# Grok pattern to search

**URL:** <https://discuss.elastic.co/t/grok-pattern-to-search/150059>\
**Category:** Kibana\
**Created:** [September 26, 2018, 5:18pm UTC](https://discuss.elastic.co/t/grok-pattern-to-search/150059 "2018-09-26T17:18:18Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![yungdebt](https://avatars.discourse-cdn.com/v4/letter/y/d07c76/32.png) [@yungdebt](https://discuss.elastic.co/u/yungdebt)\
**Post date:** [September 26, 2018, 5:18pm UTC](https://discuss.elastic.co/t/grok-pattern-to-search/150059/1 "2018-09-26T17:18:18Z")

</div>

sev=1 proto=TCP

trying to use grok with this pattern because sometimes my log format changes, but the output is TCP and null.. how can I account for a pattern to search the whole string and extract the value?

(.+proto=?=%{USERNAME:proto})?(.+sev=?=%{USERNAME:sev})?

---

<div class="post-metadata">

**Author:** ![jen-huang](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jen-huang/32/74327_2.png) [@jen-huang](https://discuss.elastic.co/u/jen-huang)\
**Post date:** [September 26, 2018, 5:37pm UTC](https://discuss.elastic.co/t/grok-pattern-to-search/150059/2 "2018-09-26T17:37:52Z")

</div>

Hi, I recommend a few changes to your pattern:

1. Switch the order since `sev` is first in your string
2. Change `.+` to `.*`, there are no characters before `sev`
3. (Optional) use `NUMBER` for `sev` if that value is always numeric

Final pattern:  
`(.*sev=?=%{NUMBER:sev})?(.*proto=?=%{USERNAME:proto})?`

Let me know if this helps.

---

<div class="post-metadata">

**Author:** ![yungdebt](https://avatars.discourse-cdn.com/v4/letter/y/d07c76/32.png) [@yungdebt](https://discuss.elastic.co/u/yungdebt)\
**Post date:** [September 26, 2018, 5:46pm UTC](https://discuss.elastic.co/t/grok-pattern-to-search/150059/3 "2018-09-26T17:46:46Z")

</div>

sorry I think i needed to be more clear.  
I'm trying to write an expression that is able to parse both:

1. sev=1 proto=TCP
2. proto=TCP sev=1

Since in my log structure, the position of the values sometimes move around in a new line.

---

<div class="post-metadata">

**Author:** ![jen-huang](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jen-huang/32/74327_2.png) [@jen-huang](https://discuss.elastic.co/u/jen-huang)\
**Post date:** [September 26, 2018, 6:04pm UTC](https://discuss.elastic.co/t/grok-pattern-to-search/150059/4 "2018-09-26T18:04:40Z")

</div>

If there are the only two values, I'd suggest a simple `OR` regex:

`(.*proto=?=%{USERNAME:proto}.*sev=?=%{NUMBER:sev})|(.*sev=?=%{NUMBER:sev}.*proto=?=%{USERNAME:proto})`

Anything beyond two values which can arbitrarily move around will involve a more complex regex pattern.

---

<div class="post-metadata">

**Author:** ![yungdebt](https://avatars.discourse-cdn.com/v4/letter/y/d07c76/32.png) [@yungdebt](https://discuss.elastic.co/u/yungdebt)\
**Post date:** [September 26, 2018, 6:39pm UTC](https://discuss.elastic.co/t/grok-pattern-to-search/150059/5 "2018-09-26T18:39:16Z")

</div>

interesting, thanks for your reply.

So it seems the flow must go in sequential order, and thus there isn't a way for one to write a regex pattern that would start from the beginning search the entire string and extract a match, and then start from the beginning again and continue?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 24, 2018, 6:39pm UTC](https://discuss.elastic.co/t/grok-pattern-to-search/150059/6 "2018-10-24T18:39:25Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
