Grok - Positive Lookbehind



Does grok match support 'positive lookbehind'? I'm take everything after 'Details=' in the following json example:


match => ["Field", "(?< Field2 >(?<=Details=).*)"]

I am getting grok failures even though the construction in the match is sound..

(Paris Mermigkas) #2

Grok does indeed support lookaheads/lookbehinds as regex expression. The reason you're probably getting grokfailures is those spaces inside the capture group name. Try this instead

grok {
    match => {
        "Field" => "(?<Field2>(?<=Details=).*)"

(system) #3

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.