# GROK pattern

**URL:** <https://discuss.elastic.co/t/grok-pattern/322443>\
**Category:** Logs\
**Created:** [January 4, 2023, 9:42am UTC](https://discuss.elastic.co/t/grok-pattern/322443 "2023-01-04T09:42:41Z")\
**Posts on this page:** 11\
**Page:** 1

<div class="post-metadata">

**Author:** ![Hamunaptroid](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/hamunaptroid/32/63795_2.png) [@Hamunaptroid](https://discuss.elastic.co/u/Hamunaptroid)\
**Post date:** [January 4, 2023, 9:42am UTC](https://discuss.elastic.co/t/grok-pattern/322443/1 "2023-01-04T09:42:41Z")

</div>

Hello,

I have trouble with writing GROK pattern for system logs. My goal is to parse logs in form "systemctl -o verbose" which looks like this

```auto
Wed 2022-10-12 09:08:42.759756
    _TRANSPORT=kernel
    SYSLOG_IDENTIFIER=kernel
    _HOSTNAME=amvscore1
    PRIORITY=6
    MESSAGE=2022-10-12 09:08:42 INFO instance/beat.go:498 filebeat stopped

```

So far I was able to match only date with %{TIMESTAMP\_ISO8601:Time}, but I don't know how to match other fields. Each field is in new line.

Can anyone help me out please ?  
Thank you.

---

<div class="post-metadata">

**Author:** ![Rios](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rios/32/95745_2.png) [@Rios](https://discuss.elastic.co/u/Rios)\
**Post date:** [January 5, 2023, 11:47pm UTC](https://discuss.elastic.co/t/grok-pattern/322443/2 "2023-01-05T23:47:21Z")

</div>

Can you put few more, 3-4 samples?

---

<div class="post-metadata">

**Author:** ![legoguy1000](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/legoguy1000/32/54301_2.png) [@legoguy1000](https://discuss.elastic.co/u/legoguy1000)\
**Post date:** [January 6, 2023, 3:50am UTC](https://discuss.elastic.co/t/grok-pattern/322443/3 "2023-01-06T03:50:30Z")

</div>

Here's the start of a pattern. I didn't do the whole thing but it should give u the idea of how to continue.

```auto
%{DAY} %{TIMESTAMP_ISO8601:date}\n%{SPACE}_TRANSPORT=%{NOTSPACE:transport}\n%{SPACE}SYSLOG_IDENTIFIER=%{NOTSPACE:syslog_id}\n%{SPACE}_HOSTNAME=%{NOTSPACE:hostname}

```

---

<div class="post-metadata">

**Author:** ![Hamunaptroid](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/hamunaptroid/32/63795_2.png) [@Hamunaptroid](https://discuss.elastic.co/u/Hamunaptroid)\
**Post date:** [January 10, 2023, 1:37pm UTC](https://discuss.elastic.co/t/grok-pattern/322443/4 "2023-01-10T13:37:37Z")

</div>

Hello @Rios,

Every log is exactly the same. I mean the exact same structure because it is log from journalctl.  
This is the only way how to parse fields from all systemd logs.

---

<div class="post-metadata">

**Author:** ![Rios](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rios/32/95745_2.png) [@Rios](https://discuss.elastic.co/u/Rios)\
**Post date:** [January 10, 2023, 1:39pm UTC](https://discuss.elastic.co/t/grok-pattern/322443/5 "2023-01-10T13:39:00Z")

</div>

OK. Have you tested legoguy1000 grok pattern?

---

<div class="post-metadata">

**Author:** ![Hamunaptroid](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/hamunaptroid/32/63795_2.png) [@Hamunaptroid](https://discuss.elastic.co/u/Hamunaptroid)\
**Post date:** [January 10, 2023, 2:12pm UTC](https://discuss.elastic.co/t/grok-pattern/322443/6 "2023-01-10T14:12:12Z")

</div>

@Rios

Yes I have, that one didn't work for me, but It gave me enough to continue.

```auto
%{DAY} %{TIMESTAMP_ISO8601:date}|(\n%{SPACE})|_TRANSPORT=%{NOTSPACE:transport}|(\n%{SPACE})|SYSLOG_IDENTIFIER=%{NOTSPACE:syslog_id}|(\n%{SPACE})|_HOSTNAME=%{NOTSPACE:hostname}|
(\n%{SPACE})|PRIORITY=%{NOTSPACE:level}

```

Although, I can't parse the content of "MESSAGE" but I will figure it out 🙂

What I don't understand is why I am able to match almost everything in pattern I posted in [https://grokdebugger.com/](https://grokdebugger.com/) but I can match only timestamp in kibana dev tools. I tried legoguy1000's pattern in kibana as well, but that didnt work at all

---

<div class="post-metadata">

**Author:** ![Rios](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rios/32/95745_2.png) [@Rios](https://discuss.elastic.co/u/Rios)\
**Post date:** [January 10, 2023, 2:24pm UTC](https://discuss.elastic.co/t/grok-pattern/322443/7 "2023-01-10T14:24:03Z")

</div>

Can you dump from the debugger, what you receive in an original message?

---

<div class="post-metadata">

**Author:** ![Hamunaptroid](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/hamunaptroid/32/63795_2.png) [@Hamunaptroid](https://discuss.elastic.co/u/Hamunaptroid)\
**Post date:** [January 10, 2023, 2:37pm UTC](https://discuss.elastic.co/t/grok-pattern/322443/8 "2023-01-10T14:37:41Z")

</div>

I am just trying to parse this log in online grok debugger or kibana grok debugger. I didn't put this pattern in logstash yet

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/c/9/c91239f5ce7f0a33d9382df64d509cea8f759ce4.png)

but not working in kibana ... perhaps grok debugger in kibana thinks each line is new log ?

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/d/4/d48a591ab069b5488374e64550c28307e2a46cc0.png)

---

<div class="post-metadata">

**Author:** ![Rios](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rios/32/95745_2.png) [@Rios](https://discuss.elastic.co/u/Rios)\
**Post date:** [January 10, 2023, 2:52pm UTC](https://discuss.elastic.co/t/grok-pattern/322443/9 "2023-01-10T14:52:38Z")

</div>

Run your LS conf read what you receive in Ruby debug or save in file without any filtering.

---

<div class="post-metadata">

**Author:** ![Hamunaptroid](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/hamunaptroid/32/63795_2.png) [@Hamunaptroid](https://discuss.elastic.co/u/Hamunaptroid)\
**Post date:** [January 13, 2023, 11:39am UTC](https://discuss.elastic.co/t/grok-pattern/322443/10 "2023-01-13T11:39:49Z")

</div>

Thanks, I discovered that filebeat supports sending journald logs and I got it working 🙂  
Everything is working 🙂 we can close this topic

Thank you for all the help.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 10, 2023, 11:40am UTC](https://discuss.elastic.co/t/grok-pattern/322443/11 "2023-02-10T11:40:04Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
