# GROK Pattern creation

**URL:** <https://discuss.elastic.co/t/grok-pattern-creation/324605>\
**Category:** Logstash\
**Created:** [February 3, 2023, 6:52am UTC](https://discuss.elastic.co/t/grok-pattern-creation/324605 "2023-02-03T06:52:46Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![anushka1203](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/anushka1203/32/98018_2.png) [@anushka1203](https://discuss.elastic.co/u/anushka1203)\
**Post date:** [February 3, 2023, 6:52am UTC](https://discuss.elastic.co/t/grok-pattern-creation/324605/1 "2023-02-03T06:52:46Z")

</div>

Hi all,

Need help in creating grok pattern that works for both the following type of logs

```auto
01/25-05:17:51.314622 192.168.1.1:138 -> 192.168.1.255:138
UDP TTL:64 TOS:0x0 ID:50222 IpLen:20 DgmLen:229 DF
Len: 201
=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+

01/25-05:18:14.789246 192.168.1.20:33581 -> 192.168.1.1:80
TCP TTL:64 TOS:0x0 ID:25670 IpLen:20 DgmLen:60 DF
****** S* Seq: 0x96391DAB Ack: 0x0 Win: 0xFAF0 TcpLen: 40
TCP Options (5) => MSS: 1460 SackOK TS: 1563007755 0 NOP WS: 7 

```

Thanks in advance  
Anushka

---

<div class="post-metadata">

**Author:** ![legoguy1000](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/legoguy1000/32/54301_2.png) [@legoguy1000](https://discuss.elastic.co/u/legoguy1000)\
**Post date:** [February 7, 2023, 10:27am UTC](https://discuss.elastic.co/t/grok-pattern-creation/324605/3 "2023-02-07T10:27:43Z")

</div>

Are those snort logs? Looks like this would be at least a good start [integrations/plaintext.yml at main · elastic/integrations · GitHub](https://github.com/elastic/integrations/blob/main/packages/snort/data_stream/log/elasticsearch/ingest_pipeline/plaintext.yml#L16)

---

<div class="post-metadata">

**Author:** ![Rios](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rios/32/95745_2.png) [@Rios](https://discuss.elastic.co/u/Rios)\
**Post date:** [February 7, 2023, 2:15pm UTC](https://discuss.elastic.co/t/grok-pattern-creation/324605/4 "2023-02-07T14:15:26Z")

</div>

Are you reading logs with Filebeat then send to Logstash or only with Logstash?

---

<div class="post-metadata">

**Author:** ![legoguy1000](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/legoguy1000/32/54301_2.png) [@legoguy1000](https://discuss.elastic.co/u/legoguy1000)\
**Post date:** [February 8, 2023, 2:34am UTC](https://discuss.elastic.co/t/grok-pattern-creation/324605/5 "2023-02-08T02:34:48Z")

</div>

This is from the agent integration which is essentially filebeat straight to elastic

---

<div class="post-metadata">

**Author:** ![Rios](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rios/32/95745_2.png) [@Rios](https://discuss.elastic.co/u/Rios)\
**Post date:** [February 8, 2023, 3:21pm UTC](https://discuss.elastic.co/t/grok-pattern-creation/324605/6 "2023-02-08T15:21:27Z")

</div>

You can use [Grok contructor](https://grokconstructor.appspot.com/do/match). The multiline pattern should be used in FB, and LS will receive a message as a single line.

`01/25-05:17:51.314622 192.168.1.1:138 -> 192.168.1.255:138 UDP TTL:64 TOS:0x0 ID:50222 IpLen:20 DgmLen:229 DF Len: 201`

`(?<timestamp>%{MONTHNUM:month}/%{MONTHDAY:day}-%{TIME:time})%{SPACE}%{IP:sourceip}:%{POSINT:sourceport}%{SPACE}->%{SPACE}%{IP:destip}:%{POSINT:destport} %{WORD:protocol}%{SPACE}%{WORD}:%{POSINT:ttl}%{SPACE}%{WORD}:%{BASE16NUM:tos}%{SPACE}%{WORD}:%{POSINT:id}%{SPACE}%{WORD}:%{POSINT:iplen}%{SPACE}%{WORD}:%{POSINT:dgmlen}%{SPACE}%{WORD:flag}%{SPACE}%{WORD}: %{POSINT:len}`

 ![Line1](https://us1.discourse-cdn.com/elastic/original/3X/7/7/77241d74803c5a4f299d51062812ce3f2b19c98b.png)

* * *

`01/25-05:18:14.789246 192.168.1.20:33581 -> 192.168.1.1:80 TCP TTL:64 TOS:0x0 ID:25670 IpLen:20 DgmLen:60 DF ****** S* Seq: 0x96391DAB Ack: 0x0 Win: 0xFAF0 TcpLen: 40 TCP Options (5) => MSS: 1460 SackOK TS: 1563007755 0 NOP WS: 7`

`(?<timestamp>%{MONTHNUM}/%{MONTHDAY}-%{TIME})%{SPACE}%{IP:sourceip}:%{POSINT:sourceport}%{SPACE}->%{SPACE}%{IP:destip}:%{POSINT:destport} %{WORD:protocol}%{SPACE}%{WORD}:%{POSINT:ttl}%{SPACE}%{WORD}:%{BASE16NUM:tos}%{SPACE}%{WORD}:%{POSINT:id}%{SPACE}%{WORD}:%{POSINT:iplen}%{SPACE}%{WORD}:%{POSINT:dgmlen}%{SPACE}%{WORD:flag}%{SPACE}%{DATA:something}%{SPACE}%{WORD}:%{SPACE}%{BASE16NUM:seq}%{SPACE}%{WORD}:%{SPACE}%{BASE16NUM:ack}%{SPACE}%{WORD}:%{SPACE}%{BASE16NUM:win}%{SPACE}%{WORD}:%{SPACE}%{POSINT:tcplen}%{SPACE}TCP Options \(%{POSINT:tcpoption}\)%{SPACE}=>%{SPACE}%{WORD}:%{SPACE}%{POSINT:mss}%{SPACE}%{WORD:sack}%{SPACE}TS: %{POSINT:ts}%{SPACE}%{INT:xvalue}%{SPACE}%{WORD:nop}%{SPACE}%{WORD}:%{SPACE}%{POSINT:ws}`

 ![Line2](https://us1.discourse-cdn.com/elastic/original/3X/0/9/09c624719510b6f6456edcc388e641fa6c0c35a6.png)

---

<div class="post-metadata">

**Author:** ![anushka1203](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/anushka1203/32/98018_2.png) [@anushka1203](https://discuss.elastic.co/u/anushka1203)\
**Post date:** [February 10, 2023, 4:21am UTC](https://discuss.elastic.co/t/grok-pattern-creation/324605/7 "2023-02-10T04:21:55Z")

</div>

Oh yes, this is very much helpful thank you!

---

<div class="post-metadata">

**Author:** ![anushka1203](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/anushka1203/32/98018_2.png) [@anushka1203](https://discuss.elastic.co/u/anushka1203)\
**Post date:** [February 10, 2023, 4:22am UTC](https://discuss.elastic.co/t/grok-pattern-creation/324605/8 "2023-02-10T04:22:09Z")

</div>

This works! thanks!

---

<div class="post-metadata">

**Author:** ![Rios](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rios/32/95745_2.png) [@Rios](https://discuss.elastic.co/u/Rios)\
**Post date:** [February 10, 2023, 6:25am UTC](https://discuss.elastic.co/t/grok-pattern-creation/324605/9 "2023-02-10T06:25:33Z")

</div>

Review the field names like something, sack, nop, ... and do you need timestamp only or all parts:  
(?%{MONTHNUM:month}/%{MONTHDAY:day}-%{TIME:time}). Te 2nd grok pattern has only the timestamp field. Test, and correct if some filed has wrong type, like WORD expects only [a-zA-Z0-9\_]  
If everything is OK, you shouln't have the `_grokparsefailure` tag

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 10, 2023, 6:26am UTC](https://discuss.elastic.co/t/grok-pattern-creation/324605/10 "2023-03-10T06:26:27Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
