# Help with GROK Pattern

**URL:** <https://discuss.elastic.co/t/help-with-grok-pattern/303547>\
**Category:** Logstash\
**Created:** [April 28, 2022, 6:48pm UTC](https://discuss.elastic.co/t/help-with-grok-pattern/303547 "2022-04-28T18:48:12Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![trubeat\_elk](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/trubeat_elk/32/104428_2.png) [@trubeat\_elk](https://discuss.elastic.co/u/trubeat_elk)\
**Post date:** [April 28, 2022, 6:48pm UTC](https://discuss.elastic.co/t/help-with-grok-pattern/303547/1 "2022-04-28T18:48:12Z")

</div>

Hello

I am very new to ELK and I am stuck at extracting fields.Below is the sample data

Dec 9 06:36:01 s-login-01 CRON[2436102]: pam\_unix(cron:session): session closed for user mXXt

Dec 9 06:34:07 s-login-01 sshd[2424671]: Disconnected from user sw 10.xx.1x.xx port 4000

Dec 9 06:34:05 s-login-01 systemd-logind[2405]: Session 20923 logged out. Waiting for processes to exit.

I have the above sample data I want to know how to write the .conf file for this .I tried using the below .conf but It did not extract the fields.

input {  
file {  
path =\> "/../syslog.log"  
type =\> "syslog"  
start\_position =\> beginning  
sincedb\_path =\> "/dev/null"  
}  
}  
filter {  
grok {

```
    match => { "message" => "%{SYSLOGTIMESTAMP:timestamp}%{SPACE}%{NOTSPACE:HOST}%{SPACE}%{NOTSPACE:PROCESS}\[%{NUMBER:PID}\]\:%{GREEDYDATA:activity}" }
    match => { "message" => "%{SYSLOGTIMESTAMP:timestamp}%{SPACE}%{NOTSPACE:HOST}%{SPACE}%{NOTSPACE:PROCESS}\[%{NUMBER:PID}\]\:%{GREEDYDATA:activity}.?*%{WORD:User}" }
    match => { "message" => "%{SYSLOGTIMESTAMP:timestamp}%{SPACE}%{NOTSPACE:HOST}%{SPACE}%{NOTSPACE:PROCESS}\[%{NUMBER:PID}\]\:%{GREEDYDATA:activity}.?*%{WORD:User}.?*%{IP:IP}.?*%{NUMBER:Port}" }
    match => { "message" => "%{SYSLOGTIMESTAMP:timestamp}%{SPACE}%{NOTSPACE:HOST}%{SPACE}%{NOTSPACE:PROCESS}\[%{NUMBER:PID}\]\:%{GREEDYDATA:activity}.?*%{NUMBER:Session_ID}" }

```

}  
}  
output {  
Elasticsearch {  
hosts =\> ["localhost:9200"]  
index =\> "sample\_"  
}  
}

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 26, 2022, 6:48pm UTC](https://discuss.elastic.co/t/help-with-grok-pattern/303547/2 "2022-05-26T18:48:27Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
