# Grok regex with or

**URL:** <https://discuss.elastic.co/t/grok-regex-with-or/254815>\
**Category:** Logstash\
**Created:** [November 9, 2020, 6:56pm UTC](https://discuss.elastic.co/t/grok-regex-with-or/254815 "2020-11-09T18:56:29Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![Carlos\_Fernando\_Palm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/carlos_fernando_palm/32/77804_2.png) [@Carlos\_Fernando\_Palm](https://discuss.elastic.co/u/Carlos_Fernando_Palm)\
**Post date:** [November 9, 2020, 6:56pm UTC](https://discuss.elastic.co/t/grok-regex-with-or/254815/1 "2020-11-09T18:56:29Z")

</div>

Hello. I am trying to get some info from a message field using regular expressions. Concretely I want to get what's after certain keywords. This is the regex:

```auto
(?<="title" :)(.+?)(?=,)|((?<="description" :)(.+?)(?=,))

```

Now the problem is that when I run this on the kibana grok debugger it does not return all the text, just the first match.  
For example with this json:

```auto
 [{
 	"image": {
 		"url": "/path/toimages/images.jpg",
 		"alt": "Hotels"
 	},
 	"title": "Hotels",
 	"description": "The best places to stay in the city",
 	"elements": [{
 		"text": "Hotels",
 		"action": {
 			"type": "EVENT",
 			"name": "anyname",
 			"entities": {
 				"reply": "reply",
 				"option": "nameofoption",
 				"query": "thequery"
 			}
 		}
 	}]
 }]

```

The response of the regex is:

```auto
{
 "response": " \"Hotels\""
}

```

However when using [regexr.com](http://regexr.com) the text after title and the text after description are highlighted:

![image](https://us1.discourse-cdn.com/elastic/original/3X/e/8/e816d2525bf5a1279d90fae185d5526cff3a395d.png)

Does the regex used in grok support this kind of aggregation of text using the | operator?

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [November 9, 2020, 7:38pm UTC](https://discuss.elastic.co/t/grok-regex-with-or/254815/2 "2020-11-09T19:38:24Z")

</div>

grok does support alternation with |, but grok only returns the first match for a pattern. If you want all the matches use a ruby filter and do a String .scan

---

<div class="post-metadata">

**Author:** ![Carlos\_Fernando\_Palm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/carlos_fernando_palm/32/77804_2.png) [@Carlos\_Fernando\_Palm](https://discuss.elastic.co/u/Carlos_Fernando_Palm)\
**Post date:** [November 9, 2020, 8:41pm UTC](https://discuss.elastic.co/t/grok-regex-with-or/254815/3 "2020-11-09T20:41:34Z")

</div>

Thank you for the answer.  
Do you know where I can find documentation on how to use a ruby filter inside logstash.conf?

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [November 9, 2020, 9:26pm UTC](https://discuss.elastic.co/t/grok-regex-with-or/254815/4 "2020-11-09T21:26:47Z")

</div>

> [@Carlos\_Fernando\_Palm](#):
>
> Do you know where I can find documentation on how to use a ruby filter inside logstash.conf?

The ruby filter is documented [here](https://www.elastic.co/guide/en/logstash/current/plugins-filters-ruby.html). Examples of using scan in a ruby filter can be found [here](https://discuss.elastic.co/t/stop-proccesing-events-lines-after-first-grok-match/214696/8) and [here](https://discuss.elastic.co/t/logstash-odx-input-file-unconventional-input-file/225324/2).

---

<div class="post-metadata">

**Author:** ![Carlos\_Fernando\_Palm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/carlos_fernando_palm/32/77804_2.png) [@Carlos\_Fernando\_Palm](https://discuss.elastic.co/u/Carlos_Fernando_Palm)\
**Post date:** [November 10, 2020, 2:14pm UTC](https://discuss.elastic.co/t/grok-regex-with-or/254815/5 "2020-11-10T14:14:34Z")

</div>

Thanks

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 8, 2020, 2:14pm UTC](https://discuss.elastic.co/t/grok-regex-with-or/254815/6 "2020-12-08T14:14:35Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
