# How to grok something out of the middle of a line?

**URL:** <https://discuss.elastic.co/t/how-to-grok-something-out-of-the-middle-of-a-line/50998>\
**Category:** Logstash\
**Created:** [May 25, 2016, 11:02pm UTC](https://discuss.elastic.co/t/how-to-grok-something-out-of-the-middle-of-a-line/50998 "2016-05-25T23:02:52Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![jerrac](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jerrac/32/52980_2.png) [@jerrac](https://discuss.elastic.co/u/jerrac)\
**Post date:** [May 25, 2016, 11:02pm UTC](https://discuss.elastic.co/t/how-to-grok-something-out-of-the-middle-of-a-line/50998/1 "2016-05-25T23:02:52Z")

</div>

If I have a line like:

```
the quick brown fox

```

How can I grok "brown" out of that line?

`(?<color>(brown))` Does not work.

If I do something like `(?<color>.*(brown))`, the color field ends up with "the quick brown".

My specific use case is getting the timestamp from the [GitLab production.log](http://docs.gitlab.com/ce/logs/logs.html) file. It is not at the beginning of the line.

I've been testing with [Grok Constructor](http://grokconstructor.appspot.com) but I just haven't figured it out. And at this time of day, I'm not going to get any farther. So any help will be appreciated. 🙂

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [May 26, 2016, 3:45am UTC](https://discuss.elastic.co/t/how-to-grok-something-out-of-the-middle-of-a-line/50998/2 "2016-05-26T03:45:20Z")

</div>

> `(?<color>(brown))` Does not work.

Works fine for me:

```auto
$ cat test.config
input { stdin {} }
output { stdout { codec => rubydebug } }
filter {
  grok {
    match => ["message", "(?<color>(brown))"]
  }
}
$ echo 'the quick brown fox' | /opt/logstash/bin/logstash -f test.config
Settings: Default pipeline workers: 2
Pipeline main started
{
       "message" => "the quick brown fox",
      "@version" => "1",
    "@timestamp" => "2016-05-26T03:43:00.830Z",
          "host" => "hallonet",
         "color" => "brown"
}
Pipeline main has been shutdown
stopping pipeline {:id=>"main"}

```

Note that the inner set of parentheses in your grok expression serve no purpose.

> If I do something like `(?<color>.*(brown))`, the color field ends up with "the quick brown".

Yes, because `.*` is inside the outer parentheses that denote what's being captured into the `color` field. If you move `.*` to the outside it'll work.

---

<div class="post-metadata">

**Author:** ![jerrac](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jerrac/32/52980_2.png) [@jerrac](https://discuss.elastic.co/u/jerrac)\
**Post date:** [May 26, 2016, 3:48pm UTC](https://discuss.elastic.co/t/how-to-grok-something-out-of-the-middle-of-a-line/50998/3 "2016-05-26T15:48:01Z")

</div>

Interesting. The first one does not work when tested on [grok constructor](http://grokconstructor.appspot.com/do/match). I assume that's a bug on that site, since it works with logstash itself.

`.*(?<color>(brown))` does work on grok constructor.

Thanks for the help!

---

<div class="post-metadata">

**Author:** ![anil\_varghese](https://avatars.discourse-cdn.com/v4/letter/a/fbc32d/32.png) [@anil\_varghese](https://discuss.elastic.co/u/anil_varghese)\
**Post date:** [May 26, 2016, 8:56pm UTC](https://discuss.elastic.co/t/how-to-grok-something-out-of-the-middle-of-a-line/50998/4 "2016-05-26T20:56:32Z")

</div>

You can use this in Grok

\S+ \S+ %{WORD.\*}

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 4:56am UTC](https://discuss.elastic.co/t/how-to-grok-something-out-of-the-middle-of-a-line/50998/5 "2017-07-06T04:56:02Z")

</div>


