# Grokking multiple line formats

**URL:** <https://discuss.elastic.co/t/grokking-multiple-line-formats/109814>\
**Category:** Logstash\
**Created:** [November 30, 2017, 5:55pm UTC](https://discuss.elastic.co/t/grokking-multiple-line-formats/109814 "2017-11-30T17:55:51Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![StivOstenberg](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stivostenberg/32/4681_2.png) [@StivOstenberg](https://discuss.elastic.co/u/StivOstenberg)\
**Post date:** [November 30, 2017, 5:55pm UTC](https://discuss.elastic.co/t/grokking-multiple-line-formats/109814/1 "2017-11-30T17:55:51Z")

</div>

New to grokking, and trying to modify an AWS ELB log filter to handle AWS ALB logs (one additional field at the beginning, 4 at the end)

if [type] == "{{logstash\_elb\_access\_logs\_type}}" {  
grok {  
match =\> ["message", "%{TIMESTAMP\_ISO8601:log\_timestamp} %{NOTSPACE:elb\_name} %{IP:elb\_client\_ip}:%{INT:elb\_client\_port:int} (?:%{IP:elb\_backend\_ip}:%{NUMBER:elb\_backend\_port:int}|-) %{NUMBER:request\_processing\_time:float} %{NUMBER:backend\_processing\_time:float} %{NUMBER:response\_processing\_time:float} (?:%{INT:elb\_status\_code:int}|-) (?:%{INT:backend\_status\_code:int}|-) %{INT:elb\_received\_bytes:int} %{INT:elb\_sent\_bytes:int} "(?:%{GREEDYDATA:elb\_request}|-)" "(?:%{GREEDYDATA:userAgent}|-)" %{NOTSPACE:elb\_sslcipher} %{NOTSPACE:elb\_sslprotocol}"]  
match =\> ["message", "%{GREEDYDATA:event\_name} for ELB: %{NOTSPACE:elb\_name} at %{TIMESTAMP\_ISO8601:log\_timestamp}"]  
}

In that statement, I see two "match" lines. Does grok go through each "match" seeking the best fit, so I simply need to add another Match line, or do I need to create a match that can handle either format?

---

<div class="post-metadata">

**Author:** ![JKhondhu](https://avatars.discourse-cdn.com/v4/letter/j/ed655f/32.png) [@JKhondhu](https://discuss.elastic.co/u/JKhondhu)\
**Post date:** [November 30, 2017, 6:06pm UTC](https://discuss.elastic.co/t/grokking-multiple-line-formats/109814/2 "2017-11-30T18:06:31Z")

</div>

Hi,  
Here is a link on grok basics: [https://www.elastic.co/guide/en/logstash/current/plugins-filters-grok.html#\_grok\_basics](https://www.elastic.co/guide/en/logstash/current/plugins-filters-grok.html#_grok_basics)

[http://grokdebug.herokuapp.com](http://grokdebug.herokuapp.com) and [http://grokconstructor.appspot.com/](http://grokconstructor.appspot.com/) are useful for helping building patterns to match your logs.

This is what the match param is: [https://www.elastic.co/guide/en/logstash/current/plugins-filters-grok.html#plugins-filters-grok-match](https://www.elastic.co/guide/en/logstash/current/plugins-filters-grok.html#plugins-filters-grok-match)

Grok does go through each match. You will want to create, add a match that catches what you require from your logs.

---

<div class="post-metadata">

**Author:** ![StivOstenberg](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stivostenberg/32/4681_2.png) [@StivOstenberg](https://discuss.elastic.co/u/StivOstenberg)\
**Post date:** [November 30, 2017, 7:08pm UTC](https://discuss.elastic.co/t/grokking-multiple-line-formats/109814/3 "2017-11-30T19:08:45Z")

</div>

Thank you. Been all through the Grok Basics, and had built some grokkers through the GrokConstructor, just could not find any examples or explanations about how multiple Grok lines were handled. You answered that, and I am good to go.

---

<div class="post-metadata">

**Author:** ![JKhondhu](https://avatars.discourse-cdn.com/v4/letter/j/ed655f/32.png) [@JKhondhu](https://discuss.elastic.co/u/JKhondhu)\
**Post date:** [November 30, 2017, 8:25pm UTC](https://discuss.elastic.co/t/grokking-multiple-line-formats/109814/4 "2017-11-30T20:25:08Z")

</div>

Good to hear. Here is note of break on match which, the first successful match by grok will result in the filter being finished: [https://www.elastic.co/guide/en/logstash/current/plugins-filters-grok.html#plugins-filters-grok-break\_on\_match](https://www.elastic.co/guide/en/logstash/current/plugins-filters-grok.html#plugins-filters-grok-break_on_match)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 28, 2017, 8:25pm UTC](https://discuss.elastic.co/t/grokking-multiple-line-formats/109814/5 "2017-12-28T20:25:15Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
