# How to map multiple patterns using dissect

**URL:** <https://discuss.elastic.co/t/how-to-map-multiple-patterns-using-dissect/246816>\
**Category:** Logstash\
**Created:** [August 28, 2020, 7:35pm UTC](https://discuss.elastic.co/t/how-to-map-multiple-patterns-using-dissect/246816 "2020-08-28T19:35:46Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![shani](https://avatars.discourse-cdn.com/v4/letter/s/e95f7d/32.png) [@shani](https://discuss.elastic.co/u/shani)\
**Post date:** [August 28, 2020, 7:35pm UTC](https://discuss.elastic.co/t/how-to-map-multiple-patterns-using-dissect/246816/1 "2020-08-28T19:35:46Z")

</div>

Hi all, do we have any option to map more than 1 mapping of raw event as we do with grok like grok {match =\> {"fieldname" =\> ["pattern1", "pattern2", "patternN" ...]}}

Below code gets failed if I see any different pattern in my raw logs. I want to create more than 1 mapping. Please help me

```
 dissect {
            mapping => {
              "message" => "%{winlog_header}

%{winlog_subject}

%{winlog_logon}

%{winlog_impersonation}

%{winlog_newlogon}

%{winlog_process}"}
           tag_on_failure => ["event_code_4624_dissect_failed"]
           }#end_dissect
```

---

<div class="post-metadata">

**Author:** ![shani](https://avatars.discourse-cdn.com/v4/letter/s/e95f7d/32.png) [@shani](https://discuss.elastic.co/u/shani)\
**Post date:** [August 28, 2020, 7:43pm UTC](https://discuss.elastic.co/t/how-to-map-multiple-patterns-using-dissect/246816/2 "2020-08-28T19:43:30Z")

</div>

Sir,

In above, I'm dissecting the content of message fields like if \n\n comes then create it a fields before and after \n\n. So I'm creating 6 fields but now I'm seeing only 3 delimiters \n\n fields in my raw logs. I want that message should also consider the second match like if first mapping gets failed then it should consider the second mapping. Do we have any option using dissect or can you suggest any other option that could resolve this issue. Thank you in advance.

---

<div class="post-metadata">

**Author:** ![shani](https://avatars.discourse-cdn.com/v4/letter/s/e95f7d/32.png) [@shani](https://discuss.elastic.co/u/shani)\
**Post date:** [August 30, 2020, 5:48pm UTC](https://discuss.elastic.co/t/how-to-map-multiple-patterns-using-dissect/246816/3 "2020-08-30T17:48:30Z")

</div>

Hi Community,

I'll be grateful if some could please reply to me on this. I know I have an option like

> if "event\_code\_4624\_dissect\_failed" in [tags] {  
> dissect {  
> this\_pattern  
> }  
> ...  
> }  
> but I don't want to use this. I want to hear about any option of multiple dissect pattern match as grok match offers like grok {match =\> {"field" =\> ["pattern1", "pattern2", "patternN"]}}

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [August 30, 2020, 8:04pm UTC](https://discuss.elastic.co/t/how-to-map-multiple-patterns-using-dissect/246816/4 "2020-08-30T20:04:41Z")

</div>

> [@shani](#):
>
> I want to hear about any option of multiple dissect pattern match as grok match offers

There is no such option.

---

<div class="post-metadata">

**Author:** ![shani](https://avatars.discourse-cdn.com/v4/letter/s/e95f7d/32.png) [@shani](https://discuss.elastic.co/u/shani)\
**Post date:** [August 30, 2020, 8:06pm UTC](https://discuss.elastic.co/t/how-to-map-multiple-patterns-using-dissect/246816/5 "2020-08-30T20:06:35Z")

</div>

So what could the best option to cater this situation.

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [August 30, 2020, 9:43pm UTC](https://discuss.elastic.co/t/how-to-map-multiple-patterns-using-dissect/246816/6 "2020-08-30T21:43:03Z")

</div>

You can make the dissect conditional, which you said you do not want to do, or unconditionally do multiple dissects. Or use grok. I am pretty sure grok can do anything dissect can do.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 27, 2020, 9:43pm UTC](https://discuss.elastic.co/t/how-to-map-multiple-patterns-using-dissect/246816/7 "2020-09-27T21:43:22Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
