# Help with Grok (syntax issue as well as question regarding double quotes)

**URL:** <https://discuss.elastic.co/t/help-with-grok-syntax-issue-as-well-as-question-regarding-double-quotes/333891>\
**Category:** Logstash\
**Created:** [May 19, 2023, 11:30pm UTC](https://discuss.elastic.co/t/help-with-grok-syntax-issue-as-well-as-question-regarding-double-quotes/333891 "2023-05-19T23:30:47Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![roman-tasi](https://avatars.discourse-cdn.com/v4/letter/r/7ea924/32.png) [@roman-tasi](https://discuss.elastic.co/u/roman-tasi)\
**Post date:** [May 19, 2023, 11:30pm UTC](https://discuss.elastic.co/t/help-with-grok-syntax-issue-as-well-as-question-regarding-double-quotes/333891/1 "2023-05-19T23:30:47Z")

</div>

This is a sample log that I want to parse:  
`type=EXECVE msg=audit(1684525987.999:148345): argc=2 a0="vim" a1="logstash-syslog.conf"`

This is the grok filter I am trying:  
`type=%{WORD:type} msg=audit\(%{NUMBER:audit}\): argc=%{NUMBER:argc} a0="%{WORD:a0}" a1="%{DATA:a1}"`

It doesn't seem to be working in online debuggers. Also assuming you can get it to work, can you also show the correct syntax in applying it in the Logstash config?

---

<div class="post-metadata">

**Author:** ![Anton\_H](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/anton_h/32/10200_2.png) [@Anton\_H](https://discuss.elastic.co/u/Anton_H)\
**Post date:** [May 20, 2023, 10:28am UTC](https://discuss.elastic.co/t/help-with-grok-syntax-issue-as-well-as-question-regarding-double-quotes/333891/2 "2023-05-20T10:28:29Z")

</div>

Hi @roman-tasi,

Your grok pattern doesn´t match.  
I am not sure if you wanted the number part after the colon in the audit field.  
This pattern excludes that number:

```auto
type\=%{WORD:type} msg\=audit\(%{NUMBER:audit}\:%{NUMBER}\)\: argc\=%{NUMBER:argc} a0\=\"%{WORD:a0}\" a1\=\"%{DATA:a1}\"

```

This results in:

```auto
[
  {
    "type": "EXECVE",
    "audit": 1684525987.999,
    "argc": 2,
    "a0": "vim",
    "a1": "logstash-syslog.conf"
  }
]

```

And this one includes it but it is no longer a number.:

```auto
type\=%{WORD:type} msg\=audit\((?<audit>[\d\.\:]*)\)\: argc\=%{NUMBER:argc} a0\=\"%{WORD:a0}\" a1\=\"%{DATA:a1}\"

```

It wil results in:

```auto
[
  {
    "type": "EXECVE",
    "audit": "1684525987.999:148345",
    "argc": 2,
    "a0": "vim",
    "a1": "logstash-syslog.conf"
  }
]

```

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [May 20, 2023, 2:40pm UTC](https://discuss.elastic.co/t/help-with-grok-syntax-issue-as-well-as-question-regarding-double-quotes/333891/3 "2023-05-20T14:40:02Z")

</div>

Also, see [this](https://discuss.elastic.co/t/ruby-script-for-auditd-execve-logs/326098/2) thread for another approach to such messages.

---

<div class="post-metadata">

**Author:** ![roman-tasi](https://avatars.discourse-cdn.com/v4/letter/r/7ea924/32.png) [@roman-tasi](https://discuss.elastic.co/u/roman-tasi)\
**Post date:** [May 23, 2023, 10:58pm UTC](https://discuss.elastic.co/t/help-with-grok-syntax-issue-as-well-as-question-regarding-double-quotes/333891/4 "2023-05-23T22:58:59Z")

</div>

Hi, I am trying this in my Logstash config:

```auto
if [log][file][path]=="/var/log/audit/audit.log" {
            kv {
                field_split => " "
                value_split => "="
                source => "message"
                trim_key => "\""
                trim_value => "\""
                remove_field => ["message"]
            }
    }

```

However it causes all logs from `/var/log/audit/audit.log` to not come into Kibana. Once I comment that code out, the logs start coming in again. What do you think its causing it to act like this? And is there a fix?

---

<div class="post-metadata">

**Author:** ![roman-tasi](https://avatars.discourse-cdn.com/v4/letter/r/7ea924/32.png) [@roman-tasi](https://discuss.elastic.co/u/roman-tasi)\
**Post date:** [June 2, 2023, 2:22am UTC](https://discuss.elastic.co/t/help-with-grok-syntax-issue-as-well-as-question-regarding-double-quotes/333891/5 "2023-06-02T02:22:24Z")

</div>

Also @Badger -\>[this](https://discuss.elastic.co/t/logstash-kv-plugin-is-not-working/300548)\<- seems to be the exact issue I am having, which you also commented on but was not resolved. I'm just curious on the solution!

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [June 2, 2023, 2:44am UTC](https://discuss.elastic.co/t/help-with-grok-syntax-issue-as-well-as-question-regarding-double-quotes/333891/6 "2023-06-02T02:44:26Z")

</div>

Remove the current output and replace it with

output { stdout { codec =\> rubydebug } }

and see what the messages look like.

---

<div class="post-metadata">

**Author:** ![roman-tasi](https://avatars.discourse-cdn.com/v4/letter/r/7ea924/32.png) [@roman-tasi](https://discuss.elastic.co/u/roman-tasi)\
**Post date:** [June 2, 2023, 5:18am UTC](https://discuss.elastic.co/t/help-with-grok-syntax-issue-as-well-as-question-regarding-double-quotes/333891/7 "2023-06-02T05:18:13Z")

</div>

@Badger I think I already have been implementing that. Here's my current output in my Logstash config:

```auto
output {
        if [type]=="syslog" {
                if [m] in ["1080", "745", "263", "1079"] {
                elasticsearch {
                hosts => ["localhost:9200"]
                index => "account-access-%{+yyyy.MM}"
                }
                } else {
                elasticsearch {
                hosts => ["localhost:9200"]
                index => "syslog-%{+yyyy.MM.dd}"
                }
                }
        stdout { codec => rubydebug }
        }

        if [type]=="beats" {
                if [host][os][type]=="linux" {
                    if [host][name]=="mail.uhtasi.org" {
                        if [cmd]=="Auth"{
                            elasticsearch {
                            hosts => ["localhost:9200"]
                            index => "account-access-%{+yyyy.MM}"
                            }
                            } else {
                            elasticsearch {
                            hosts => ["localhost:9200"]
                            index => "zimbra-%{+yyyy.MM.dd}"
                            }
                        }
                    } else {
                        elasticsearch {
                        hosts => ["localhost:9200"]
                        index => "linux-%{+yyyy.MM.dd}"
                        }
                    }
                }
                if [host][os][type]=="windows" or [agent][name]=="DCON2" or [agent][name]=="Dcon3" {
                    if [event][code] in ["307", "4624", "4625", "4634", "4723", "4740", "4767", "11707"] {
                        elasticsearch {
                        hosts => ["localhost:9200"]
                        index => "account-access-%{+yyyy.MM}"
                        }
                    } else {
                        elasticsearch {
                        hosts => ["localhost:9200"]
                        index => "winlogbeat-%{+yyyy.MM.dd}"
                        }
                    }
                }
        stdout { codec => rubydebug }
        }
}

```

---

<div class="post-metadata">

**Author:** ![roman-tasi](https://avatars.discourse-cdn.com/v4/letter/r/7ea924/32.png) [@roman-tasi](https://discuss.elastic.co/u/roman-tasi)\
**Post date:** [June 2, 2023, 7:19am UTC](https://discuss.elastic.co/t/help-with-grok-syntax-issue-as-well-as-question-regarding-double-quotes/333891/8 "2023-06-02T07:19:40Z")

</div>

Also here is some lines from the `/var/log/messages` file related to `/var/log/audit/audit.log` :

```auto
Jun 1 20:40:03 ELK-Stack filebeat: "path": "/var/log/audit/audit.log"
Jun 1 20:40:03 ELK-Stack filebeat: "path": "/var/log/audit/audit.log"
Jun 1 20:40:07 ELK-Stack filebeat: 2023-06-01T20:40:07.799-1000#011DEBUG#011[input.filestream]#011filestream/prospector.go:188#011File /var/log/audit/audit.log has been updated#011{"id": "my-filestream-id", "prospector": "file_prospector", "operation": "write", "source_name": "native::201877637-64768", "os_id": "201877637-64768", "new_path": "/var/log/audit/audit.log", "old_path": "/var/log/audit/audit.log"}
Jun 1 20:40:09 ELK-Stack filebeat: "message": "Jun 1 20:40:03 ELK-Stack filebeat: \"path\": \"/var/log/audit/audit.log\"",
Jun 1 20:41:07 ELK-Stack filebeat: 2023-06-01T20:41:07.092-1000#011DEBUG#011[input.filestream]#011filestream/filestream.go:131#011End of file reached: /var/log/audit/audit.log; Backoff now.#011{"id": "my-filestream-id", "source": "filestream::my-filestream-id::native::201877637-64768", "path": "/var/log/audit/audit.log", "state-id": "native::201877637-64768"}
Jun 1 20:41:37 ELK-Stack filebeat: 2023-06-01T20:41:37.103-1000#011DEBUG#011[input.filestream]#011filestream/filestream.go:131#011End of file reached: /var/log/audit/audit.log; Backoff now.#011{"id": "my-filestream-id", "source": "filestream::my-filestream-id::native::201877637-64768", "path": "/var/log/audit/audit.log", "state-id": "native::201877637-64768"}

```

Also notice its related to `filebeat` not `logstash`

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 30, 2023, 7:19am UTC](https://discuss.elastic.co/t/help-with-grok-syntax-issue-as-well-as-question-regarding-double-quotes/333891/9 "2023-06-30T07:19:52Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
