# Grok pattern for custome logs

**URL:** <https://discuss.elastic.co/t/grok-pattern-for-custome-logs/146873>\
**Category:** Logstash\
**Created:** [August 31, 2018, 2:00pm UTC](https://discuss.elastic.co/t/grok-pattern-for-custome-logs/146873 "2018-08-31T14:00:24Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![learnhub17](https://avatars.discourse-cdn.com/v4/letter/l/91b2a8/32.png) [@learnhub17](https://discuss.elastic.co/u/learnhub17)\
**Post date:** [August 31, 2018, 2:00pm UTC](https://discuss.elastic.co/t/grok-pattern-for-custome-logs/146873/1 "2018-08-31T14:00:25Z")

</div>

Hi,

version of logstash is: 6.3.2

I am parsing my nginx logs, logging format is:  
log\_format timed\_combined '$remote\_addr - $remote\_user [$time\_local] "$request" '  
'$status $body\_bytes\_sent "$http\_referer" '  
'"$http\_user\_agent" "$http\_x\_forwarded\_for" '  
'$request\_time $upstream\_response\_time $sent\_http\_x\_request\_id $pipe $hostname '  
'$cookie\_u\_role $sent\_http\_x\_runtime '  
'$cookie\_login\_impersonate\_id $cookie\_u\_email $mobile\_rewrite $http\_x\_amzn\_trace\_id "$virgin" "$pass\_server" "$pass\_server\_ssl" "$scheme" "$is\_varnish" "$varnish\_hit"';

Based on this format, my nginx log is:

192.3.1.3 - - [28/Aug/2018:08:10:00 +0000] "GET /sr/dev HTTP/1.1" 304 0 "[https://xyz.com/path](https://xyz.com/path)" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/68.0.3440.106 Safari/537.36" "-" 0.001 0.001 1b88bdb421456a362cb59954affd4ba9 . dev-server1 - 0.341967 - - do\_not\_perform - "000" "http://elb\_browsing" "[http://varnish](http://varnish)" "https" "1" "1"

My grok is :

match =\> { "message" =\> ["%{IPORHOST:[nginx][access][remote\_ip]} - %{DATA:[nginx][access][user\_name]} [%{HTTPDATE:[nginx][access][time]}] "%{WORD:[nginx][access][method]} %{DATA:[nginx][access][url]} HTTP/%{NUMBER:[nginx][access][http\_version]}" %{NUMBER:[nginx][access][response\_code]} %{NUMBER:[nginx][access][body\_sent][bytes]} "%{DATA:[nginx][access][domain]}" "%{DATA:[nginx][access][agent]}" %{NUMBER:request\_time} %{NUMBER:upstream\_time} %{NOTSPACE:[nginx][access][request\_id]}"] }

With this grok I can able to filter upto requested\_id but unable to skip "." character and then after "dev-server1" want to skip "-"  
Kindly help me to complete this.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 28, 2018, 2:08pm UTC](https://discuss.elastic.co/t/grok-pattern-for-custome-logs/146873/2 "2018-09-28T14:08:22Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
