# Grok pattern test

**URL:** <https://discuss.elastic.co/t/grok-pattern-test/134835>\
**Category:** Logstash\
**Created:** [June 6, 2018, 3:03pm UTC](https://discuss.elastic.co/t/grok-pattern-test/134835 "2018-06-06T15:03:00Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![rouchad\_rouchad](https://avatars.discourse-cdn.com/v4/letter/r/4491bb/32.png) [@rouchad\_rouchad](https://discuss.elastic.co/u/rouchad_rouchad)\
**Post date:** [June 6, 2018, 3:03pm UTC](https://discuss.elastic.co/t/grok-pattern-test/134835/1 "2018-06-06T15:03:00Z")

</div>

hi everyone ,  
i wanna do filter grok for some expression  
the filter work but there is only one probleme

there is the txt :  
we have detected abuse from the IP address ( 197.230.107.154 ), which according to a whois lookup is on your network. We would appreciate if you would investigate and take action as appropriate. Any feedback is welcome but not mandatory.  
Log lines are given below, but please ask if you require any further information.  
(If you are not the correct person to contact about this please accept our apologies - your e-mail address was extracted from the whois record by an automated process. This mail was generated by Fail2Ban.)  
IP of the attacker: 197.230.107.154  
You can contact us by using: [abuse-reply@keyweb.de](mailto:abuse-reply@keyweb.de)  
Addresses to send to: noc\_isp@meditel.ma

there is the filter grok :  
%{GREEDYDATA:message} (%{IPV4:attacker}) _%{GREEDYDATA:message}\n_%{GREEDYDATA:message}\n\*%{GREEDYDATA:message} \n\*%{GREEDYDATA:message}\n\*%{CISCO\_REASON}: %{GREEDYDATA:attacker2} \n\*%{CISCO\_REASON}: %{GREEDYDATA:sender}\n\*%{CISCO\_REASON}: %{GREEDYDATA:receiver}

there is the rsult i get in kibana :

attacker : 197.230.107.154  
attacker 2 : 197.230.107.154 You can contact us by  
sender : [abuse-reply@keyweb.de](mailto:abuse-reply@keyweb.de) Addresses to send to  
receiver : noc\_isp@meditel.ma

what i need to do for attacker 2 and sender ?

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [June 6, 2018, 3:39pm UTC](https://discuss.elastic.co/t/grok-pattern-test/134835/2 "2018-06-06T15:39:54Z")

</div>

Once again, do not use a pattern using multiple GREEDYDATA. Instead, use multiple grok patterns, each with just enough context to get the piece of data you want. For example:

```
grok { 
    break_on_match => false
    match => { 
        "message" => [
            "abuse from the IP address \( %{IPV4:attacker1} \)",
            "^IP of the attacker: %{IPV4:attacker2}$",
            "^You can contact us by using: %{DATA:sender}$"
        ]
    }
}
```

---

<div class="post-metadata">

**Author:** ![rouchad\_rouchad](https://avatars.discourse-cdn.com/v4/letter/r/4491bb/32.png) [@rouchad\_rouchad](https://discuss.elastic.co/u/rouchad_rouchad)\
**Post date:** [June 6, 2018, 3:53pm UTC](https://discuss.elastic.co/t/grok-pattern-test/134835/3 "2018-06-06T15:53:06Z")

</div>

thank u very much Badger ,

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 10, 2018, 12:59pm UTC](https://discuss.elastic.co/t/grok-pattern-test/134835/5 "2018-07-10T12:59:44Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
