# Grok pattern for a unique value inside a field

**URL:** <https://discuss.elastic.co/t/grok-pattern-for-a-unique-value-inside-a-field/288890>\
**Category:** Logstash\
**Created:** [November 10, 2021, 1:10pm UTC](https://discuss.elastic.co/t/grok-pattern-for-a-unique-value-inside-a-field/288890 "2021-11-10T13:10:21Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![sidharth\_vijayakumar](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sidharth_vijayakumar/32/97257_2.png) [@sidharth\_vijayakumar](https://discuss.elastic.co/u/sidharth_vijayakumar)\
**Post date:** [November 10, 2021, 1:10pm UTC](https://discuss.elastic.co/t/grok-pattern-for-a-unique-value-inside-a-field/288890/1 "2021-11-10T13:10:21Z")

</div>

need to create a new field status\_code with value-successful by using ingest pipeline when status inside message field has 200 and when status inside message field is 502,404,402 it muse create status\_code with value failed.

Figured out how to create the fields but was unable to pick the exact value of status from the logs. Sample logs:

{action:show,count:208,duration:6.38ms,status:200}

How do I write a grok pattern to pick status value alone from these logs? 200 has different logs compared to 404. Hence unable to define a common pattern(each 404 has a different log structure as well)

---

<div class="post-metadata">

**Author:** ![aaron-nimocks](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/aaron-nimocks/32/73965_2.png) [@aaron-nimocks](https://discuss.elastic.co/u/aaron-nimocks)\
**Post date:** [November 10, 2021, 9:34pm UTC](https://discuss.elastic.co/t/grok-pattern-for-a-unique-value-inside-a-field/288890/2 "2021-11-10T21:34:26Z")

</div>

You can do a [KV processor](https://www.elastic.co/guide/en/elasticsearch/reference/current/kv-processor.html) to parse the data. Then I added the code from your other thread. This should work if the field names are the same.

\*\* I see this is in the Logstash category but I believe you are still looking for an ingest pipeline solution. If you need it done in Logstash that can be all executed there also.

```auto
POST /_ingest/pipeline/_simulate
{
  "pipeline": {
    "processors": [
      {
        "kv": {
          "field": "message",
          "field_split": ",",
          "value_split": ":",
          "trim_key": "{",
          "trim_value": "}"
        }
      },
      {
        "set": {
          "if": "ctx.status == '200'",
          "field": "status_code",
          "value": "successful"
        }
      },
      {
        "set": {
          "if": "ctx.status == '404' || ctx.status == '502'",
          "field": "status_code",
          "value": "failed"
        }
      },
      {
        "remove": {
          "field": "message"
        }
      }
    ]
  },
  "docs": [
    {
      "_index": "index",
      "_id": "id",
      "_source": {
        "message": "{action:show,count:208,duration:6.38ms,status:200}"
      }
    },
    {
      "_index": "index",
      "_id": "id",
      "_source": {
        "message": "{action:show,count:208,duration:6.38ms,status:502}"
      }
    }
  ]
}

```

---

<div class="post-metadata">

**Author:** ![sidharth\_vijayakumar](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sidharth_vijayakumar/32/97257_2.png) [@sidharth\_vijayakumar](https://discuss.elastic.co/u/sidharth_vijayakumar)\
**Post date:** [November 12, 2021, 9:35am UTC](https://discuss.elastic.co/t/grok-pattern-for-a-unique-value-inside-a-field/288890/4 "2021-11-12T09:35:20Z")

</div>

Hi,  
Thanks a lot for ur suggestion and time but this was not working as expected. I used json processor to resolve this issue

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 10, 2021, 9:35am UTC](https://discuss.elastic.co/t/grok-pattern-for-a-unique-value-inside-a-field/288890/5 "2021-12-10T09:35:26Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
