# Grok pattern for snort alerts

**URL:** <https://discuss.elastic.co/t/grok-pattern-for-snort-alerts/306625>\
**Category:** Logstash\
**Created:** [June 8, 2022, 5:28am UTC](https://discuss.elastic.co/t/grok-pattern-for-snort-alerts/306625 "2022-06-08T05:28:19Z")\
**Posts on this page:** 1\
**Showing post:** 3

<div class="post-metadata">

**Author:** ![anushka1203](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/anushka1203/32/98018_2.png) [@anushka1203](https://discuss.elastic.co/u/anushka1203)\
**Post date:** [June 8, 2022, 5:11pm UTC](https://discuss.elastic.co/t/grok-pattern-for-snort-alerts/306625/3 "2022-06-08T17:11:43Z")

</div>

My apologies. These are my sample log messages-

```auto
05/25-12:03:17.905976 [**] [1:100001:1] ICMP Ping Detected [**] [Priority: 0] {IPV6-ICMP} fe80::20c:29ff:feba:be38 -> ff02::1
05/25-12:03:17.914533 [**] [1:100001:1] ICMP Ping Detected [**] [Classification: a i l] [Priority: 0] {IPV6-ICMP} fe80::20c:29ff:feca:579 -> ff02::16

```

ANd this is the pattern that works for the @nd entre but not the first one.

```auto
%{MONTHNUM:month}\/%{MONTHDAY:day}-%{HOUR:hour}:%{MINUTE:minute}:%{SECOND:second}\s+\[\*\*\] \[%{INT:ids_gid}:%{INT:ids_sid}:%{INT:ids_rev}\]\s+%{DATA:ids_proto}\s+\[\*\*\] \[.*?: %{DATA:Classification}\] \[.*?: %{INT:Priority}\] \{%{DATA:data}} %{IP:dst_ip} .*?> %{IP:dest_port}

```

It is due to the presence of the field "classification". how do I get it to work for both?

---

_[View the full topic](https://discuss.elastic.co/t/grok-pattern-for-snort-alerts/306625)._
