# Grok Pattern for logstash

**URL:** <https://discuss.elastic.co/t/grok-pattern-for-logstash/149783>\
**Category:** Logstash\
**Created:** [September 25, 2018, 8:51am UTC](https://discuss.elastic.co/t/grok-pattern-for-logstash/149783 "2018-09-25T08:51:35Z")\
**Posts on this page:** 15\
**Page:** 1

<div class="post-metadata">

**Author:** ![muthu\_kumar1](https://avatars.discourse-cdn.com/v4/letter/m/f17d59/32.png) [@muthu\_kumar1](https://discuss.elastic.co/u/muthu_kumar1)\
**Post date:** [September 25, 2018, 8:51am UTC](https://discuss.elastic.co/t/grok-pattern-for-logstash/149783/1 "2018-09-25T08:51:35Z")

</div>

Hi ,

Can someone help on grok pattern for the below logs

message#IE-7.0||trident/4.0#message

tried with below pattern

%{WORD:THREADNAME}#%{HOSTNAME:IE}||trident/%{JAVACLASS}#{%WORD:MESSAGE}

but not worked..please help

Regards  
Muthu

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [September 25, 2018, 9:14am UTC](https://discuss.elastic.co/t/grok-pattern-for-logstash/149783/2 "2018-09-25T09:14:39Z")

</div>

`|` has a special meaning and must be escaped. Otherwise it should work, even though using HOSTNAME and JAVACLASS doesn't really make sense.

---

<div class="post-metadata">

**Author:** ![hello\_34](https://avatars.discourse-cdn.com/v4/letter/h/b5ac83/32.png) [@hello\_34](https://discuss.elastic.co/u/hello_34)\
**Post date:** [September 25, 2018, 9:48am UTC](https://discuss.elastic.co/t/grok-pattern-for-logstash/149783/3 "2018-09-25T09:48:33Z")

</div>

Hi All,

my CSV File has one date field ,by default kibana is taking it as string how to change the type of the field. I'm not able to apply grok filter

Thanks in Advance

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [September 25, 2018, 11:09am UTC](https://discuss.elastic.co/t/grok-pattern-for-logstash/149783/4 "2018-09-25T11:09:55Z")

</div>

You can use a date filter to convert a field into an ISO8601 format that ES recognizes as a date, or you can set the index's mappings to recognize your particular date format as a date.

---

<div class="post-metadata">

**Author:** ![hello\_34](https://avatars.discourse-cdn.com/v4/letter/h/b5ac83/32.png) [@hello\_34](https://discuss.elastic.co/u/hello_34)\
**Post date:** [September 26, 2018, 5:14am UTC](https://discuss.elastic.co/t/grok-pattern-for-logstash/149783/5 "2018-09-26T05:14:03Z")

</div>

Below is my csv Data

| JOB | STATUS | RESULT | STARTTIME | ENDTIME | ACTIVE | TRIGGERTIME | CUSTOMSTATUS | REGION | Date |
| --- | --- | --- | --- | --- | --- | --- | --- | --- | --- |
| Solr Indexed Property(es) | ABORTED | ERROR | Mon Jun 18 11:54:58 GMT 2018 | null | TRUE | [] | FAILED\_ABORTED\_JOB | EU | 11/13/2018 |
| Solr Indexed Property(en\_GB) | FINISHED | FAILURE | Mon Jul 02 15:50:18 GMT 2018 | Mon Jul 02 15:50:24 GMT 2018 | TRUE | [] | FAILED\_ABORTED\_JOB | EU | 11/13/2018 |
| sk-tokoAutomatedReturnJob | FINISHED | FAILURE | Tue Jul 03 02:30:02 GMT 2018 | Tue Jul 03 02:30:02 GMT 2018 | TRUE | [Tue Jul 03 03:00:00 GMT 2018] | FAILED\_ABORTED\_JOB | EU | 11/13/2018 |
| delete-esIndex-cronJob | ABORTED | FAILURE | Tue Jun 19 09:10:31 GMT 2018 | null | TRUE | [Tue Jul 03 02:47:15 GMT 2018] | FAILED\_ABORTED\_JOB | EU | 11/13/2018 |
| update-beIndex-cronJob | ABORTED | FAILURE | Thu Jun 28 14:48:02 GMT 2018 | null | TRUE | [Tue Jul 03 02:46:51 GMT 2018] | FAILED\_ABORTED\_JOB | EU | 11/13/2018 |

and my config file is in below format

input  
{  
file  
{  
path =\> "/ELK/data/cronjobtrend.csv"  
start\_position =\> "beginning"  
sincedb\_path =\> "NUL"  
ignore\_older =\> 0

}  
}  
filter  
{  
csv  
{  
separator=\> ","  
columns =\> ["JOB","STATUS","RESULT","STARTTIME","ENDTIME","ACTIVE","TRIGGERTIME","CUSTOMSTATUS","REGION","Date"]  
}  
}  
output  
{  
elasticsearch  
{  
index =\> "cronjobtrend"  
#document\_type =\> "cronjobtrend"  
}  
}

where should i add the grok filter for Date column in the CSV and please provide me the syntax

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [September 26, 2018, 6:26am UTC](https://discuss.elastic.co/t/grok-pattern-for-logstash/149783/6 "2018-09-26T06:26:11Z")

</div>

You don't need a grok filter, you need a date filter. Two of them, in fact; one that processes `STARTTIME` and one that processes `ENDTIME`. The date filter documentation lists how the patterns for parsing timestamps are built up. You probably need something like `EEE MMM dd HH:mm:ss 'GMT' yyyy`, assuming that the timezone is always GMT.

---

<div class="post-metadata">

**Author:** ![hello\_34](https://avatars.discourse-cdn.com/v4/letter/h/b5ac83/32.png) [@hello\_34](https://discuss.elastic.co/u/hello_34)\
**Post date:** [September 26, 2018, 6:45am UTC](https://discuss.elastic.co/t/grok-pattern-for-logstash/149783/7 "2018-09-26T06:45:38Z")

</div>

yes time is always GMT  
Is the below one looks fine?  
input  
{  
file  
{  
path =\> "/ELK/data/cronjobtrend.csv"  
start\_position =\> "beginning"  
sincedb\_path =\> "NUL"  
ignore\_older =\> 0

}  
}  
filter  
{  
csv  
{  
separator=\> ","  
columns =\> ["JOB","STATUS","RESULT","STARTTIME","ENDTIME","ACTIVE","TRIGGERTIME","CUSTOMSTATUS","REGION","Date"]  
}  
date {  
match =\> ["STARTTIME", "EEE MMM dd HH:mm:ss 'GMT' yyyy"]  
target =\> "Date"  
}  
}  
output  
{  
elasticsearch  
{  
index =\> "cronjobtrend"  
#document\_type =\> "cronjobtrend"  
}  
}

---

<div class="post-metadata">

**Author:** ![hello\_34](https://avatars.discourse-cdn.com/v4/letter/h/b5ac83/32.png) [@hello\_34](https://discuss.elastic.co/u/hello_34)\
**Post date:** [September 26, 2018, 7:21am UTC](https://discuss.elastic.co/t/grok-pattern-for-logstash/149783/8 "2018-09-26T07:21:57Z")

</div>

Thanks magnnusbaeck its working 🙂

Can you give the format for Date Column

---

<div class="post-metadata">

**Author:** ![hello\_34](https://avatars.discourse-cdn.com/v4/letter/h/b5ac83/32.png) [@hello\_34](https://discuss.elastic.co/u/hello_34)\
**Post date:** [September 26, 2018, 10:56am UTC](https://discuss.elastic.co/t/grok-pattern-for-logstash/149783/9 "2018-09-26T10:56:16Z")

</div>

Hi Magnusbaeck

can you provide me the format of date 11/13/2018

my config file is in below format

input  
{  
file  
{  
path =\> "/ELK/data/cronjobtrend.csv"  
start\_position =\> "beginning"  
sincedb\_path =\> "NUL"  
ignore\_older =\> 0

}  
}  
filter  
{  
csv  
{  
separator=\> ","  
columns =\> ["JOB","STATUS","RESULT","STARTTIME","ENDTIME","ACTIVE","TRIGGERTIME","CUSTOMSTATUS","REGION","Date"]  
}

date {  
match =\> ["Date", "mm/dd/YYYY"]  
target =\> "Date"  
}

}  
output  
{  
elasticsearch  
{  
index =\> "cronjobtrend\_date"  
#document\_type =\> "cronjobtrend\_date"  
}  
}

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [September 26, 2018, 10:59am UTC](https://discuss.elastic.co/t/grok-pattern-for-logstash/149783/10 "2018-09-26T10:59:55Z")

</div>

Check the date filter documentation. "mm" does not mean month.

---

<div class="post-metadata">

**Author:** ![hello\_34](https://avatars.discourse-cdn.com/v4/letter/h/b5ac83/32.png) [@hello\_34](https://discuss.elastic.co/u/hello_34)\
**Post date:** [September 27, 2018, 4:46am UTC](https://discuss.elastic.co/t/grok-pattern-for-logstash/149783/11 "2018-09-27T04:46:24Z")

</div>

input  
{  
file  
{  
path =\> "/ELK/data/cronjobtrend.csv"  
start\_position =\> "beginning"  
sincedb\_path =\> "NUL"  
ignore\_older =\> 0

}  
}  
filter  
{  
csv  
{  
separator=\> ","  
columns =\> ["JOB","STATUS","RESULT","STARTTIME","ENDTIME","ACTIVE","TRIGGERTIME","CUSTOMSTATUS","REGION","Date"]  
}

date {  
match =\> ["Date", "MM/dd/YYYY"]  
target =\> "Date"  
}

}  
output  
{  
elasticsearch  
{  
index =\> "cronjobtrend\_date"  
#document\_type =\> "cronjobtrend\_date"  
}  
}

even though i tried the above one its not taking "Date" column is not taking as date format

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [September 27, 2018, 6:14am UTC](https://discuss.elastic.co/t/grok-pattern-for-logstash/149783/12 "2018-09-27T06:14:40Z")

</div>

Please show an example document stored in ES. Copy/paste the raw JSON from the JSON tab in Kibana's Discover view.

---

<div class="post-metadata">

**Author:** ![hello\_34](https://avatars.discourse-cdn.com/v4/letter/h/b5ac83/32.png) [@hello\_34](https://discuss.elastic.co/u/hello_34)\
**Post date:** [September 27, 2018, 9:22am UTC](https://discuss.elastic.co/t/grok-pattern-for-logstash/149783/13 "2018-09-27T09:22:28Z")

</div>

it's working fine  
Thanks magnusbaeck

---

<div class="post-metadata">

**Author:** ![elad\_sheinfeld](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/elad_sheinfeld/32/91900_2.png) [@elad\_sheinfeld](https://discuss.elastic.co/u/elad_sheinfeld)\
**Post date:** [October 8, 2018, 10:32am UTC](https://discuss.elastic.co/t/grok-pattern-for-logstash/149783/14 "2018-10-08T10:32:28Z")

</div>

> [@muthu\_kumar1](#):
>
> message#IE-7.0||trident/4.0#message

try that:  
%{WORD:THREADNAME}#%{HOSTNAME:IE}||trident/%{JAVACLASS}#%{WORD:MESSAGE}

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 5, 2018, 10:32am UTC](https://discuss.elastic.co/t/grok-pattern-for-logstash/149783/15 "2018-11-05T10:32:31Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
