# Grok Syntax

**URL:** <https://discuss.elastic.co/t/grok-syntax/249372>\
**Category:** Logstash\
**Created:** [September 21, 2020, 1:58pm UTC](https://discuss.elastic.co/t/grok-syntax/249372 "2020-09-21T13:58:17Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![kotis](https://avatars.discourse-cdn.com/v4/letter/k/9dc877/32.png) [@kotis](https://discuss.elastic.co/u/kotis)\
**Post date:** [September 21, 2020, 1:58pm UTC](https://discuss.elastic.co/t/grok-syntax/249372/1 "2020-09-21T13:58:17Z")

</div>

Hi all 🙂 ,

I need help with a log file that I need to make a filter from it but I can't since I am not very experienced with grok..

The log is like  
2020-07-27 03:04:04,708 INFO hosty.bow.hh.hsw\_5421 Target 'RegistrationService', Duration 5738051 ns, Type 'USERVALIDATION', Params '[SOMETHING]'

I need to extract all the fields.

Thank you all for your time 🙂

---

<div class="post-metadata">

**Author:** ![kavierkoo](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kavierkoo/32/86555_2.png) [@kavierkoo](https://discuss.elastic.co/u/kavierkoo)\
**Post date:** [September 21, 2020, 4:13pm UTC](https://discuss.elastic.co/t/grok-syntax/249372/2 "2020-09-21T16:13:26Z")

</div>

Hi,

The logs seems to have proper delimiter, I think dissect filter plugin might be useful to parse the logs.

> **[Dissect filter plugin | Logstash Reference \[7.9\] | Elastic](https://www.elastic.co/guide/en/logstash/current/plugins-filters-dissect.html)**

Hope this could help you!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 19, 2020, 4:13pm UTC](https://discuss.elastic.co/t/grok-syntax/249372/3 "2020-10-19T16:13:30Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
