. I don't have error in rubydebug but i don't have a new field with the user, any idea? Problem with syntax maybe?

Best regards.  
Jonathan

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [May 27, 2020, 12:36pm UTC](https://discuss.elastic.co/t/grok-part-of-message/234534/2 "2020-05-27T12:36:21Z")

</div>

Your grok pattern has an equals sign and no quotes. Your message has a space and single quotes around the username. That is not going to match.

---

<div class="post-metadata">

**Author:** ![GedeoN](https://avatars.discourse-cdn.com/v4/letter/g/e9c0ed/32.png) [@GedeoN](https://discuss.elastic.co/u/GedeoN)\
**Post date:** [May 27, 2020, 12:46pm UTC](https://discuss.elastic.co/t/grok-part-of-message/234534/3 "2020-05-27T12:46:45Z")

</div>

I'm trying many syntax, but it doesn't work, do you know how to match it?

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [May 27, 2020, 12:50pm UTC](https://discuss.elastic.co/t/grok-part-of-message/234534/4 "2020-05-27T12:50:19Z")

</div>

I would expect

```
  match => { "message" => "Login failed for user '{USERNAME:user}'" }

```

to work.

---

<div class="post-metadata">

**Author:** ![GedeoN](https://avatars.discourse-cdn.com/v4/letter/g/e9c0ed/32.png) [@GedeoN](https://discuss.elastic.co/u/GedeoN)\
**Post date:** [May 27, 2020, 2:59pm UTC](https://discuss.elastic.co/t/grok-part-of-message/234534/5 "2020-05-27T14:59:52Z")

</div>

Hi finally find like this

```auto
match => { "message" => ".*Login failed for user\s* \s*'%{USERNAME:user}'" }

```

And it works well 🙂  
Thank you very much.

Regards

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 24, 2020, 3:11pm UTC](https://discuss.elastic.co/t/grok-part-of-message/234534/6 "2020-06-24T15:11:11Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
