# How to grok different format record lines in one single log file

**URL:** <https://discuss.elastic.co/t/how-to-grok-different-format-record-lines-in-one-single-log-file/236797>\
**Category:** Logstash\
**Created:** [June 11, 2020, 11:18pm UTC](https://discuss.elastic.co/t/how-to-grok-different-format-record-lines-in-one-single-log-file/236797 "2020-06-11T23:18:21Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![Eaven](https://avatars.discourse-cdn.com/v4/letter/e/9de0a6/32.png) [@Eaven](https://discuss.elastic.co/u/Eaven)\
**Post date:** [June 11, 2020, 11:18pm UTC](https://discuss.elastic.co/t/how-to-grok-different-format-record-lines-in-one-single-log-file/236797/1 "2020-06-11T23:18:21Z")

</div>

Dear Friend,

I'm encountering an issue when configuring logstash, here is an example from my case that I need to grok filter to match - some lines are with IP fields and sesseionID fields but some are not (so they are not exacly the same fields in one single log file). How can I modify the grok expression to cater for this?

"SMTPD" 1882 4499 "2020-06-11 18:18:18.188" "192.168.8.98" "SENT:220 MAILSER ESMTP"  
"SMTPC" 1572 4898 "2020-06-11 18:18:18.925" "192.168.8.97" "SENT: 250 Queued"  
"APPLICATION" 1767 "2020-06-11 18:18:18.925" "SMTPDeliverer - Message 3458327"  
"TCP" 1992 "2020-06-11 18:18:18.925" "TCP - 192.168.8.98 connect to 192.168.8.99"  
"TCPIP" 1992 "2020-06-11 18:18:18.925" "TCP - 192.168.8.98 connect to 192.168.8.99"

All lines start with quotation mark ", that's something annoying. You can see SMTP\* are 2 more fields than APPLICATION, TCP lines. I tried to use two message expression in the same grok:

["message", ''"SMTP\*""\s\*(%{BASE10NUM:process})\s\*(%{BASE10NUM:session})\s\*...],  
["message", ''"APP\*""\s\*(%{BASE10NUM:process})\s\*...]

But it didn't work this way. Any help or advice would be greatly appreciated!

---

<div class="post-metadata">

**Author:** ![wangqinghuan](https://avatars.discourse-cdn.com/v4/letter/w/d26b3c/32.png) [@wangqinghuan](https://discuss.elastic.co/u/wangqinghuan)\
**Post date:** [June 12, 2020, 1:51am UTC](https://discuss.elastic.co/t/how-to-grok-different-format-record-lines-in-one-single-log-file/236797/2 "2020-06-12T01:51:31Z")

</div>

Two grok matches should work:  
grok{  
match =\> ["message", ''"SMTP\*""\s\*(%{BASE10NUM:process})\s\*(%{BASE10NUM:session})\s\*...]  
match =\> ["message", ''"APP\*""\s\*(%{BASE10NUM:process})\s\*...]  
}

---

<div class="post-metadata">

**Author:** ![Eaven](https://avatars.discourse-cdn.com/v4/letter/e/9de0a6/32.png) [@Eaven](https://discuss.elastic.co/u/Eaven)\
**Post date:** [June 12, 2020, 2:45am UTC](https://discuss.elastic.co/t/how-to-grok-different-format-record-lines-in-one-single-log-file/236797/3 "2020-06-12T02:45:59Z")

</div>

Badly that it didn't work.

Firstly I think we need to use " instead of ", but it's still not working by doing so. I tried it with Grij Debugger by using "SMTP\*" but it didn't match any patterns as listed. Any ideas?

How we can let grok to match the first expression when it's starting with "SMPT  
then grok to match the second expression when the line of log starting with "APP\*

---

<div class="post-metadata">

**Author:** ![Eaven](https://avatars.discourse-cdn.com/v4/letter/e/9de0a6/32.png) [@Eaven](https://discuss.elastic.co/u/Eaven)\
**Post date:** [June 12, 2020, 3:26am UTC](https://discuss.elastic.co/t/how-to-grok-different-format-record-lines-in-one-single-log-file/236797/4 "2020-06-12T03:26:48Z")

</div>

Dear Wang, I found a way out (looks like that):

I have to match exactly SMTPD for the first match expression by using "SMTPD", then use "\APPLICATION" for the other expression. it works this way! but if I got too many types of works to start, I'm trying to figure out how to use the first one to start with "SMTP and the other express will match those lines not starting with "SMTP

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [June 12, 2020, 3:02pm UTC](https://discuss.elastic.co/t/how-to-grok-different-format-record-lines-in-one-single-log-file/236797/5 "2020-06-12T15:02:29Z")

</div>

You can make fields optional by surrounding them with ( )? So this will parse those messages

```
grok { match => { "message" => '"%{WORD:app}" %{INT:number1}( %{INT:number2})? %{QS:string1} %{QS:string2}( %{QS:string3})?' } }
```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 10, 2020, 3:02pm UTC](https://discuss.elastic.co/t/how-to-grok-different-format-record-lines-in-one-single-log-file/236797/6 "2020-07-10T15:02:55Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
