# Grok Pattern

**URL:** <https://discuss.elastic.co/t/grok-pattern/281878>\
**Category:** Logstash\
**Created:** [August 18, 2021, 9:13pm UTC](https://discuss.elastic.co/t/grok-pattern/281878 "2021-08-18T21:13:53Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![leemase004](https://avatars.discourse-cdn.com/v4/letter/l/fbc32d/32.png) [@leemase004](https://discuss.elastic.co/u/leemase004)\
**Post date:** [August 18, 2021, 9:13pm UTC](https://discuss.elastic.co/t/grok-pattern/281878/1 "2021-08-18T21:13:53Z")

</div>

What is the correct syntax to incorporate raw regex expressions in between grok patterns?

Ex (Cisco device):

LOG: Aug 1 22:15:10 abc-hostname tcp

GROK pattern:  
%{CISCOTIMESTAMP:timestamp} \b\w+-\w+\b %{WORD:protocol}

The following regex \b\w+-\w+\b has successfully parsed abc-hostname when I run it on regex test sites but I am unable to get it to work on the grok debugger. I have tried playing around with the syntax with parenthesis and curly brackets but havent had any luck

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [August 18, 2021, 10:23pm UTC](https://discuss.elastic.co/t/grok-pattern/281878/2 "2021-08-18T22:23:41Z")

</div>

> [@leemase004](#):
>
> %{CISCOTIMESTAMP:timestamp} \b\w+-\w+\b %{WORD:protocol}

I cannot speak to any grok debuggers since I never use them, but it works just fine in logstash

```
input { generator { count => 1 lines => ['Aug 1 22:15:10 abc-hostname tcp'] } }
filter {
    grok { match => { "message" => "%{CISCOTIMESTAMP:timestamp} \b\w+-\w+\b %{WORD:protocol}" } }
}
output { stdout { codec => rubydebug { metadata => false } } }

```

results in

```
 "timestamp" => "Aug 1 22:15:10",
  "protocol" => "tcp",

```

---

<div class="post-metadata">

**Author:** ![leemase004](https://avatars.discourse-cdn.com/v4/letter/l/fbc32d/32.png) [@leemase004](https://discuss.elastic.co/u/leemase004)\
**Post date:** [August 19, 2021, 2:38pm UTC](https://discuss.elastic.co/t/grok-pattern/281878/3 "2021-08-19T14:38:04Z")

</div>

Hey thanks, my only follow up would be in the "results in" snippet you submitted there isnt a "hostname: abc-hostname". Do you know a way to make the Grok filter read that "abc-hostname" portion and give it a field?

---

<div class="post-metadata">

**Author:** ![leemase004](https://avatars.discourse-cdn.com/v4/letter/l/fbc32d/32.png) [@leemase004](https://discuss.elastic.co/u/leemase004)\
**Post date:** [August 19, 2021, 2:39pm UTC](https://discuss.elastic.co/t/grok-pattern/281878/4 "2021-08-19T14:39:25Z")

</div>

If I used %{WORD:hostname} it only takes "abc" and does not include the "-hostname"  
I am attempting to include the "-hostname" portion as well

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [August 19, 2021, 2:54pm UTC](https://discuss.elastic.co/t/grok-pattern/281878/5 "2021-08-19T14:54:53Z")

</div>

Use a [custom pattern](https://www.elastic.co/guide/en/logstash/current/plugins-filters-grok.html#_custom_patterns).

```
"%{CISCOTIMESTAMP:timestamp} \b(?<hostname)\w+-\w+)\b %{WORD:protocol}"
```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 16, 2021, 2:55pm UTC](https://discuss.elastic.co/t/grok-pattern/281878/6 "2021-09-16T14:55:54Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
