# Grok Pattern to extract brackets content

**URL:** <https://discuss.elastic.co/t/grok-pattern-to-extract-brackets-content/149802>\
**Category:** Logstash\
**Created:** [September 25, 2018, 10:35am UTC](https://discuss.elastic.co/t/grok-pattern-to-extract-brackets-content/149802 "2018-09-25T10:35:30Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![gsiap5](https://avatars.discourse-cdn.com/v4/letter/g/b9bd4f/32.png) [@gsiap5](https://discuss.elastic.co/u/gsiap5)\
**Post date:** [September 25, 2018, 10:35am UTC](https://discuss.elastic.co/t/grok-pattern-to-extract-brackets-content/149802/1 "2018-09-25T10:35:30Z")

</div>

Hi , I am attempting to create a grok pattern to parse the following log file.

14:10:49:158017|5860-00088:JMIX: ChainSubscription {INFO} Action {Update} Chain  
{MOVE.AA\_MOVE\_TOP.ABC\_SWITCH\_COMP\_GO.SHOP\_ABC} Snapshot {false}

I would like to assign fields in Kibana to;

ChainSubscription = INFO  
Action= Update  
Chain= MOVE.AA\_MOVE\_TOP.ABC\_SWITCH\_COMP\_GO.SHOP\_ABC  
Snapshot= false

appreciate any help here.

---

<div class="post-metadata">

**Author:** ![yaauie](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yaauie/32/23363_2.png) [@yaauie](https://discuss.elastic.co/u/yaauie)\
**Post date:** [September 26, 2018, 1:31am UTC](https://discuss.elastic.co/t/grok-pattern-to-extract-brackets-content/149802/2 "2018-09-26T01:31:29Z")

</div>

> [@gsiap5](#):
>
> 14:10:49:158017|5860-00088:JMIX: ChainSubscription {INFO} Action {Update} Chain {MOVE.AA\_MOVE\_TOP.ABC\_SWITCH\_COMP\_GO.SHOP\_ABC} Snapshot {false}

Are you _always_ going to have exactly those keys, or are the keys variable too?

If the keys are variable, the kv filter may be helpful:

```auto
filter {
  # first, split the message into component parts. I don't know
  # what the format of yours means, so I used the dissect filter
  # to split on the `:JMIX:` sequence. You can use grok if you'd
  # like to achieve similar. The point though, is that the entire
  # key/value sequence is put in a single var `[@metadata][kv]`.
  dissect {
     mapping => {
        "message" => "%{a}:JMIX:%{[@metadata][kv]}"
      }
  }
  # now we use the KV filter to split that up. This won't work well
  # if your squiggle-bracket-quoted values contain squiggle-brackets,
  # since it has no way to differentiate between a _meaningful_
  # squiggle-bracket and a _literal_ one.
  kv {
    "source" => "[@metadata][kv]"
    "field_split" => "}"
    "value_split" => "{"
    "trim_key" => " "
    "trim_value" => " "
  }
}

```

---

<div class="post-metadata">

**Author:** ![gsiap5](https://avatars.discourse-cdn.com/v4/letter/g/b9bd4f/32.png) [@gsiap5](https://discuss.elastic.co/u/gsiap5)\
**Post date:** [September 26, 2018, 2:38pm UTC](https://discuss.elastic.co/t/grok-pattern-to-extract-brackets-content/149802/3 "2018-09-26T14:38:06Z")

</div>

thank you

I couldn't get it to work. I am still working on your solution.

using this seems to work alot better.  
filter {  
grok {  
match =\> { "message" =\> ["%{TIME}|%{WORD:info}-%{WORD:ID2}:%{WORD:mgs\_level}:%{SPACE}%{WORD:code}%{SPACE}{%{W ORD:data2}}%{SPACE}%{WORD:code3}%{SPACE}{%{WORD:data3}}%{SPACE}%{WORD:code4}%{SPACE}{(?.\*?)}%{GREEDYDATA:msg}"] }  
}  
}

---

<div class="post-metadata">

**Author:** ![yaauie](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yaauie/32/23363_2.png) [@yaauie](https://discuss.elastic.co/u/yaauie)\
**Post date:** [September 26, 2018, 5:16pm UTC](https://discuss.elastic.co/t/grok-pattern-to-extract-brackets-content/149802/4 "2018-09-26T17:16:11Z")

</div>

> [@gsiap5](#):
>
> %{TIME}|%{WORD:info}-%{WORD:ID2}:%{WORD:mgs\_level}:%{SPACE}%{WORD:code}%{SPACE}{%{W ORD:data2}}%{SPACE}%{WORD:code3}%{SPACE}{%{WORD:data3}}%{SPACE}%{WORD:code4}%{SPACE}{(?.\*?)}%{GREEDYDATA:msg}

Grok patterns can get pretty complex; I prefer to start with the Dissect filter, and only move on to Grok if I encounter input that cannot be handled by Dissect. Dissect is especially great because you don't have to define perfect patterns for each captured variable, so it's easier to get things right.

Here, I've used your names for things and applied it to a Dissect matcher.

```auto
filter {
  # first, split the message into component parts. I don't know
  # what the format of yours means, so I used the dissect filter
  # to split on the `:JMIX:` sequence. You can use grok if you'd
  # like to achieve similar. The point though, is that the entire
  # key/value sequence is put in a single var `[@metadata][kv]`.
  dissect {
     mapping => {
        "message" => "%{}|%{info}-%{ID2}:%{mgs_level}: %{[@metadata][kv]}"
      }
  }
  # now we use the KV filter to split that up. This won't work well
  # if your squiggle-bracket-quoted values contain squiggle-brackets,
  # since it has no way to differentiate between a _meaningful_
  # squiggle-bracket and a _literal_ one.
  kv {
    "source" => "[@metadata][kv]"
    "field_split" => "}"
    "value_split" => "{"
    "trim_key" => " "
    "trim_value" => " "
  }
}

```

With your input, the rubydebug output looks like:

```auto
{
                  "ID2" => "00088",
            "mgs_level" => "JMIX",
             "Snapshot" => "false",
                 "info" => "5860",
    "ChainSubscription" => "INFO",
               "Action" => "Update",
                "Chain" => "MOVE.AA_MOVE_TOP.ABC_SWITCH_COMP_GO.SHOP_ABC",
              "message" => "14:10:49:158017|5860-00088:JMIX: ChainSubscription {INFO} Action {Update} Chain {MOVE.AA_MOVE_TOP.ABC_SWITCH_COMP_GO.SHOP_ABC} Snapshot {false}",
             "@version" => "1",
                 "host" => "castrovel.local",
           "@timestamp" => 2018-09-26T17:17:50.758Z
}

```

---

<div class="post-metadata">

**Author:** ![gsiap5](https://avatars.discourse-cdn.com/v4/letter/g/b9bd4f/32.png) [@gsiap5](https://discuss.elastic.co/u/gsiap5)\
**Post date:** [October 10, 2018, 7:19am UTC](https://discuss.elastic.co/t/grok-pattern-to-extract-brackets-content/149802/5 "2018-10-10T07:19:56Z")

</div>

many thanks

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 7, 2018, 7:20am UTC](https://discuss.elastic.co/t/grok-pattern-to-extract-brackets-content/149802/6 "2018-11-07T07:20:00Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
