# Help me writing grook filter pattern for my log to injest into elasticsearch

**URL:** <https://discuss.elastic.co/t/help-me-writing-grook-filter-pattern-for-my-log-to-injest-into-elasticsearch/266423>\
**Category:** Logstash\
**Created:** [March 6, 2021, 4:17am UTC](https://discuss.elastic.co/t/help-me-writing-grook-filter-pattern-for-my-log-to-injest-into-elasticsearch/266423 "2021-03-06T04:17:07Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![abhishek\_s1](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/abhishek_s1/32/85080_2.png) [@abhishek\_s1](https://discuss.elastic.co/u/abhishek_s1)\
**Post date:** [March 6, 2021, 4:17am UTC](https://discuss.elastic.co/t/help-me-writing-grook-filter-pattern-for-my-log-to-injest-into-elasticsearch/266423/1 "2021-03-06T04:17:07Z")

</div>

These are few sample log lines

74128 2021-01-25T23:28:42.753582Z - xyz svn/repos get-latest-rev

74128 2021-01-25T23:28:43.030543Z - xyz svn/repos reparent /sm/branches/6.0r

74128 2021-01-25T23:28:43.307469Z - xyz svn/repos stat /sm/branches/6.0r@267554

74128 2021-01-25T23:28:43.591372Z - xyz svn/repos get-dir /sm/branches/6.0r r267554 text

74132 2021-01-25T23:28:57.008969Z - xyz svn/repos open 2 cap=(edit-pipeline svndiff1 absent-entries depth mergeinfo log-revprops) /sm/branches/6.0r SVN/1.9.5%20(amd64-portbld-freebsd8.4) -

---

<div class="post-metadata">

**Author:** ![nugusbayevkk](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nugusbayevkk/32/126683_2.png) [@nugusbayevkk](https://discuss.elastic.co/u/nugusbayevkk)\
**Post date:** [March 6, 2021, 3:31pm UTC](https://discuss.elastic.co/t/help-me-writing-grook-filter-pattern-for-my-log-to-injest-into-elasticsearch/266423/2 "2021-03-06T15:31:28Z")

</div>

Hi @abhishek_s1  
You can use this documentation to try do it:

> **[Grok filter plugin | Logstash Reference \[7.11\] | Elastic](https://www.elastic.co/guide/en/logstash/current/plugins-filters-grok.html)**

[https://streamsets.com/documentation/datacollector/latest/help/datacollector/UserGuide/Apx-GrokPatterns/GrokPatterns\_title.html](https://streamsets.com/documentation/datacollector/latest/help/datacollector/UserGuide/Apx-GrokPatterns/GrokPatterns_title.html)

> **[Debugging grok expressions | Kibana Guide \[7.9\] | Elastic](https://www.elastic.co/guide/en/kibana/7.9/xpack-grokdebugger.html)**

Try to do it yourself, if you fail, write the pattern that you got and what result you expect.

---

<div class="post-metadata">

**Author:** ![abhishek\_s1](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/abhishek_s1/32/85080_2.png) [@abhishek\_s1](https://discuss.elastic.co/u/abhishek_s1)\
**Post date:** [March 7, 2021, 3:00pm UTC](https://discuss.elastic.co/t/help-me-writing-grook-filter-pattern-for-my-log-to-injest-into-elasticsearch/266423/3 "2021-03-07T15:00:53Z")

</div>

Hi @nugusbayevkk .

Thanks for replying & providing appropriate documentation. I got the pattern & it works !!

---

<div class="post-metadata">

**Author:** ![nugusbayevkk](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nugusbayevkk/32/126683_2.png) [@nugusbayevkk](https://discuss.elastic.co/u/nugusbayevkk)\
**Post date:** [March 7, 2021, 3:07pm UTC](https://discuss.elastic.co/t/help-me-writing-grook-filter-pattern-for-my-log-to-injest-into-elasticsearch/266423/4 "2021-03-07T15:07:38Z")

</div>

Glad to hear that 👍

---

<div class="post-metadata">

**Author:** ![humbaw](https://avatars.discourse-cdn.com/v4/letter/h/b5e925/32.png) [@humbaw](https://discuss.elastic.co/u/humbaw)\
**Post date:** [March 7, 2021, 5:36pm UTC](https://discuss.elastic.co/t/help-me-writing-grook-filter-pattern-for-my-log-to-injest-into-elasticsearch/266423/5 "2021-03-07T17:36:27Z")

</div>

HI i've been having issues ingesting a pcap file into elastixsearch 7.11. I've first converted my pcap file to json by using the " tshark -r packet.pcap -T ek \> packets.json" command. i then create a index template . but when i try to injest the packets into elasticsearch using `curl -s -H "Content-Type: application/x-ndjson" -XPOST "localhost:9200/_bulk" --data-binary "@packets.json"`

i get the following error: `"status":400,"error":{"type":"mapper_parsing_exception","reason":"failed to parse field [layers.frame.frame_frame_offset_shift] of type [date] in document with id " `

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 4, 2021, 5:37pm UTC](https://discuss.elastic.co/t/help-me-writing-grook-filter-pattern-for-my-log-to-injest-into-elasticsearch/266423/6 "2021-04-04T17:37:11Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
