# Grok regular expression support in Filebeats

**URL:** <https://discuss.elastic.co/t/grok-regular-expression-support-in-filebeats/110880>\
**Category:** Beats\
**Created:** [December 8, 2017, 5:13pm UTC](https://discuss.elastic.co/t/grok-regular-expression-support-in-filebeats/110880 "2017-12-08T17:13:40Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![ramon\_garcia](https://avatars.discourse-cdn.com/v4/letter/r/94ad74/32.png) [@ramon\_garcia](https://discuss.elastic.co/u/ramon_garcia)\
**Post date:** [December 8, 2017, 5:13pm UTC](https://discuss.elastic.co/t/grok-regular-expression-support-in-filebeats/110880/1 "2017-12-08T17:13:40Z")

</div>

Hello,

I have developed Grok expression support in Beats.

You can get the code from [https://github.com/ramon-garcia/beats/tree/extend-processors/](https://github.com/ramon-garcia/beats/tree/extend-processors/) (branch extended-processors). You can see the documentation here [https://github.com/ramon-garcia/beats/blob/extend-processors/libbeat/docs/processors-using.asciidoc#grok](https://github.com/ramon-garcia/beats/blob/extend-processors/libbeat/docs/processors-using.asciidoc#grok)

I offered a [pull request](https://github.com/elastic/beats/pull/5790) to Beats, but the development team disagrees about client side processing. The prefer everything processed in the server side.

Anyway, if you want to process your logs in the client side, you can look at my code (grok.go and grok\_test.go) My experience is that writting Beats processing modules is simple. I encourage you to do so.

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [December 8, 2017, 5:27pm UTC](https://discuss.elastic.co/t/grok-regular-expression-support-in-filebeats/110880/2 "2017-12-08T17:27:01Z")

</div>

Maybe you could turn it into a plugin like I did with this [beats-processor-fingerprint](https://github.com/andrewkroh/beats-processor-fingerprint). The only tricky thing at the current time with Go plugins is that they need to be compiled against the same source as the Beat and with the same Go version.

---

<div class="post-metadata">

**Author:** ![ramon\_garcia](https://avatars.discourse-cdn.com/v4/letter/r/94ad74/32.png) [@ramon\_garcia](https://discuss.elastic.co/u/ramon_garcia)\
**Post date:** [December 8, 2017, 5:49pm UTC](https://discuss.elastic.co/t/grok-regular-expression-support-in-filebeats/110880/3 "2017-12-08T17:49:01Z")

</div>

Thank you very much!! Didn't know that this was possible.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 29, 2017, 5:13pm UTC](https://discuss.elastic.co/t/grok-regular-expression-support-in-filebeats/110880/4 "2017-12-29T17:13:46Z")

</div>

This topic was automatically closed after 21 days. New replies are no longer allowed.
