# How to grok a certain fields from a log file

**URL:** <https://discuss.elastic.co/t/how-to-grok-a-certain-fields-from-a-log-file/315996>\
**Category:** Logstash\
**Created:** [October 6, 2022, 5:26pm UTC](https://discuss.elastic.co/t/how-to-grok-a-certain-fields-from-a-log-file/315996 "2022-10-06T17:26:30Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![anupvtr](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/anupvtr/32/128607_2.png) [@anupvtr](https://discuss.elastic.co/u/anupvtr)\
**Post date:** [October 6, 2022, 5:26pm UTC](https://discuss.elastic.co/t/how-to-grok-a-certain-fields-from-a-log-file/315996/1 "2022-10-06T17:26:30Z")

</div>

`Preformatted text`Hi All,

I am quite new to the magic world of Grok. Any help will be thankful.

I need to apply filter for the following file.

2022-08-22 22:18:59 , 666 INFO @ (blockurcolumn-11) [rbbit\_MQ\_Versa.appache 75] start collection of :  
messageid: 8765568  
  
\<sol:create Id="8765568"\>  
com:createlibidFR%67com:createlibid  
com:doinglibidFRANCEcom:doinglibid  
com:complelibidTRUEcom:complelibid  
\</sol:create Id\>

==================================================  
The grok pattern i am trying to use  
(?m)(?\<Rabbit\_datetimeTMP\>.{23}) %{LOGLEVEL:Level}._messageid:\s_%{BASE10NUM:Id}  
\<%{GREEDYDATA:Data}\>

Requirement:  
I need to grok the datetime logelevel message id and the first line of xml() . starts with\< and ends with \>.  
unfortunately its taking the entire xml format.

---

<div class="post-metadata">

**Author:** ![Rios](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rios/32/95745_2.png) [@Rios](https://discuss.elastic.co/u/Rios)\
**Post date:** [October 31, 2022, 6:43am UTC](https://discuss.elastic.co/t/how-to-grok-a-certain-fields-from-a-log-file/315996/5 "2022-10-31T06:43:42Z")

</div>

This is working in grok debugger:  
`(?m)(?<Rabbit_datetimeTMP>.{23})\s*%{LOGLEVEL:Level}\s*%{DATA}messageid:\s*%{POSINT:messageid}%{DATA}<%{DATA:msg}>%{GREEDYDATA}`

```auto
{
  "Rabbit_datetimeTMP": [
    [
      "22-08-22 22:18:59 , 666"
    ]
  ],
  "Level": [
    [
      "INFO"
    ]
  ],
  "DATA": [
    [
      "@ (blockurcolumn-11) [rbbit_MQ_Versa.appache 75] start collection of :\n",
      "\n\n"
    ]
  ],
  "messageid": [
    [
      "8765568"
    ]
  ],
  "msg": [
    [
      "sol:create Id="8765568""
    ]
  ],
  "GREEDYDATA": [
    [
      "\ncom:createlibidFR%67com:createlibid\ncom:doinglibidFRANCEcom:doinglibid\ncom:complelibidTRUEcom:complelibid\n</sol:create Id>"
    ]
  ]
}

```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 28, 2022, 6:43am UTC](https://discuss.elastic.co/t/how-to-grok-a-certain-fields-from-a-log-file/315996/6 "2022-11-28T06:43:56Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
