# How to Grok hexidecimals to Human Readable Values

**URL:** <https://discuss.elastic.co/t/how-to-grok-hexidecimals-to-human-readable-values/313380>\
**Category:** Elasticsearch\
**Created:** [August 31, 2022, 5:14pm UTC](https://discuss.elastic.co/t/how-to-grok-hexidecimals-to-human-readable-values/313380 "2022-08-31T17:14:44Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![DominicS](https://avatars.discourse-cdn.com/v4/letter/d/eada6e/32.png) [@DominicS](https://discuss.elastic.co/u/DominicS)\
**Post date:** [August 31, 2022, 5:14pm UTC](https://discuss.elastic.co/t/how-to-grok-hexidecimals-to-human-readable-values/313380/1 "2022-08-31T17:14:44Z")

</div>

Hello,  
I am a Grok newbie , this is my first post i need to know how to grok hex values into a grok pattern for the purpose of creating a logstash pipeline.I have googled for a while but found nothing helpful

this is a typical sample of the data i need to grok

4167b8f8 RADAR\_PASW42\_LSSW\_J0570001|23fe|b72afd25|10f

Any help would be greatly appreciated

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [August 31, 2022, 5:27pm UTC](https://discuss.elastic.co/t/how-to-grok-hexidecimals-to-human-readable-values/313380/2 "2022-08-31T17:27:43Z")

</div>

Can you give more context about what you want to do?

What is your expected output?

What fields do you want to extract from this message:

```auto
4167b8f8 RADAR_PASW42_LSSW_J0570001|23fe|b72afd25|10f

```

Also, if your data always look like the one you shared, you do not even need grok to parse it, there are other filters like dissect, csv and kv, that can be combined to parse a message more easily than grok.

---

<div class="post-metadata">

**Author:** ![DominicS](https://avatars.discourse-cdn.com/v4/letter/d/eada6e/32.png) [@DominicS](https://discuss.elastic.co/u/DominicS)\
**Post date:** [August 31, 2022, 9:32pm UTC](https://discuss.elastic.co/t/how-to-grok-hexidecimals-to-human-readable-values/313380/3 "2022-08-31T21:32:37Z")

</div>

4167b8f8 RADAR\_PASW42\_LSSW\_J0570001|23fe|b72afd25|10f  
| | | | |  
| | | | +-\> Unique number in hex  
| | | +--------\> Directory Identifier  
| | +---------------\> File Size in hex  
| +-------------------------------\> File Name  
+---------------------------------------------------\> Unix Time in hex

Hope this explains it better

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [August 31, 2022, 11:23pm UTC](https://discuss.elastic.co/t/how-to-grok-hexidecimals-to-human-readable-values/313380/4 "2022-08-31T23:23:25Z")

</div>

You want something like this?

```auto
Unix Time in hex = 4167b8f8
File name = RADAR_PASW42_LSSW_J0570001
File Size in hex = 23fe
Directory Identifier = b72afd25 
Unique number in hex = 10f

```

If so, you can easily use the [dissect filter](https://www.elastic.co/guide/en/logstash/current/plugins-filters-dissect.html) plugin to parse this message.

Something like this:

```auto
filter {
    dissect {
        mapping => {
            "message" => "%{time_in_hex} %{file_name}|%{size_in_hex}|%{directory_id}|%{unique_number}"
        }
    }
}

```

You can also use grok, but everything will need to use the `DATA` pattern.

```auto
filter {
    grok {
        match => {
            "message" => "%{DATA:time_in_hex}%{SPACE}%{DATA:file_name}|%{DATA:size_in_hex}|%{DATA:directory_id}|%{DATA:unique_number}"
        }
    }
}

```

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [September 1, 2022, 12:36am UTC](https://discuss.elastic.co/t/how-to-grok-hexidecimals-to-human-readable-values/313380/5 "2022-09-01T00:36:26Z")

</div>

There's nothing native to convert hex to decimal. You might be able to do it via [Script processor | Elasticsearch Guide [8.4] | Elastic](https://www.elastic.co/guide/en/elasticsearch/reference/8.4/script-processor.html), but it'd probably be a funky script.

---

<div class="post-metadata">

**Author:** ![DominicS](https://avatars.discourse-cdn.com/v4/letter/d/eada6e/32.png) [@DominicS](https://discuss.elastic.co/u/DominicS)\
**Post date:** [September 1, 2022, 6:58pm UTC](https://discuss.elastic.co/t/how-to-grok-hexidecimals-to-human-readable-values/313380/6 "2022-09-01T18:58:34Z")

</div>

HI Leandrojmp many thanks for all your help very useful, on the other sample data i managed to work with it ...however how do i grok for this other sample data , i have made some progress but note quite what want

6310fc62 Example-pre 0 0 a|20220901183445\_solar\_radio07274b0\_refl-opt\_metdb.h5||6b613|0.01|0|54270446|6310fc62\_53bd\_0

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 29, 2022, 6:59pm UTC](https://discuss.elastic.co/t/how-to-grok-hexidecimals-to-human-readable-values/313380/7 "2022-09-29T18:59:33Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
