# How can i use grok to match a single character of word

**URL:** <https://discuss.elastic.co/t/how-can-i-use-grok-to-match-a-single-character-of-word/130929>\
**Category:** Logstash\
**Created:** [May 8, 2018, 4:20am UTC](https://discuss.elastic.co/t/how-can-i-use-grok-to-match-a-single-character-of-word/130929 "2018-05-08T04:20:10Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![regex99](https://avatars.discourse-cdn.com/v4/letter/r/3da27b/32.png) [@regex99](https://discuss.elastic.co/u/regex99)\
**Post date:** [May 8, 2018, 4:20am UTC](https://discuss.elastic.co/t/how-can-i-use-grok-to-match-a-single-character-of-word/130929/1 "2018-05-08T04:20:10Z")

</div>

hi,  
I have a string like `SAMPLE DATA 08X71 +F(9)L`.

i can match each word with `%{WORD}` like this,

`%{WORD:1}\s*%{WORD:2}\s*%{WORD}`

but how can I match each character separately from the last word in the same grok pattern? I want to create separate field for `+`, `F` and `L`

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [May 8, 2018, 11:38am UTC](https://discuss.elastic.co/t/how-can-i-use-grok-to-match-a-single-character-of-word/130929/2 "2018-05-08T11:38:59Z")

</div>

> [@regex99](#):
>
> how can I match each character separately from the last word in the same grok pattern? I want to create separate field for +, F and L

```auto
grok { match => { "message" => "%{WORD:1}\s*%{WORD:2}\s*%{WORD}\s(?<g1>.)(?<g2>.)\(%{WORD}\)(?<g3>.)" } }

```

---

<div class="post-metadata">

**Author:** ![regex99](https://avatars.discourse-cdn.com/v4/letter/r/3da27b/32.png) [@regex99](https://discuss.elastic.co/u/regex99)\
**Post date:** [May 8, 2018, 10:13pm UTC](https://discuss.elastic.co/t/how-can-i-use-grok-to-match-a-single-character-of-word/130929/3 "2018-05-08T22:13:14Z")

</div>

> [@regex99](#):
>
> SAMPLE DATA 08X71 +F(9)L

Thank you for this. Would you be able to explain `\s(?<g1>.)` this part please? i couldn't find `\s` on grok default patterns, i can see SPACE and NOTSPACE though.

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [May 9, 2018, 12:23am UTC](https://discuss.elastic.co/t/how-can-i-use-grok-to-match-a-single-character-of-word/130929/4 "2018-05-09T00:23:35Z")

</div>

> [@Badger](#):
>
> (?\<g1\>.)

Take a look at the section of the grok filter [documentation](https://www.elastic.co/guide/en/logstash/current/plugins-filters-grok.html) called "Custom Patterns". That defines a capture group that creates a field on the event called g1, which consists of a single character from the message (which is what . matches). The \s means whitespace, which you were already using.

You might want to try running logstash on the command line with this configuration

```auto
input { generator { message => 'SAMPLE DATA 08X71 +F(9)L' count => 1 } }
output { stdout { codec => rubydebug } }
filter {
  grok { match => { "message" => "%{WORD:1}\s*%{WORD:2}\s*%{WORD}\s(?<g1>.)(?<g2>.)\(%{WORD}\)(?<g3>.)" } }
}

```

and you should see the following plus the standard fields.

```auto
            "g3" => "L",
       "message" => "SAMPLE DATA 08X71 +F(9)L",
            "g2" => "F",
             "1" => "SAMPLE",
             "2" => "DATA",
            "g1" => "+"

```

I find this really useful for verifying patterns, although having to restart logstash for every tweak is painfully expensive.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 6, 2018, 12:32am UTC](https://discuss.elastic.co/t/how-can-i-use-grok-to-match-a-single-character-of-word/130929/5 "2018-06-06T00:32:22Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
