# Grok pattern to parse to multiple values

**URL:** <https://discuss.elastic.co/t/grok-pattern-to-parse-to-multiple-values/262651>\
**Category:** Logstash\
**Created:** [January 29, 2021, 1:50pm UTC](https://discuss.elastic.co/t/grok-pattern-to-parse-to-multiple-values/262651 "2021-01-29T13:50:38Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![Deny7](https://avatars.discourse-cdn.com/v4/letter/d/e0b2c6/32.png) [@Deny7](https://discuss.elastic.co/u/Deny7)\
**Post date:** [January 29, 2021, 1:50pm UTC](https://discuss.elastic.co/t/grok-pattern-to-parse-to-multiple-values/262651/1 "2021-01-29T13:50:38Z")

</div>

Hi,

I have log line like this:

> ",session":"kred06@gmail.com"

Grok Pattern:

```
(,"session":"(%{DATA:name}@%{DATA:company})?")?

```

and I want to split the email to values name and company and also save email as whole to session value. I can split it but I dont know how to save it to session value at the same time.

The values I want:

```
name: "kred06"
company: "gmail.com"
session: "kred06@gmail.com" 

```

Can Anybody help?

---

<div class="post-metadata">

**Author:** ![aaron-nimocks](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/aaron-nimocks/32/73965_2.png) [@aaron-nimocks](https://discuss.elastic.co/u/aaron-nimocks)\
**Post date:** [January 29, 2021, 2:12pm UTC](https://discuss.elastic.co/t/grok-pattern-to-parse-to-multiple-values/262651/2 "2021-01-29T14:12:56Z")

</div>

An easy solution is to just create a new field after your grok and combine the 2 fields together.

```auto
  mutate {
    add_field => {
      "session" => "%{[name]}@%{[company]}"
    }
  }

```

`"session" => "kred06@gmail.com"`

---

<div class="post-metadata">

**Author:** ![Deny7](https://avatars.discourse-cdn.com/v4/letter/d/e0b2c6/32.png) [@Deny7](https://discuss.elastic.co/u/Deny7)\
**Post date:** [January 29, 2021, 3:27pm UTC](https://discuss.elastic.co/t/grok-pattern-to-parse-to-multiple-values/262651/3 "2021-01-29T15:27:14Z")

</div>

Thanks, but name and company are marked as optional. When they are not there, it will show in kibana `"session" : "%{[name]}@%{[company]}"` How can I repair this?

---

<div class="post-metadata">

**Author:** ![aaron-nimocks](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/aaron-nimocks/32/73965_2.png) [@aaron-nimocks](https://discuss.elastic.co/u/aaron-nimocks)\
**Post date:** [January 29, 2021, 3:32pm UTC](https://discuss.elastic.co/t/grok-pattern-to-parse-to-multiple-values/262651/4 "2021-01-29T15:32:08Z")

</div>

Add a conditional to only add that field if company and name both exist.

```auto
  if [name] and [company] {
    mutate {
      add_field => {
        "session" => "%{[name]}@%{[company]}"
      }
    }
  }

```

---

<div class="post-metadata">

**Author:** ![Deny7](https://avatars.discourse-cdn.com/v4/letter/d/e0b2c6/32.png) [@Deny7](https://discuss.elastic.co/u/Deny7)\
**Post date:** [January 29, 2021, 3:45pm UTC](https://discuss.elastic.co/t/grok-pattern-to-parse-to-multiple-values/262651/5 "2021-01-29T15:45:59Z")

</div>

In my mutate I have also `replace => {"[type]" => "index-name"}` That needs to go throught every time. Can I define multiple mutate blocks?

```
  if [name] and [company] {
    mutate {
      add_field => {
        "session" => "%{[name]}@%{[company]}"
      }
    }
  }
mutate {
       replace => {"[type]" => "index-name"}
}
```

---

<div class="post-metadata">

**Author:** ![aaron-nimocks](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/aaron-nimocks/32/73965_2.png) [@aaron-nimocks](https://discuss.elastic.co/u/aaron-nimocks)\
**Post date:** [January 29, 2021, 3:49pm UTC](https://discuss.elastic.co/t/grok-pattern-to-parse-to-multiple-values/262651/6 "2021-01-29T15:49:29Z")

</div>

Yes. That will work.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 26, 2021, 3:50pm UTC](https://discuss.elastic.co/t/grok-pattern-to-parse-to-multiple-values/262651/7 "2021-02-26T15:50:15Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
