# Help me writing grok filter for the pattern

**URL:** <https://discuss.elastic.co/t/help-me-writing-grok-filter-for-the-pattern/268794>\
**Category:** Logstash\
**Created:** [March 30, 2021, 12:56pm UTC](https://discuss.elastic.co/t/help-me-writing-grok-filter-for-the-pattern/268794 "2021-03-30T12:56:26Z")\
**Posts on this page:** 10\
**Page:** 1

<div class="post-metadata">

**Author:** ![abhishek\_s1](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/abhishek_s1/32/85080_2.png) [@abhishek\_s1](https://discuss.elastic.co/u/abhishek_s1)\
**Post date:** [March 30, 2021, 12:56pm UTC](https://discuss.elastic.co/t/help-me-writing-grok-filter-for-the-pattern/268794/1 "2021-03-30T12:56:26Z")

</div>

I've http log of the form

```auto
10.255.255.255 - jira [11/Mar/2021:10:00:03 -0800] "GET /svn/repos/branches/feature-IPv6-TWLP-3.2/ZProxyHealthManager.cpp HTTP/1.1" 200 29110 

```

& my pattern is:

```auto
%{IPORHOST:client_ip} %{HTTPDUSER:ident} %{USER:username} \[%{HTTPDATE:timestamp}\] \"(?:%{WORD:http_method} %{NOTSPACE:svn_path}(?: HTTP/%{NUMBER:http_version})?|%{DATA:svn_path})\" %{NUMBER:http_response} (?:%{NUMBER:content_length}|-)

```

I need one more field which should be named as svn\_branch which comes from svn\_path after, /branches (eg here svn\_branch is, /feature-IPv6-TWLP-3.2) please help me creating this new field called svn\_branch.

---

<div class="post-metadata">

**Author:** ![Mohammed\_Anas](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mohammed_anas/32/77073_2.png) [@Mohammed\_Anas](https://discuss.elastic.co/u/Mohammed_Anas)\
**Post date:** [March 30, 2021, 1:45pm UTC](https://discuss.elastic.co/t/help-me-writing-grok-filter-for-the-pattern/268794/2 "2021-03-30T13:45:59Z")

</div>

grok {  
match =\> {"svn\_path" =\> "(.\*)/branches%{GREEDYDATA:svn\_brnch}"}  
}

filter {  
mutate {  
add\_field =\> { "svn\_branch" =\> "%{svn\_brnch}" }  
}

---

<div class="post-metadata">

**Author:** ![abhishek\_s1](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/abhishek_s1/32/85080_2.png) [@abhishek\_s1](https://discuss.elastic.co/u/abhishek_s1)\
**Post date:** [March 31, 2021, 7:07am UTC](https://discuss.elastic.co/t/help-me-writing-grok-filter-for-the-pattern/268794/4 "2021-03-31T07:07:44Z")

</div>

HI @Mohammed_Anas. Thanks for replying!!

I didn't get the expected out as add\_field is not working ig.  
Here is my logstash pipeline

```auto
input {

    file {

        path => "C:/Users/Abhishek S/Desktop/logfiles/prod logs/httpd-access-new.log"
        start_position => "beginning"
        type => "apache-access"
        sincedb_path => "NUL"
    }
}

filter {

    if [type] == "apache-access" {

        grok {
            match => { "message" => [
                                        "%{IPORHOST:client_ip} %{HTTPDUSER:ident} %{USER:username} \[%{HTTPDATE:timestamp}\] \"(?:%{WORD:http_method} %{NOTSPACE:svn_path}(?: HTTP/%{NUMBER:http_version})?|%{DATA:svn_paths})\" %{NUMBER:http_response} (?:%{NUMBER:con_len}|-) \"-\" \"%{GREEDYDATA:user_agent}\"" ,
                                        "%{IPORHOST:client_ip} %{HTTPDUSER:ident} %{USER:username} \[%{HTTPDATE:timestamp}\] \"(?:%{WORD:http_method} %{NOTSPACE:svn_path}(?: HTTP/%{NUMBER:http_version})?|%{DATA:svn_paths})\" %{NUMBER:http_response} (?:%{NUMBER:con_len}|-)" 
                                    ]

                        
                    }

            match => { "svn_path" => "(.*)/branches/%{GREEDYDATA:svn_brnch}"
                     }
        }

        date {
            match => ["timestamp", "dd/MMM/yyyy:HH:mm:ss Z"]
        }

        mutate { 
            add_field => { "svn_branch" => "%{svn_brnch}" }
            remove_field => ["http_version", "host", "path", "ident"] 
            
            }
    }

}

output {

    elasticsearch {

        hosts => "http://localhost:9200"
        index => "svn.corp"
        
    }
    stdout { }
}   

```

And the output is:

```auto
{
         "@version" => "1",
         "username" => "jirasvn",
          "message" => "10.34.115.33 - jirasvn [11/Mar/2021:10:00:29 -0800] \"GET /svn/repos/!svn/rvr/271559/mobile/client/branches/release-3.4/apps/mac/system/ZSecureAgent/ZSecureAgent.xcodeproj/project.pbxproj HTTP/1.1\" 200 335628 \"-\" \"SVN/1.9.7 (x86_64-pc-linux-gnu) serf/1.3.9\"\r",
      "http_method" => "GET",
       "svn_branch" => "%{svn_brnch}",
        "client_ip" => "10.34.115.33",
    "http_response" => "200",
       "@timestamp" => 2021-03-11T18:00:29.000Z,
       "user_agent" => "SVN/1.9.7 (x86_64-pc-linux-gnu) serf/1.3.9",
          "con_len" => "335628",
        "timestamp" => "11/Mar/2021:10:00:29 -0800",
         "svn_path" => "/svn/repos/!svn/rvr/271559/mobile/client/branches/release-3.4/apps/mac/project.pbxproj",
             "type" => "apache-access"
}

```

Please help me out where I'm going wrong.

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [March 31, 2021, 2:22pm UTC](https://discuss.elastic.co/t/help-me-writing-grok-filter-for-the-pattern/268794/5 "2021-03-31T14:22:09Z")

</div>

If you have multiple match options in a single grok filter they may not be evaluated in the order you expect. If the svn\_path match is evaluated before that field is created then you will get the result you see. Split it into two grok filters.

---

<div class="post-metadata">

**Author:** ![abhishek\_s1](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/abhishek_s1/32/85080_2.png) [@abhishek\_s1](https://discuss.elastic.co/u/abhishek_s1)\
**Post date:** [April 1, 2021, 6:56am UTC](https://discuss.elastic.co/t/help-me-writing-grok-filter-for-the-pattern/268794/6 "2021-04-01T06:56:09Z")

</div>

Hi @Badger & @Mohammed_Anas ,

I got this done & its working!!  
But, you can see there's huge time gap between @timestamp & timestamp which is annoying me, can you please help me out to maintain 0 time gap between them?  
btw mytimezone is :

```auto
timezone => "Asia/Kolkata"
```

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [April 1, 2021, 2:56pm UTC](https://discuss.elastic.co/t/help-me-writing-grok-filter-for-the-pattern/268794/7 "2021-04-01T14:56:56Z")

</div>

> [@abhishek\_s1](#):
>
> you can see there's huge time gap between @timestamp & timestamp

No, there is not. @timestamp is 18:00:29 in UTC, and timestamp is 10:00:29 in the timezone that is 8 hours behind UTC (that is what the -8000 means).

---

<div class="post-metadata">

**Author:** ![abhishek\_s1](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/abhishek_s1/32/85080_2.png) [@abhishek\_s1](https://discuss.elastic.co/u/abhishek_s1)\
**Post date:** [April 2, 2021, 10:25am UTC](https://discuss.elastic.co/t/help-me-writing-grok-filter-for-the-pattern/268794/8 "2021-04-02T10:25:26Z")

</div>

Thanks alot @Badger for on point explaination!!

---

<div class="post-metadata">

**Author:** ![abhishek\_s1](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/abhishek_s1/32/85080_2.png) [@abhishek\_s1](https://discuss.elastic.co/u/abhishek_s1)\
**Post date:** [April 2, 2021, 10:45am UTC](https://discuss.elastic.co/t/help-me-writing-grok-filter-for-the-pattern/268794/9 "2021-04-02T10:45:01Z")

</div>

But, what necessary changes I need to make so that both times will be in my timezone (viz., 8 hrs behind UTC)

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [April 2, 2021, 3:39pm UTC](https://discuss.elastic.co/t/help-me-writing-grok-filter-for-the-pattern/268794/10 "2021-04-02T15:39:21Z")

</div>

@timestamp will always be in UTC, because elasticsearch always stores times as UTC. Kibana then shifts them to the browser's timezone.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 30, 2021, 3:39pm UTC](https://discuss.elastic.co/t/help-me-writing-grok-filter-for-the-pattern/268794/11 "2021-04-30T15:39:29Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
