# Grok pattern

**URL:** https://discuss.elastic.co/t/grok-pattern/372704
**Category:** Logstash
**Tags:** elastic-stack-monitoring
**Created:** [January 2, 2025, 10:32am UTC](https://discuss.elastic.co/t/grok-pattern/372704 "2025-01-02T10:32:55Z")
**Posts on this page:** 1
**Showing post:** 2

<div class="post-metadata">

### Author: ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)
#### Post date: [January 2, 2025, 2:30pm UTC](https://discuss.elastic.co/t/grok-pattern/372704/2 "2025-01-02T14:30:16Z")

</div>

I wouldn't use grok, I would use dissect and kv filters. See [here](https://discuss.elastic.co/t/parsing-firewall-logs-in-logstash/212786/2) for an example.

---

_[View the full topic](https://discuss.elastic.co/t/grok-pattern/372704)._
